use of tech.pegasys.web3signer.dsl.tls.BasicTlsOptions in project web3signer by ConsenSys.
the class ServerSideTlsCaClientAcceptanceTest method createSigner.
private Signer createSigner(final TlsCertificateDefinition certInCa, final Path testDir, final boolean useConfigFile) throws Exception {
final Path passwordPath = testDir.resolve("keystore.passwd");
writeString(passwordPath, serverCert.getPassword());
final TlsOptions serverOptions = new BasicTlsOptions(serverCert.getPkcs12File(), passwordPath.toFile(), Optional.of(BasicClientAuthConstraints.caOnly()));
final SignerConfigurationBuilder configBuilder = new SignerConfigurationBuilder().withServerTlsOptions(serverOptions).withOverriddenCA(certInCa).withUseConfigFile(useConfigFile).withMode("eth2");
final ClientTlsConfig clientTlsConfig = new ClientTlsConfig(serverCert, clientCert);
return new Signer(configBuilder.build(), clientTlsConfig);
}
use of tech.pegasys.web3signer.dsl.tls.BasicTlsOptions in project web3signer by ConsenSys.
the class ServerSideTlsAcceptanceTest method createTlsSigner.
private Signer createTlsSigner(final TlsCertificateDefinition serverPresentedCerts, final TlsCertificateDefinition clientExpectedCert, final TlsCertificateDefinition clientCertInServerWhitelist, final TlsCertificateDefinition clientToPresent, final int fixedListenPort, final boolean useConfigFile) {
try {
final SignerConfigurationBuilder configBuilder = new SignerConfigurationBuilder().withHttpPort(fixedListenPort).withUseConfigFile(useConfigFile).withMode("eth1");
final ClientAuthConstraints clientAuthConstraints;
if (clientCertInServerWhitelist != null) {
final Path fingerPrintFilePath = dataPath.resolve("known_clients");
populateFingerprintFile(fingerPrintFilePath, clientCertInServerWhitelist, Optional.empty());
clientAuthConstraints = BasicClientAuthConstraints.fromFile(fingerPrintFilePath.toFile());
} else {
clientAuthConstraints = null;
}
final Path passwordPath = dataPath.resolve("keystore.passwd");
if (serverPresentedCerts.getPassword() != null) {
writeString(passwordPath, serverPresentedCerts.getPassword());
}
final TlsOptions serverOptions = new BasicTlsOptions(serverPresentedCerts.getPkcs12File(), passwordPath.toFile(), Optional.ofNullable(clientAuthConstraints));
configBuilder.withServerTlsOptions(serverOptions);
final ClientTlsConfig clientTlsConfig;
if (clientExpectedCert != null) {
clientTlsConfig = new ClientTlsConfig(clientExpectedCert, clientToPresent);
} else {
clientTlsConfig = null;
}
return new Signer(configBuilder.build(), clientTlsConfig);
} catch (final Exception e) {
fail("Failed to create EthSigner.", e);
return null;
}
}
use of tech.pegasys.web3signer.dsl.tls.BasicTlsOptions in project web3signer by ConsenSys.
the class ServerSideTlsAcceptanceTest method missingKeyStoreFileResultsInEthSignerExiting.
@ParameterizedTest
@ValueSource(booleans = { true, false })
void missingKeyStoreFileResultsInEthSignerExiting(final boolean useConfigFile) throws IOException {
final TlsOptions serverOptions = new BasicTlsOptions(dataPath.resolve("missing_keystore").toFile(), Files.writeString(dataPath.resolve("password"), "password").toFile(), Optional.empty());
// Requires arbitrary port to avoid waiting for Ports file
final SignerConfigurationBuilder configBuilder = new SignerConfigurationBuilder().withUseConfigFile(useConfigFile).withServerTlsOptions(serverOptions).withHttpPort(9000);
signer = new Signer(configBuilder.withMode("eth2").build(), null);
signer.start();
waitFor(() -> assertThat(signer.isRunning()).isFalse());
}
Aggregations