Path: blob/aarch64-shenandoah-jdk8u272-b10/jdk/test/javax/net/ssl/sanity/ciphersuites/CheckCipherSuites.java
38861 views
/*1* Copyright (c) 2002, 2019, Oracle and/or its affiliates. All rights reserved.2* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.3*4* This code is free software; you can redistribute it and/or modify it5* under the terms of the GNU General Public License version 2 only, as6* published by the Free Software Foundation.7*8* This code is distributed in the hope that it will be useful, but WITHOUT9* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or10* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License11* version 2 for more details (a copy is included in the LICENSE file that12* accompanied this code).13*14* You should have received a copy of the GNU General Public License version15* 2 along with this work; if not, write to the Free Software Foundation,16* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.17*18* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA19* or visit www.oracle.com if you need additional information or have any20* questions.21*/2223/*24* @test25* @bug 4750141 4895631 821757926* @summary Check enabled and supported ciphersuites are correct27* @run main/othervm -Djdk.tls.client.protocols="TLSv1.3,TLSv1.2,TLSv1.1,TLSv1,SSLv3" CheckCipherSuites default28* @run main/othervm -Djdk.tls.client.protocols="TLSv1.3,TLSv1.2,TLSv1.1,TLSv1,SSLv3" CheckCipherSuites limited29*/3031import java.util.*;32import java.security.Security;33import javax.net.ssl.*;3435public class CheckCipherSuites {3637// List of enabled cipher suites when the "crypto.policy" security38// property is set to "unlimited" (the default value).39private final static String[] ENABLED_DEFAULT = {40"TLS_AES_128_GCM_SHA256",41"TLS_AES_256_GCM_SHA384",42"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384",43"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256",44"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384",45"TLS_RSA_WITH_AES_256_GCM_SHA384",46"TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384",47"TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384",48"TLS_DHE_RSA_WITH_AES_256_GCM_SHA384",49"TLS_DHE_DSS_WITH_AES_256_GCM_SHA384",50"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256",51"TLS_RSA_WITH_AES_128_GCM_SHA256",52"TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256",53"TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256",54"TLS_DHE_RSA_WITH_AES_128_GCM_SHA256",55"TLS_DHE_DSS_WITH_AES_128_GCM_SHA256",56"TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384",57"TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384",58"TLS_RSA_WITH_AES_256_CBC_SHA256",59"TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384",60"TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384",61"TLS_DHE_RSA_WITH_AES_256_CBC_SHA256",62"TLS_DHE_DSS_WITH_AES_256_CBC_SHA256",63"TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA",64"TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA",65"TLS_RSA_WITH_AES_256_CBC_SHA",66"TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA",67"TLS_ECDH_RSA_WITH_AES_256_CBC_SHA",68"TLS_DHE_RSA_WITH_AES_256_CBC_SHA",69"TLS_DHE_DSS_WITH_AES_256_CBC_SHA",70"TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256",71"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256",72"TLS_RSA_WITH_AES_128_CBC_SHA256",73"TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256",74"TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256",75"TLS_DHE_RSA_WITH_AES_128_CBC_SHA256",76"TLS_DHE_DSS_WITH_AES_128_CBC_SHA256",77"TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA",78"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA",79"TLS_RSA_WITH_AES_128_CBC_SHA",80"TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA",81"TLS_ECDH_RSA_WITH_AES_128_CBC_SHA",82"TLS_DHE_RSA_WITH_AES_128_CBC_SHA",83"TLS_DHE_DSS_WITH_AES_128_CBC_SHA",84"TLS_EMPTY_RENEGOTIATION_INFO_SCSV"85};8687// List of enabled cipher suites when the "crypto.policy" security88// property is set to "limited".89private final static String[] ENABLED_LIMITED = {90"TLS_AES_128_GCM_SHA256",91"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256",92"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256",93"TLS_RSA_WITH_AES_128_GCM_SHA256",94"TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256",95"TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256",96"TLS_DHE_RSA_WITH_AES_128_GCM_SHA256",97"TLS_DHE_DSS_WITH_AES_128_GCM_SHA256",98"TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256",99"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256",100"TLS_RSA_WITH_AES_128_CBC_SHA256",101"TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256",102"TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256",103"TLS_DHE_RSA_WITH_AES_128_CBC_SHA256",104"TLS_DHE_DSS_WITH_AES_128_CBC_SHA256",105"TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA",106"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA",107"TLS_RSA_WITH_AES_128_CBC_SHA",108"TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA",109"TLS_ECDH_RSA_WITH_AES_128_CBC_SHA",110"TLS_DHE_RSA_WITH_AES_128_CBC_SHA",111"TLS_DHE_DSS_WITH_AES_128_CBC_SHA",112"TLS_EMPTY_RENEGOTIATION_INFO_SCSV"113};114115// List of supported cipher suites when the "crypto.policy" security116// property is set to "unlimited" (the default value).117private final static String[] SUPPORTED_DEFAULT = {118"TLS_AES_128_GCM_SHA256",119"TLS_AES_256_GCM_SHA384",120"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384",121"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256",122"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384",123"TLS_RSA_WITH_AES_256_GCM_SHA384",124"TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384",125"TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384",126"TLS_DHE_RSA_WITH_AES_256_GCM_SHA384",127"TLS_DHE_DSS_WITH_AES_256_GCM_SHA384",128"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256",129"TLS_RSA_WITH_AES_128_GCM_SHA256",130"TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256",131"TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256",132"TLS_DHE_RSA_WITH_AES_128_GCM_SHA256",133"TLS_DHE_DSS_WITH_AES_128_GCM_SHA256",134"TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384",135"TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384",136"TLS_RSA_WITH_AES_256_CBC_SHA256",137"TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384",138"TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384",139"TLS_DHE_RSA_WITH_AES_256_CBC_SHA256",140"TLS_DHE_DSS_WITH_AES_256_CBC_SHA256",141"TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA",142"TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA",143"TLS_RSA_WITH_AES_256_CBC_SHA",144"TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA",145"TLS_ECDH_RSA_WITH_AES_256_CBC_SHA",146"TLS_DHE_RSA_WITH_AES_256_CBC_SHA",147"TLS_DHE_DSS_WITH_AES_256_CBC_SHA",148"TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256",149"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256",150"TLS_RSA_WITH_AES_128_CBC_SHA256",151"TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256",152"TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256",153"TLS_DHE_RSA_WITH_AES_128_CBC_SHA256",154"TLS_DHE_DSS_WITH_AES_128_CBC_SHA256",155"TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA",156"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA",157"TLS_RSA_WITH_AES_128_CBC_SHA",158"TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA",159"TLS_ECDH_RSA_WITH_AES_128_CBC_SHA",160"TLS_DHE_RSA_WITH_AES_128_CBC_SHA",161"TLS_DHE_DSS_WITH_AES_128_CBC_SHA",162"TLS_EMPTY_RENEGOTIATION_INFO_SCSV"163};164165// List of supported cipher suites when the "crypto.policy" security166// property is set to "limited".167private final static String[] SUPPORTED_LIMITED = {168"TLS_AES_128_GCM_SHA256",169"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256",170"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256",171"TLS_RSA_WITH_AES_128_GCM_SHA256",172"TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256",173"TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256",174"TLS_DHE_RSA_WITH_AES_128_GCM_SHA256",175"TLS_DHE_DSS_WITH_AES_128_GCM_SHA256",176"TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256",177"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256",178"TLS_RSA_WITH_AES_128_CBC_SHA256",179"TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256",180"TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256",181"TLS_DHE_RSA_WITH_AES_128_CBC_SHA256",182"TLS_DHE_DSS_WITH_AES_128_CBC_SHA256",183"TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA",184"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA",185"TLS_RSA_WITH_AES_128_CBC_SHA",186"TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA",187"TLS_ECDH_RSA_WITH_AES_128_CBC_SHA",188"TLS_DHE_RSA_WITH_AES_128_CBC_SHA",189"TLS_DHE_DSS_WITH_AES_128_CBC_SHA",190"TLS_EMPTY_RENEGOTIATION_INFO_SCSV"191};192193private static void showSuites(String[] suites) {194if ((suites == null) || (suites.length == 0)) {195System.out.println("<none>");196}197for (int i = 0; i < suites.length; i++) {198System.out.println(" " + suites[i]);199}200}201202public static void main(String[] args) throws Exception {203long start = System.currentTimeMillis();204205if (args.length != 1) {206throw new Exception("One arg required");207}208209String[] ENABLED;210String[] SUPPORTED;211if (args[0].equals("default")) {212ENABLED = ENABLED_DEFAULT;213SUPPORTED = SUPPORTED_DEFAULT;214} else if (args[0].equals("limited")) {215Security.setProperty("crypto.policy", "limited");216ENABLED = ENABLED_LIMITED;217SUPPORTED = SUPPORTED_LIMITED;218} else {219throw new Exception("Illegal argument");220}221222SSLSocketFactory factory = (SSLSocketFactory)SSLSocketFactory.getDefault();223SSLSocket socket = (SSLSocket)factory.createSocket();224String[] enabled = socket.getEnabledCipherSuites();225226System.out.println("Default enabled ciphersuites:");227showSuites(enabled);228229if (Arrays.equals(ENABLED, enabled) == false) {230System.out.println("*** MISMATCH, should be ***");231showSuites(ENABLED);232throw new Exception("Enabled ciphersuite mismatch");233}234System.out.println("OK");235System.out.println();236237String[] supported = socket.getSupportedCipherSuites();238System.out.println("Supported ciphersuites:");239showSuites(supported);240241if (Arrays.equals(SUPPORTED, supported) == false) {242System.out.println("*** MISMATCH, should be ***");243showSuites(SUPPORTED);244throw new Exception("Supported ciphersuite mismatch");245}246System.out.println("OK");247248long end = System.currentTimeMillis();249System.out.println("Done (" + (end - start) + " ms).");250}251252}253254255