Search in sources :

Example 1 with PasswordFactory

use of org.wildfly.security.password.PasswordFactory in project fuse-karaf by jboss-fuse.

the class MaskedPasswordHelper method createConfiguration.

@Override
public Map<String, String> createConfiguration(final Map<String, String> attributes) throws GeneralSecurityException, IOException {
    final Provider provider = ProviderHelper.provider(option(attributes, "provider", ProviderHelper.WILDFLY_PROVIDER));
    final String algorithm = option(attributes, "algorithm", DEFAULT_ALGORITHM);
    final PasswordFactory passwordFactory = PasswordFactory.getInstance(algorithm, provider);
    final String password = option(attributes, "password", null);
    final String salt = option(attributes, "salt", "");
    final String iterations = option(attributes, "iterations", "");
    final AlgorithmParameterSpec algorithmParameterSpec;
    if (salt.isEmpty() && iterations.isEmpty()) {
        algorithmParameterSpec = null;
    } else if (salt.isEmpty()) {
        algorithmParameterSpec = new IteratedPasswordAlgorithmSpec(parseInt(iterations));
    } else {
        final byte[] saltBytes = Base64.getDecoder().decode(salt);
        algorithmParameterSpec = new IteratedSaltedPasswordAlgorithmSpec(parseInt(iterations), saltBytes);
    }
    final EncryptablePasswordSpec keySpec = new EncryptablePasswordSpec(password.toCharArray(), algorithmParameterSpec);
    final MaskedPassword maskedPassword = passwordFactory.generatePassword(keySpec).castAs(MaskedPassword.class);
    final MaskedPasswordAlgorithmSpec maskedPasswordAlgorithmSpec = maskedPassword.getParameterSpec();
    final Map<String, String> configuration = new HashMap<>();
    final Encoder encoder = Base64.getEncoder();
    if (!DEFAULT_ALGORITHM.equals(algorithm)) {
        configuration.put(CREDENTIAL_STORE_PROTECTION_ALGORITHM, algorithm);
    }
    configuration.put(CREDENTIAL_STORE_PROTECTION, encoder.encodeToString(maskedPassword.getMaskedPasswordBytes()));
    final AlgorithmParameters algorithmParameters = AlgorithmParameters.getInstance(algorithm, provider);
    algorithmParameters.init(maskedPasswordAlgorithmSpec);
    final byte[] encoded = algorithmParameters.getEncoded();
    configuration.put(CREDENTIAL_STORE_PROTECTION_PARAMS, encoder.encodeToString(encoded));
    return configuration;
}
Also used : HashMap(java.util.HashMap) EncryptablePasswordSpec(org.wildfly.security.password.spec.EncryptablePasswordSpec) Provider(java.security.Provider) IteratedPasswordAlgorithmSpec(org.wildfly.security.password.spec.IteratedPasswordAlgorithmSpec) PasswordFactory(org.wildfly.security.password.PasswordFactory) Encoder(java.util.Base64.Encoder) IteratedSaltedPasswordAlgorithmSpec(org.wildfly.security.password.spec.IteratedSaltedPasswordAlgorithmSpec) AlgorithmParameterSpec(java.security.spec.AlgorithmParameterSpec) MaskedPassword(org.wildfly.security.password.interfaces.MaskedPassword) MaskedPasswordAlgorithmSpec(org.wildfly.security.password.spec.MaskedPasswordAlgorithmSpec) AlgorithmParameters(java.security.AlgorithmParameters)

Example 2 with PasswordFactory

use of org.wildfly.security.password.PasswordFactory in project fuse-karaf by jboss-fuse.

the class MaskedPasswordHelper method createCredentialSource.

@Override
public CredentialSource createCredentialSource(final Map<String, String> configuration) throws GeneralSecurityException, IOException {
    final String algorithmParamsBase64 = option(configuration, CREDENTIAL_STORE_PROTECTION_PARAMS, "");
    final Decoder decoder = Base64.getDecoder();
    final byte[] encodedAlgorithmParams = decoder.decode(algorithmParamsBase64);
    final String algorithm = option(configuration, CREDENTIAL_STORE_PROTECTION_ALGORITHM, DEFAULT_ALGORITHM);
    final Provider provider = ProviderHelper.provider(option(configuration, CREDENTIAL_STORE_PROTECTION_PROVIDER, ProviderHelper.WILDFLY_PROVIDER));
    final AlgorithmParameters algorithmParameters = AlgorithmParameters.getInstance(algorithm, provider);
    algorithmParameters.init(encodedAlgorithmParams);
    final MaskedPasswordAlgorithmSpec maskedPasswordAlgorithmSpec = algorithmParameters.getParameterSpec(MaskedPasswordAlgorithmSpec.class);
    final char[] initialKeyMaterial = maskedPasswordAlgorithmSpec.getInitialKeyMaterial();
    final int iterationCount = maskedPasswordAlgorithmSpec.getIterationCount();
    final byte[] salt = maskedPasswordAlgorithmSpec.getSalt();
    final String maskedPasswordBase64 = option(configuration, CREDENTIAL_STORE_PROTECTION, "");
    final byte[] maskedPasswordBytes = decoder.decode(maskedPasswordBase64);
    final MaskedPasswordSpec maskedPasswordSpec = new MaskedPasswordSpec(initialKeyMaterial, iterationCount, salt, maskedPasswordBytes);
    final PasswordFactory passwordFactory = PasswordFactory.getInstance(algorithm, provider);
    final Password maskedPassword = passwordFactory.generatePassword(maskedPasswordSpec);
    final PasswordFactory clearPasswordFactory = PasswordFactory.getInstance(ClearPassword.ALGORITHM_CLEAR, provider);
    final ClearPasswordSpec clearPasswordSpec = passwordFactory.getKeySpec(maskedPassword, ClearPasswordSpec.class);
    final Password password = clearPasswordFactory.generatePassword(clearPasswordSpec);
    final PasswordCredential passwordCredential = new PasswordCredential(password);
    return IdentityCredentials.NONE.withCredential(passwordCredential);
}
Also used : MaskedPasswordSpec(org.wildfly.security.password.spec.MaskedPasswordSpec) PasswordCredential(org.wildfly.security.credential.PasswordCredential) ClearPasswordSpec(org.wildfly.security.password.spec.ClearPasswordSpec) Decoder(java.util.Base64.Decoder) Provider(java.security.Provider) PasswordFactory(org.wildfly.security.password.PasswordFactory) MaskedPasswordAlgorithmSpec(org.wildfly.security.password.spec.MaskedPasswordAlgorithmSpec) AlgorithmParameters(java.security.AlgorithmParameters) MaskedPassword(org.wildfly.security.password.interfaces.MaskedPassword) Password(org.wildfly.security.password.Password) ClearPassword(org.wildfly.security.password.interfaces.ClearPassword)

Example 3 with PasswordFactory

use of org.wildfly.security.password.PasswordFactory in project fuse-karaf by jboss-fuse.

the class ProtectionTypeTest method shouldCreateMaskedPasswordCredentialSourceFromConfiguration.

@Test
public void shouldCreateMaskedPasswordCredentialSourceFromConfiguration() throws IOException, GeneralSecurityException {
    final Map<String, String> configuration = new HashMap<>();
    configuration.put("CREDENTIAL_STORE_PROTECTION_ALGORITHM", MaskedPassword.ALGORITHM_MASKED_MD5_DES);
    configuration.put("CREDENTIAL_STORE_PROTECTION_PARAMS", "MDkEKXNvbWVhcmJpdHJhcnljcmF6eXN0cmluZ3RoYXRkb2Vzbm90bWF0dGVyAgID6AQIHmrp8uDnGLE=");
    configuration.put("CREDENTIAL_STORE_PROTECTION", "mC/60tWnla4bmFn2e5Z8U3CZnjsG9Pvc");
    final CredentialSource credentialSource = ProtectionType.masked.createCredentialSource(configuration);
    assertThat(credentialSource).isNotNull();
    final PasswordCredential credential = credentialSource.getCredential(PasswordCredential.class);
    final Password password = credential.getPassword();
    final PasswordFactory clearPasswordFactory = PasswordFactory.getInstance(ClearPassword.ALGORITHM_CLEAR, new WildFlyElytronProvider());
    final ClearPasswordSpec clearPasswordSpec = clearPasswordFactory.getKeySpec(password, ClearPasswordSpec.class);
    assertThat(new String(clearPasswordSpec.getEncodedPassword())).isEqualTo("my deep dark secret");
}
Also used : PasswordFactory(org.wildfly.security.password.PasswordFactory) HashMap(java.util.HashMap) PasswordCredential(org.wildfly.security.credential.PasswordCredential) ClearPasswordSpec(org.wildfly.security.password.spec.ClearPasswordSpec) WildFlyElytronProvider(org.wildfly.security.WildFlyElytronProvider) CredentialSource(org.wildfly.security.credential.source.CredentialSource) MaskedPassword(org.wildfly.security.password.interfaces.MaskedPassword) Password(org.wildfly.security.password.Password) ClearPassword(org.wildfly.security.password.interfaces.ClearPassword) Test(org.junit.Test)

Example 4 with PasswordFactory

use of org.wildfly.security.password.PasswordFactory in project fuse-karaf by jboss-fuse.

the class ActivatorTest method initializeCredentialStore.

@Before
public void initializeCredentialStore() throws Exception {
    activator.start(null);
    final WildFlyElytronProvider elytron = new WildFlyElytronProvider();
    Security.addProvider(elytron);
    final PasswordFactory passwordFactory = PasswordFactory.getInstance(ClearPassword.ALGORITHM_CLEAR, elytron);
    final Password password = passwordFactory.generatePassword(new ClearPasswordSpec("it was the best of times it was the worst of times".toCharArray()));
    final Credential credential = new PasswordCredential(password);
    final CredentialSource credentialSource = IdentityCredentials.NONE.withCredential(credential);
    credentialStore = CredentialStore.getInstance(KeyStoreCredentialStore.KEY_STORE_CREDENTIAL_STORE, elytron);
    final String storePath = new File(tmp.getRoot(), "credential.store").getAbsolutePath();
    final Map<String, String> parameters = new HashMap<>();
    parameters.put("location", storePath);
    parameters.put("keyStoreType", "JCEKS");
    credentialStore.initialize(parameters, new CredentialStore.CredentialSourceProtectionParameter(credentialSource));
    final Password secret = passwordFactory.generatePassword(new ClearPasswordSpec("this is a password".toCharArray()));
    final Credential value = new PasswordCredential(secret);
    credentialStore.store("alias", value);
    credentialStore.flush();
}
Also used : PasswordCredential(org.wildfly.security.credential.PasswordCredential) Credential(org.wildfly.security.credential.Credential) HashMap(java.util.HashMap) PasswordCredential(org.wildfly.security.credential.PasswordCredential) ClearPasswordSpec(org.wildfly.security.password.spec.ClearPasswordSpec) WildFlyElytronProvider(org.wildfly.security.WildFlyElytronProvider) PasswordFactory(org.wildfly.security.password.PasswordFactory) CredentialStore(org.wildfly.security.credential.store.CredentialStore) KeyStoreCredentialStore(org.wildfly.security.credential.store.impl.KeyStoreCredentialStore) File(java.io.File) Password(org.wildfly.security.password.Password) ClearPassword(org.wildfly.security.password.interfaces.ClearPassword) CredentialSource(org.wildfly.security.credential.source.CredentialSource) Before(org.junit.Before)

Example 5 with PasswordFactory

use of org.wildfly.security.password.PasswordFactory in project fuse-karaf by jboss-fuse.

the class StoreInCredentialStore method execute.

@Override
public Object execute() throws Exception {
    final CredentialStore credentialStore = CredentialStoreHelper.credentialStoreFromEnvironment();
    final PasswordFactory passwordFactory = PasswordFactory.getInstance("clear", ProviderHelper.provider(ProviderHelper.WILDFLY_PROVIDER));
    final Password password = passwordFactory.generatePassword(new ClearPasswordSpec(secret.toCharArray()));
    credentialStore.store(alias, new PasswordCredential(password));
    credentialStore.flush();
    System.out.println("Value stored in the credential store to reference it use: " + CredentialStoreHelper.referenceForAlias(alias));
    return null;
}
Also used : PasswordFactory(org.wildfly.security.password.PasswordFactory) CredentialStore(org.wildfly.security.credential.store.CredentialStore) PasswordCredential(org.wildfly.security.credential.PasswordCredential) ClearPasswordSpec(org.wildfly.security.password.spec.ClearPasswordSpec) Password(org.wildfly.security.password.Password)

Aggregations

PasswordFactory (org.wildfly.security.password.PasswordFactory)5 PasswordCredential (org.wildfly.security.credential.PasswordCredential)4 Password (org.wildfly.security.password.Password)4 ClearPasswordSpec (org.wildfly.security.password.spec.ClearPasswordSpec)4 HashMap (java.util.HashMap)3 ClearPassword (org.wildfly.security.password.interfaces.ClearPassword)3 MaskedPassword (org.wildfly.security.password.interfaces.MaskedPassword)3 AlgorithmParameters (java.security.AlgorithmParameters)2 Provider (java.security.Provider)2 WildFlyElytronProvider (org.wildfly.security.WildFlyElytronProvider)2 CredentialSource (org.wildfly.security.credential.source.CredentialSource)2 CredentialStore (org.wildfly.security.credential.store.CredentialStore)2 MaskedPasswordAlgorithmSpec (org.wildfly.security.password.spec.MaskedPasswordAlgorithmSpec)2 File (java.io.File)1 AlgorithmParameterSpec (java.security.spec.AlgorithmParameterSpec)1 Decoder (java.util.Base64.Decoder)1 Encoder (java.util.Base64.Encoder)1 Before (org.junit.Before)1 Test (org.junit.Test)1 Credential (org.wildfly.security.credential.Credential)1