Skip to content

Commit 3e58161

Browse files
committed
test: reject expired mTLS client certificates
1 parent aeb4398 commit 3e58161

1 file changed

Lines changed: 28 additions & 0 deletions

File tree

‎server/src/test/java/org/cloudfoundry/identity/uaa/oauth/tls/TlsClientAuthenticationTest.java‎

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -190,6 +190,23 @@ void validateClientCertSucceedsWhenChainOmitsTrustAnchor() throws Exception {
190190
assertThat(result).contains(leafCert);
191191
}
192192

193+
@Test
194+
void validateClientCertRejectsExpiredLeafCertificate() throws Exception {
195+
KeyPair rootKp = generateKeyPair();
196+
X500Name rootName = new X500Name("CN=Test Root CA");
197+
X509Certificate rootCert = signCert(rootName, rootName, rootKp.getPublic(), rootKp.getPrivate(), true, BigInteger.ONE);
198+
199+
KeyPair leafKp = generateKeyPair();
200+
X509Certificate expiredLeafCert = signCertWithValidity(
201+
new X500Name("CN=expired-leaf-instance"), rootName, leafKp.getPublic(), rootKp.getPrivate(), false,
202+
BigInteger.TWO, new Date(System.currentTimeMillis() - 7_200_000), new Date(System.currentTimeMillis() - 3_600_000));
203+
204+
TlsClientAuthConfiguration config = new TlsClientAuthConfiguration(toPem(rootCert), null);
205+
206+
assertThatThrownBy(() -> service.validateClientCert(new X509Certificate[]{expiredLeafCert}, config))
207+
.hasMessageContaining("tls_client_auth");
208+
}
209+
193210
@Test
194211
void validateClientCertSucceedsWhenChainIncludesTrustAnchor() throws Exception {
195212
// Reproduces the reviewer's concern (PR #3972 discussion on TlsClientAuthentication.java:113):
@@ -805,6 +822,17 @@ private static X509Certificate signCert(X500Name subject, X500Name issuer, Publi
805822
Integer keyUsageBits, List<KeyPurposeId> ekuPurposes) throws Exception {
806823
Date notBefore = new Date(System.currentTimeMillis() - 60_000);
807824
Date notAfter = new Date(System.currentTimeMillis() + 3_600_000);
825+
return signCertWithValidity(subject, issuer, subjectKey, signerKey, isCa, serial, notBefore, notAfter, keyUsageBits, ekuPurposes);
826+
}
827+
828+
private static X509Certificate signCertWithValidity(X500Name subject, X500Name issuer, PublicKey subjectKey,
829+
PrivateKey signerKey, boolean isCa, BigInteger serial, Date notBefore, Date notAfter) throws Exception {
830+
return signCertWithValidity(subject, issuer, subjectKey, signerKey, isCa, serial, notBefore, notAfter, null, null);
831+
}
832+
833+
private static X509Certificate signCertWithValidity(X500Name subject, X500Name issuer, PublicKey subjectKey,
834+
PrivateKey signerKey, boolean isCa, BigInteger serial, Date notBefore, Date notAfter,
835+
Integer keyUsageBits, List<KeyPurposeId> ekuPurposes) throws Exception {
808836
JcaX509v3CertificateBuilder builder = new JcaX509v3CertificateBuilder(
809837
issuer, serial, notBefore, notAfter, subject, subjectKey);
810838
builder.addExtension(Extension.basicConstraints, true, new BasicConstraints(isCa));

0 commit comments

Comments
 (0)