<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
#email-body { min-width: 30em !important; }
#email-page { padding: 8px !important; }
#email-banner { padding: 8px 8px 0 8px !important; }
#email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
#email-fields { padding: 0 8px 8px 8px !important; }
#email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
<tr valign="top">
<td id="email-page" style="padding:16px !important;">
<table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
<tr valign="top">
<td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
</tr><tr valign="top">
<td id="email-banner" style="padding:32px 32px 0 32px;">
<table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
<img id="email-avatar" src="https://issues.shibboleth.net/jira/secure/useravatar?avatarId=10202" alt="" height="48" width="48" border="0" align="left" style="padding:0;margin: 0 16px 16px 0;" />
<div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
<a class="user-hover" rel="putmanb@shibboleth.net" id="email_putmanb@shibboleth.net" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=putmanb%40shibboleth.net" style="color:#326ca6;">Brent Putman</a>
commented on <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/task.png" height="16" width="16" border="0" align="absmiddle" alt="Task"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/OSJ-83'>OSJ-83</a>
</div>
<div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
<a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/OSJ-83'><strong>Investigate supporting TrustEngine-based TLS trust eval for HttpClient</strong></a>
</div>
</td>
</tr>
</table>
</td>
</tr>
<tr valign="top">
<td id="email-fields" style="padding:0 32px 32px 32px;">
<table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
<tr valign="top">
<td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
<td>
<table border="0" cellpadding="0" cellspacing="0" width="100%">
<tr valign="top">
<td colspan="2" style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 16px 0;width:100%;">
<div class="comment-block" style="background-color:#edf5ff;border:1px solid #dddddd;color:#000000;padding:12px;"><p>This turned out to be pretty straightforward. My initial idea of a custom X509TrustManager didn't work b/c there's no way to contextualize the eval, as we need to do with a TrustEngine via the CriteriaSet.</p>
<p>What I came up with is similar to what we have always done on the server-side for client TLS: Disable standard javax.net.ssl eval with a "no trust" trust manager on the "real" HttpClient socket factory that does the actual socket work, and then implement our trust eval in a specialized impl of the socket factory interface, which just wraps the real instance. They made this very easy b/c they already have an HttpContext which can be populated by the caller with its own data.</p>
<p>See org.opensaml.security.httpclient.impl.TrustEngineTLSSocketFactory in security-impl. Context key constants are defined in org.opensaml.security.httpclient.HttpClientSecurityConstants in security-api.</p>
<p>Aside from testing, the only thing left would be to add support for injecting or otherwise obtaining/building TrustEngine and CriteriaSet in the HttpClient calling code components (CriteriaSet building perhaps via a strategy Function), and then populating it on the HttpContext.</p>
<p>Sketch of usage:</p>
<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-java"><span class="code-comment">// Example setup code, to get the idea
</span>LayeredConnectionSocketFactory innerFactory = HttpClientSupport.buildNoTrustSSLConnectionSocketFactory();
TrustEngineTLSSocketFactory trustEngineFactory = <span class="code-keyword">new</span> TrustEngineTLSSocketFactory(innerFactory, <span class="code-keyword">new</span> StrictHostnameVerifier());
CloseableHttpClient httpClient = HttpClientBuilder.create().setSSLSocketFactory(trustEngineFactory).build();
<span class="code-comment">// In the HttpClient calling code
</span>HttpClientContext context = HttpClientContext.create();
context.setAttribute(HttpClientSecurityConstants.CONTEXT_KEY_TRUST_ENGINE, trustEngine);
context.setAttribute(HttpClientSecurityConstants.CONTEXT_KEY_CRITERIA_SET, criteriaSet);
response = httpClient.execute(request, context);
<span class="code-comment">// Now can explicitly check the trust eval status post-execute <span class="code-keyword">if</span> desired.
</span><span class="code-comment">// If the credential was untrusted, execute also would have thrown an SSLPeerUnverifiedException
</span><span class="code-comment">// as with the standard Java trust mechanism.
</span><span class="code-object">Boolean</span> serverTLSTrusted = context.getAttribute(
HttpClientSecurityConstants.CONTEXT_KEY_SERVER_TLS_CREDENTIAL_TRUSTED,
<span class="code-object">Boolean</span>.class));
</pre>
</div></div></div>
<div style="color:#505050;padding:4px 0 0 0;"> </div>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td><!-- End #email-page -->
</tr>
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
This message is automatically generated by JIRA.<br />
If you think it was sent incorrectly, please contact your JIRA administrators<br />
For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
</td>
</tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->