From e333af0c8fbb8d69d79f420de01ce39dcade5930 Mon Sep 17 00:00:00 2001
From: Valery Kharseko <vharseko@3a-systems.ru>
Date: Thu, 24 Sep 2026 08:06:21 +0000
Subject: [PATCH] Keep PKCS5S2 usable on a FIPS-restricted JCE, and name the key wrapping property when the runtime has no RSA-OAEP (#1058)
---
opendj-server-legacy/src/test/java/org/opends/server/crypto/CryptoManagerTestCase.java | 58 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
1 files changed, 58 insertions(+), 0 deletions(-)
diff --git a/opendj-server-legacy/src/test/java/org/opends/server/crypto/CryptoManagerTestCase.java b/opendj-server-legacy/src/test/java/org/opends/server/crypto/CryptoManagerTestCase.java
index 37537a7..0642f4c 100644
--- a/opendj-server-legacy/src/test/java/org/opends/server/crypto/CryptoManagerTestCase.java
+++ b/opendj-server-legacy/src/test/java/org/opends/server/crypto/CryptoManagerTestCase.java
@@ -39,7 +39,10 @@
import java.nio.file.Files;
import java.nio.file.Path;
import java.security.MessageDigest;
+import java.security.Provider;
+import java.util.ArrayList;
import java.util.Arrays;
+import java.util.List;
import java.util.TreeSet;
import java.util.UUID;
@@ -298,6 +301,61 @@
}
/**
+ A key wrapping transformation this Java runtime cannot provide is refused, at start (where
+ the refusal is what keeps the server from starting) as on a change, and the refusal has to
+ name the property to set, not only the cipher which failed: on a FIPS-restricted runtime
+ without RSA-OAEP that is all the administrator has to go on.
+ */
+ @Test
+ public void testUnsupportedKeyWrappingTransformationIsRefusedNamingTheProperty() throws Exception
+ {
+ final CryptoManagerImpl cm = DirectoryServer.getCryptoManager();
+ final CryptoManagerCfg cfg = getServerContext().getRootConfig().getCryptoManager();
+ final String unsupported = "RSA/ECB/NoSuchPadding";
+ final List<LocalizableMessage> why = new ArrayList<>();
+
+ final boolean acceptable =
+ cm.isConfigurationChangeAcceptable(withProperty(cfg, "getKeyWrappingTransformation", unsupported), why);
+
+ assertThat(acceptable).isFalse();
+ assertThat(why).hasSize(1);
+ assertThat(why.get(0).ordinal()).isEqualTo(ERR_CRYPTOMGR_KEY_WRAPPING_TRANSFORMATION_UNSUPPORTED.ordinal());
+ assertThat(why.get(0).toString()).contains(unsupported).contains("key-wrapping-transformation");
+ }
+
+ /**
+ A transformation the runtime provides, refused because of the rest of the check (here the
+ MD5 digest of the instance key identifier), is not reported as a matter of the property:
+ changing key-wrapping-transformation would not help.
+ */
+ @Test
+ public void testKeyWrappingRefusalForAnotherCauseDoesNotNameTheProperty() throws Exception
+ {
+ final CryptoManagerImpl cm = DirectoryServer.getCryptoManager();
+ final CryptoManagerCfg cfg = getServerContext().getRootConfig().getCryptoManager();
+ final String supported = "RSA/ECB/OAEPWITHSHA1ANDMGF1PADDING";
+ assertThat(supported).isNotEqualTo(cfg.getKeyWrappingTransformation());
+ final List<LocalizableMessage> why = new ArrayList<>();
+
+ // Withdrawing MD5 withdraws the SUN provider, whose SHA-1 digest the OAEP cipher still needs.
+ final Provider sha1Only = new Provider("Sha1OnlyDigest", "1.0", "SHA-1 digest only") {};
+ sha1Only.put("MessageDigest.SHA-1", "sun.security.provider.SHA");
+ sha1Only.put("Alg.Alias.MessageDigest.SHA1", "SHA-1");
+
+ withoutJceService("MessageDigest", "MD5", () ->
+ {
+ assertThat(cm.isConfigurationChangeAcceptable(withProperty(cfg, "getKeyWrappingTransformation", supported), why))
+ .isFalse();
+ return null;
+ }, sha1Only);
+
+ assertThat(why).hasSize(1);
+ final String reason = why.get(0).toString();
+ assertThat(why.get(0).ordinal()).as(reason).isEqualTo(ERR_CRYPTOMGR_CANNOT_GET_PREFERRED_KEY_WRAPPING_CIPHER.ordinal());
+ assertThat(reason).contains("MD5").doesNotContain("key-wrapping-transformation");
+ }
+
+ /**
Returns the crypto manager configuration as it stands, with the ssl-cert-nickname
property answering the provided nicknames, so that a change to that property is applied
without the configuration of the running server being modified.
--
Gitblit v1.10.0