From dd586a46c9ce5f9790ae097f491b088300603452 Mon Sep 17 00:00:00 2001 From: Chad Brubaker Date: Thu, 10 Dec 2015 18:32:40 -0800 Subject: [PATCH] Check for null hostnames in RootTrustManager Even if the hostname aware method is called if the hostname is null then the destination is unknown and the configuration can be ambiguous. Change-Id: I7cacbd57a42604933fdc882371f143dc0a20902d --- .../android/security/net/config/RootTrustManager.java | 4 ++++ .../android/security/net/config/XmlConfigTests.java | 11 +++++++++++ 2 files changed, 15 insertions(+) diff --git a/core/java/android/security/net/config/RootTrustManager.java b/core/java/android/security/net/config/RootTrustManager.java index e307ad00275ec..b4e58e6e9da6e 100644 --- a/core/java/android/security/net/config/RootTrustManager.java +++ b/core/java/android/security/net/config/RootTrustManager.java @@ -71,6 +71,10 @@ public class RootTrustManager implements X509TrustManager { */ public List checkServerTrusted(X509Certificate[] certs, String authType, String hostname) throws CertificateException { + if (hostname == null && mConfig.hasPerDomainConfigs()) { + throw new CertificateException( + "Domain specific configurations require that the hostname be provided"); + } NetworkSecurityConfig config = mConfig.getConfigForHostname(hostname); return config.getTrustManager().checkServerTrusted(certs, authType, hostname); } diff --git a/tests/NetworkSecurityConfigTest/src/android/security/net/config/XmlConfigTests.java b/tests/NetworkSecurityConfigTest/src/android/security/net/config/XmlConfigTests.java index 998bb681dd24c..35e3ef4c38cc0 100644 --- a/tests/NetworkSecurityConfigTest/src/android/security/net/config/XmlConfigTests.java +++ b/tests/NetworkSecurityConfigTest/src/android/security/net/config/XmlConfigTests.java @@ -22,6 +22,7 @@ import android.test.MoreAsserts; import android.util.ArraySet; import android.util.Pair; import java.io.IOException; +import java.net.InetAddress; import java.net.Socket; import java.net.URL; import java.security.KeyStore; @@ -34,6 +35,7 @@ import java.util.Set; import javax.net.ssl.HttpsURLConnection; import javax.net.ssl.SSLContext; import javax.net.ssl.SSLHandshakeException; +import javax.net.ssl.SSLSocket; import javax.net.ssl.TrustManager; import javax.net.ssl.TrustManagerFactory; @@ -103,6 +105,15 @@ public class XmlConfigTests extends AndroidTestCase { TestUtils.assertConnectionFails(context, "developer.android.com", 443); TestUtils.assertUrlConnectionFails(context, "google.com", 443); TestUtils.assertUrlConnectionSucceeds(context, "android.com", 443); + // Check that sockets created without the hostname fail with per-domain configs + SSLSocket socket = (SSLSocket) context.getSocketFactory() + .createSocket(InetAddress.getByName("android.com"), 443); + try { + socket.startHandshake(); + socket.getInputStream(); + fail(); + } catch (IOException expected) { + } } public void testBasicPinning() throws Exception {