1 /* 2 * Copyright (C) 2018 The Android Open Source Project 3 * 4 * Licensed under the Apache License, Version 2.0 (the "License"); 5 * you may not use this file except in compliance with the License. 6 * You may obtain a copy of the License at 7 * 8 * http://www.apache.org/licenses/LICENSE-2.0 9 * 10 * Unless required by applicable law or agreed to in writing, software 11 * distributed under the License is distributed on an "AS IS" BASIS, 12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13 * See the License for the specific language governing permissions and 14 * limitations under the License. 15 */ 16 17 package android.net.ipsec.ike; 18 19 import android.annotation.IntDef; 20 import android.annotation.NonNull; 21 import android.net.ipsec.ike.exceptions.AuthenticationFailedException; 22 import android.os.PersistableBundle; 23 import android.util.ArraySet; 24 25 import java.lang.annotation.Retention; 26 import java.lang.annotation.RetentionPolicy; 27 import java.security.cert.CertificateParsingException; 28 import java.security.cert.X509Certificate; 29 import java.util.Collection; 30 import java.util.List; 31 import java.util.Set; 32 33 /** 34 * IkeIdentification is abstract base class that represents the common information for all types of 35 * IKE entity identification. 36 * 37 * <p>{@link IkeIdentification} is used in IKE authentication. 38 * 39 * @see <a href="https://tools.ietf.org/html/rfc7296#section-3.5">RFC 7296, Internet Key Exchange 40 * Protocol Version 2 (IKEv2)</a> 41 */ 42 public abstract class IkeIdentification { 43 // Set of supported ID types. 44 private static final Set<Integer> SUPPORTED_ID_TYPES; 45 46 private static final int INDEX_SAN_TYPE = 0; 47 private static final int INDEX_SAN_DATA = 1; 48 49 /** @hide */ 50 @Retention(RetentionPolicy.SOURCE) 51 @IntDef({ 52 ID_TYPE_IPV4_ADDR, 53 ID_TYPE_FQDN, 54 ID_TYPE_RFC822_ADDR, 55 ID_TYPE_IPV6_ADDR, 56 ID_TYPE_DER_ASN1_DN, 57 ID_TYPE_KEY_ID 58 }) 59 public @interface IdType {} 60 61 /** @hide */ 62 public static final int ID_TYPE_IPV4_ADDR = 1; 63 /** @hide */ 64 public static final int ID_TYPE_FQDN = 2; 65 /** @hide */ 66 public static final int ID_TYPE_RFC822_ADDR = 3; 67 /** @hide */ 68 public static final int ID_TYPE_IPV6_ADDR = 5; 69 /** @hide */ 70 public static final int ID_TYPE_DER_ASN1_DN = 9; 71 /** @hide */ 72 public static final int ID_TYPE_KEY_ID = 11; 73 74 static { 75 SUPPORTED_ID_TYPES = new ArraySet(); 76 SUPPORTED_ID_TYPES.add(ID_TYPE_IPV4_ADDR); 77 SUPPORTED_ID_TYPES.add(ID_TYPE_FQDN); 78 SUPPORTED_ID_TYPES.add(ID_TYPE_RFC822_ADDR); 79 SUPPORTED_ID_TYPES.add(ID_TYPE_IPV6_ADDR); 80 SUPPORTED_ID_TYPES.add(ID_TYPE_DER_ASN1_DN); 81 SUPPORTED_ID_TYPES.add(ID_TYPE_KEY_ID); 82 } 83 84 /** @hide Subject Alternative Name Type for RFC822 Email Address defined in RFC 5280 */ 85 protected static final int SAN_TYPE_RFC822_NAME = 1; 86 /** @hide Subject Alternative Name Type for DNS Name defined in RFC 5280 */ 87 protected static final int SAN_TYPE_DNS = 2; 88 /** @hide Subject Alternative Name Type for IP Address defined in RFC 5280 */ 89 protected static final int SAN_TYPE_IP_ADDRESS = 7; 90 91 private static final String ID_TYPE_KEY = "idType"; 92 /** @hide */ 93 public final int idType; 94 95 /** @hide */ IkeIdentification(@dType int type)96 protected IkeIdentification(@IdType int type) { 97 idType = type; 98 } 99 100 /** 101 * Constructs this object by deserializing a PersistableBundle 102 * 103 * @hide 104 */ 105 @NonNull fromPersistableBundle(@onNull PersistableBundle in)106 public static IkeIdentification fromPersistableBundle(@NonNull PersistableBundle in) { 107 int idType = in.getInt(ID_TYPE_KEY); 108 switch (idType) { 109 case ID_TYPE_IPV4_ADDR: 110 return IkeIpv4AddrIdentification.fromPersistableBundle(in); 111 case ID_TYPE_FQDN: 112 return IkeFqdnIdentification.fromPersistableBundle(in); 113 case ID_TYPE_RFC822_ADDR: 114 return IkeRfc822AddrIdentification.fromPersistableBundle(in); 115 case ID_TYPE_IPV6_ADDR: 116 return IkeIpv6AddrIdentification.fromPersistableBundle(in); 117 case ID_TYPE_DER_ASN1_DN: 118 return IkeDerAsn1DnIdentification.fromPersistableBundle(in); 119 case ID_TYPE_KEY_ID: 120 return IkeKeyIdIdentification.fromPersistableBundle(in); 121 default: 122 throw new IllegalArgumentException("Invalid ID type: " + idType); 123 } 124 } 125 126 /** 127 * Serializes this object to a PersistableBundle 128 * 129 * @hide 130 */ 131 @NonNull toPersistableBundle()132 public PersistableBundle toPersistableBundle() { 133 final PersistableBundle result = new PersistableBundle(); 134 result.putInt(ID_TYPE_KEY, idType); 135 return result; 136 } 137 138 /** 139 * Returns ID type as a String 140 * 141 * @hide 142 */ getIdTypeString()143 public abstract String getIdTypeString(); 144 145 /** 146 * Check if the end certificate's subject DN or SAN matches this identification 147 * 148 * @hide 149 */ validateEndCertIdOrThrow(X509Certificate endCert)150 public abstract void validateEndCertIdOrThrow(X509Certificate endCert) 151 throws AuthenticationFailedException; 152 153 /** 154 * Check if the end certificate SAN matches the identification 155 * 156 * <p>According to RFC 7296, the received IKE ID that types are FQDN, IPv4/IPv6 Address and 157 * RFC822 Address should match the end certificate Subject Alternative Name (SAN). 158 * 159 * @hide 160 */ validateEndCertSanOrThrow( X509Certificate endCert, int expectedSanType, Object expectedSanData)161 protected void validateEndCertSanOrThrow( 162 X509Certificate endCert, int expectedSanType, Object expectedSanData) 163 throws AuthenticationFailedException { 164 try { 165 // Each List is one SAN whose first entry is an Integer that represents a SAN type and 166 // second entry is a String or a byte array that represents the SAN data 167 Collection<List<?>> allSans = endCert.getSubjectAlternativeNames(); 168 if (allSans == null) { 169 throw new AuthenticationFailedException("End certificate does not contain SAN"); 170 } 171 172 for (List<?> san : allSans) { 173 if ((Integer) san.get(INDEX_SAN_TYPE) == expectedSanType) { 174 Object item = san.get(INDEX_SAN_DATA); 175 if (expectedSanData.equals(item)) { 176 return; 177 } 178 } 179 } 180 throw new AuthenticationFailedException( 181 "End certificate SAN and " + getIdTypeString() + " ID mismatched"); 182 } catch (CertificateParsingException e) { 183 throw new AuthenticationFailedException(e); 184 } 185 } 186 /** 187 * Return the encoded identification data in a byte array. 188 * 189 * @return the encoded identification data. 190 * @hide 191 */ getEncodedIdData()192 public abstract byte[] getEncodedIdData(); 193 } 194