Search in sources :

Example 1 with ActivateSessionRequest

use of org.eclipse.milo.opcua.stack.core.types.structured.ActivateSessionRequest in project milo by eclipse.

the class SessionFsmFactory method activateSession.

@SuppressWarnings("Duplicates")
private static CompletableFuture<OpcUaSession> activateSession(FsmContext<State, Event> ctx, OpcUaClient client, CreateSessionResponse csr) {
    UaStackClient stackClient = client.getStackClient();
    try {
        EndpointDescription endpoint = client.getConfig().getEndpoint();
        ByteString csrNonce = csr.getServerNonce();
        SignedIdentityToken signedIdentityToken = client.getConfig().getIdentityProvider().getIdentityToken(endpoint, csrNonce);
        UserIdentityToken userIdentityToken = signedIdentityToken.getToken();
        SignatureData userTokenSignature = signedIdentityToken.getSignature();
        ActivateSessionRequest request = new ActivateSessionRequest(client.newRequestHeader(csr.getAuthenticationToken()), buildClientSignature(client.getConfig(), csrNonce), new SignedSoftwareCertificate[0], new String[0], ExtensionObject.encode(client.getStaticSerializationContext(), userIdentityToken), userTokenSignature);
        LOGGER.debug("[{}] Sending ActivateSessionRequest...", ctx.getInstanceId());
        return stackClient.sendRequest(request).thenApply(ActivateSessionResponse.class::cast).thenCompose(asr -> {
            ByteString asrNonce = asr.getServerNonce();
            // TODO check for repeated nonce?
            OpcUaSession session = new OpcUaSession(csr.getAuthenticationToken(), csr.getSessionId(), client.getConfig().getSessionName().get(), csr.getRevisedSessionTimeout(), csr.getMaxRequestMessageSize(), csr.getServerCertificate(), csr.getServerSoftwareCertificates());
            session.setServerNonce(asrNonce);
            return completedFuture(session);
        });
    } catch (Exception ex) {
        return failedFuture(ex);
    }
}
Also used : SignatureData(org.eclipse.milo.opcua.stack.core.types.structured.SignatureData) OpcUaSession(org.eclipse.milo.opcua.sdk.client.OpcUaSession) ActivateSessionRequest(org.eclipse.milo.opcua.stack.core.types.structured.ActivateSessionRequest) UaStackClient(org.eclipse.milo.opcua.stack.client.UaStackClient) ByteString(org.eclipse.milo.opcua.stack.core.types.builtin.ByteString) SignedIdentityToken(org.eclipse.milo.opcua.sdk.client.api.identity.SignedIdentityToken) EndpointDescription(org.eclipse.milo.opcua.stack.core.types.structured.EndpointDescription) UserIdentityToken(org.eclipse.milo.opcua.stack.core.types.structured.UserIdentityToken) CertificateEncodingException(java.security.cert.CertificateEncodingException) UaException(org.eclipse.milo.opcua.stack.core.UaException)

Example 2 with ActivateSessionRequest

use of org.eclipse.milo.opcua.stack.core.types.structured.ActivateSessionRequest in project milo by eclipse.

the class SessionManager method activateSession.

private ActivateSessionResponse activateSession(ServiceRequest serviceRequest) throws UaException {
    ActivateSessionRequest request = (ActivateSessionRequest) serviceRequest.getRequest();
    long secureChannelId = serviceRequest.getSecureChannelId();
    NodeId authToken = request.getRequestHeader().getAuthenticationToken();
    List<SignedSoftwareCertificate> clientSoftwareCertificates = l(request.getClientSoftwareCertificates());
    Session session = createdSessions.get(authToken);
    if (session == null) {
        session = activeSessions.get(authToken);
        if (session == null) {
            throw new UaException(StatusCodes.Bad_SessionIdInvalid);
        } else {
            verifyClientSignature(session, request);
            SecurityConfiguration securityConfiguration = session.getSecurityConfiguration();
            if (session.getSecureChannelId() == secureChannelId) {
                /*
                     * Identity change
                     */
                UserIdentityToken identityToken = decodeIdentityToken(request.getUserIdentityToken(), session.getEndpoint().getUserIdentityTokens());
                Object identityObject = validateIdentityToken(session, identityToken, request.getUserTokenSignature());
                StatusCode[] results = new StatusCode[clientSoftwareCertificates.size()];
                Arrays.fill(results, StatusCode.GOOD);
                ByteString serverNonce = NonceUtil.generateNonce(32);
                session.setClientAddress(serviceRequest.getClientAddress());
                session.setIdentityObject(identityObject, identityToken);
                session.setLastNonce(serverNonce);
                session.setLocaleIds(request.getLocaleIds());
                return new ActivateSessionResponse(serviceRequest.createResponseHeader(), serverNonce, results, new DiagnosticInfo[0]);
            } else {
                /*
                     * Associate session with new secure channel if client certificate and identity token match.
                     */
                ByteString clientCertificateBytes = serviceRequest.getClientCertificateBytes();
                UserIdentityToken identityToken = decodeIdentityToken(request.getUserIdentityToken(), session.getEndpoint().getUserIdentityTokens());
                Object identityObject = validateIdentityToken(session, identityToken, request.getUserTokenSignature());
                boolean sameIdentity = Objects.equal(identityObject, session.getIdentityObject());
                boolean sameCertificate = Objects.equal(clientCertificateBytes, securityConfiguration.getClientCertificateBytes());
                if (sameIdentity && sameCertificate) {
                    SecurityConfiguration newSecurityConfiguration = createSecurityConfiguration(serviceRequest.getEndpoint(), clientCertificateBytes);
                    session.setEndpoint(serviceRequest.getEndpoint());
                    session.setSecureChannelId(secureChannelId);
                    session.setSecurityConfiguration(newSecurityConfiguration);
                    logger.debug("Session id={} is now associated with secureChannelId={}", session.getSessionId(), secureChannelId);
                    StatusCode[] results = new StatusCode[clientSoftwareCertificates.size()];
                    Arrays.fill(results, StatusCode.GOOD);
                    ByteString serverNonce = NonceUtil.generateNonce(32);
                    session.setClientAddress(serviceRequest.getClientAddress());
                    session.setLastNonce(serverNonce);
                    session.setLocaleIds(request.getLocaleIds());
                    return new ActivateSessionResponse(serviceRequest.createResponseHeader(), serverNonce, results, new DiagnosticInfo[0]);
                } else {
                    throw new UaException(StatusCodes.Bad_SecurityChecksFailed);
                }
            }
        }
    } else {
        if (secureChannelId != session.getSecureChannelId()) {
            throw new UaException(StatusCodes.Bad_SecurityChecksFailed);
        }
        verifyClientSignature(session, request);
        UserIdentityToken identityToken = decodeIdentityToken(request.getUserIdentityToken(), session.getEndpoint().getUserIdentityTokens());
        Object identityObject = validateIdentityToken(session, identityToken, request.getUserTokenSignature());
        createdSessions.remove(authToken);
        activeSessions.put(authToken, session);
        StatusCode[] results = new StatusCode[clientSoftwareCertificates.size()];
        Arrays.fill(results, StatusCode.GOOD);
        ByteString serverNonce = NonceUtil.generateNonce(32);
        session.setClientAddress(serviceRequest.getClientAddress());
        session.setIdentityObject(identityObject, identityToken);
        session.setLocaleIds(request.getLocaleIds());
        session.setLastNonce(serverNonce);
        return new ActivateSessionResponse(serviceRequest.createResponseHeader(), serverNonce, results, new DiagnosticInfo[0]);
    }
}
Also used : ActivateSessionRequest(org.eclipse.milo.opcua.stack.core.types.structured.ActivateSessionRequest) UaException(org.eclipse.milo.opcua.stack.core.UaException) ByteString(org.eclipse.milo.opcua.stack.core.types.builtin.ByteString) StatusCode(org.eclipse.milo.opcua.stack.core.types.builtin.StatusCode) NodeId(org.eclipse.milo.opcua.stack.core.types.builtin.NodeId) SignedSoftwareCertificate(org.eclipse.milo.opcua.stack.core.types.structured.SignedSoftwareCertificate) ExtensionObject(org.eclipse.milo.opcua.stack.core.types.builtin.ExtensionObject) UserIdentityToken(org.eclipse.milo.opcua.stack.core.types.structured.UserIdentityToken) ActivateSessionResponse(org.eclipse.milo.opcua.stack.core.types.structured.ActivateSessionResponse)

Aggregations

UaException (org.eclipse.milo.opcua.stack.core.UaException)2 ByteString (org.eclipse.milo.opcua.stack.core.types.builtin.ByteString)2 ActivateSessionRequest (org.eclipse.milo.opcua.stack.core.types.structured.ActivateSessionRequest)2 UserIdentityToken (org.eclipse.milo.opcua.stack.core.types.structured.UserIdentityToken)2 CertificateEncodingException (java.security.cert.CertificateEncodingException)1 OpcUaSession (org.eclipse.milo.opcua.sdk.client.OpcUaSession)1 SignedIdentityToken (org.eclipse.milo.opcua.sdk.client.api.identity.SignedIdentityToken)1 UaStackClient (org.eclipse.milo.opcua.stack.client.UaStackClient)1 ExtensionObject (org.eclipse.milo.opcua.stack.core.types.builtin.ExtensionObject)1 NodeId (org.eclipse.milo.opcua.stack.core.types.builtin.NodeId)1 StatusCode (org.eclipse.milo.opcua.stack.core.types.builtin.StatusCode)1 ActivateSessionResponse (org.eclipse.milo.opcua.stack.core.types.structured.ActivateSessionResponse)1 EndpointDescription (org.eclipse.milo.opcua.stack.core.types.structured.EndpointDescription)1 SignatureData (org.eclipse.milo.opcua.stack.core.types.structured.SignatureData)1 SignedSoftwareCertificate (org.eclipse.milo.opcua.stack.core.types.structured.SignedSoftwareCertificate)1