All Downloads are FREE. Search and download functionalities are using the official Maven repository.

com.aoindustries.aoserv.master.PkiCertificateHandler Maven / Gradle / Ivy

There is a newer version: 1.91.8
Show newest version
/*
 * aoserv-master - Master server for the AOServ Platform.
 * Copyright (C) 2018, 2019  AO Industries, Inc.
 *     [email protected]
 *     7262 Bull Pen Cir
 *     Mobile, AL 36695
 *
 * This file is part of aoserv-master.
 *
 * aoserv-master is free software: you can redistribute it and/or modify
 * it under the terms of the GNU Lesser General Public License as published by
 * the Free Software Foundation, either version 3 of the License, or
 * (at your option) any later version.
 *
 * aoserv-master is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public License
 * along with aoserv-master.  If not, see .
 */
package com.aoindustries.aoserv.master;

import com.aoindustries.aoserv.client.account.Account;
import com.aoindustries.aoserv.client.master.User;
import com.aoindustries.aoserv.client.pki.Certificate;
import com.aoindustries.aoserv.daemon.client.AOServDaemonConnector;
import com.aoindustries.dbc.DatabaseConnection;
import java.io.IOException;
import java.sql.SQLException;
import java.util.List;

/**
 * @author  AO Industries, Inc.
 */
final public class PkiCertificateHandler {

	private PkiCertificateHandler() {
	}

	public static void checkAccessCertificate(DatabaseConnection conn, RequestSource source, String action, int certificate) throws IOException, SQLException {
		User mu = MasterServer.getUser(conn, source.getCurrentAdministrator());
		if(mu != null) {
			if(MasterServer.getUserHosts(conn, source.getCurrentAdministrator()).length != 0) {
				int linuxServer = getLinuxServerForCertificate(conn, certificate);
				NetHostHandler.checkAccessHost(conn, source, action, linuxServer);
			}
		} else {
			PackageHandler.checkAccessPackage(conn, source, action, getPackageForCertificate(conn, certificate));
		}
	}

	public static Account.Name getPackageForCertificate(DatabaseConnection conn, int certificate) throws IOException, SQLException {
		return conn.executeObjectQuery(ObjectFactories.accountNameFactory,
			"select package from pki.\"Certificate\" where id=?",
			certificate
		);
	}

	public static int getLinuxServerForCertificate(DatabaseConnection conn, int certificate) throws IOException, SQLException {
		return conn.executeIntQuery(
			"select ao_server from pki.\"Certificate\" where id=?",
			certificate
		);
	}

	public static List check(
		DatabaseConnection conn,
		RequestSource source,
		int certificate,
		boolean allowCached
	) throws IOException, SQLException {
		// Check access
		checkAccessCertificate(conn, source, "check", certificate);
		AOServDaemonConnector daemonConnector = DaemonHandler.getDaemonConnector(
			conn,
			getLinuxServerForCertificate(conn, certificate)
		);
		conn.releaseConnection();
		return daemonConnector.checkSslCertificate(certificate, allowCached);
	}
}




© 2015 - 2025 Weber Informatics LLC | Privacy Policy