From eb507a5a0dd13db1042ff05e5ae72c6fe0525170 Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Sat, 30 Apr 2016 16:11:45 +0200 Subject: [PATCH] android: Add helper function to TrustedCertificateEntry to get subjectAltNames Duplicates (e.g. with different types) are filtered. If necessary we could later perhaps add a prefix. --- .../security/TrustedCertificateEntry.java | 47 +++++++++++++++++-- 1 file changed, 43 insertions(+), 4 deletions(-) diff --git a/src/frontends/android/app/src/main/java/org/strongswan/android/security/TrustedCertificateEntry.java b/src/frontends/android/app/src/main/java/org/strongswan/android/security/TrustedCertificateEntry.java index 143741faf7..5e9873d1bd 100644 --- a/src/frontends/android/app/src/main/java/org/strongswan/android/security/TrustedCertificateEntry.java +++ b/src/frontends/android/app/src/main/java/org/strongswan/android/security/TrustedCertificateEntry.java @@ -1,6 +1,6 @@ /* - * Copyright (C) 2012 Tobias Brunner - * Hochschule fuer Technik Rapperswil + * Copyright (C) 2012-2016 Tobias Brunner + * HSR Hochschule fuer Technik Rapperswil * * This program is free software; you can redistribute it and/or modify it * under the terms of the GNU General Public License as published by the @@ -15,10 +15,15 @@ package org.strongswan.android.security; -import java.security.cert.X509Certificate; - import android.net.http.SslCertificate; +import java.security.cert.CertificateParsingException; +import java.security.cert.X509Certificate; +import java.util.ArrayList; +import java.util.Collection; +import java.util.Collections; +import java.util.List; + public class TrustedCertificateEntry implements Comparable { private final X509Certificate mCert; @@ -86,6 +91,40 @@ public class TrustedCertificateEntry implements Comparable getSubjectAltNames() + { + List list = new ArrayList<>(); + try + { + Collection> sans = mCert.getSubjectAlternativeNames(); + if (sans != null) + { + for (List san : sans) + { + switch ((Integer)san.get(0)) + { + case 1: /* rfc822Name */ + case 2: /* dnSName */ + case 7: /* iPAddress */ + list.add((String)san.get(1)); + break; + } + } + } + Collections.sort(list); + } + catch(CertificateParsingException ex) + { + ex.printStackTrace(); + } + return list; + } + /** * The alias associated with this certificate. *