Make ConscryptEngineSocket call correct methods (#643)

ConscryptEngineSocket uses an SSLEngine internally to function, and
that naturally calls the SSLEngine-accepting methods on
X509ExtendedTrustManager to do trust checks.  We were passing our
given trust manager directly to the SSLEngine, which resulted in an
SSLSocket implementation that ended up calling SSLEngine-based
methods, which isn't right.

Instead, create a delegating trust manager that maps the calls to the
correct objects.  On platforms where X509ExtendedTrustManager isn't
available, we can pass in the provided trust manager directly, since
it doesn't receive a reference to the calling object.

Also adds tests for getHandshakeSession() that ensure it functions in
the middle of the handshake and provides properties that should be
set.
9 files changed
tree: c16e5875b1d16627a7cf8f6ccc3abb09e6376c54
  1. android/
  2. android-stub/
  3. api-doclet/
  4. benchmark-android/
  5. benchmark-base/
  6. benchmark-graphs/
  7. benchmark-jmh/
  8. common/
  9. constants/
  10. gradle/
  11. libcore-stub/
  12. licenses/
  13. openjdk/
  14. openjdk-integ-tests/
  15. openjdk-uber/
  16. platform/
  17. release/
  18. testing/
  19. .clang-format
  20. .gitignore
  21. .travis.yml
  22. appveyor.yml
  23. build.gradle
  24. BUILDING.md
  25. CAPABILITIES.md
  26. CONTRIBUTING.md
  27. CPPLINT.cfg
  28. gradlew
  29. gradlew.bat
  30. LICENSE
  31. MODULE_LICENSE_APACHE2
  32. NOTICE
  33. PREUPLOAD.cfg
  34. README.md
  35. settings.gradle
  36. test_logging.properties
README.md

Conscrypt - A Java Security Provider

Conscrypt is a Java Security Provider (JSP) that implements parts of the Java Cryptography Extension (JCE) and Java Secure Socket Extension (JSSE). It uses BoringSSL to provide cryptographic primitives and Transport Layer Security (TLS) for Java applications on Android and OpenJDK. See the capabilities documentation for detailed information on what is provided.

The core SSL engine has borrowed liberally from the Netty project and their work on netty-tcnative, giving Conscrypt similar performance.

Download

Conscrypt supports Java 7 or later on OpenJDK and Gingerbread (API Level 9) or later on Android. The build artifacts are available on Maven Central.

Download JARs

You can download the JARs directly from the Maven repositories.

OpenJDK (i.e. non-Android)

Native Classifiers

The OpenJDK artifacts are platform-dependent since each embeds a native library for a particular platform. We publish artifacts to Maven Central for the following platforms:

ClassifierOSArchitecture
linux-x86_64Linuxx86_64 (64-bit)
osx-x86_64Macx86_64 (64-bit)
windows-x86Windowsx86 (32-bit)
windows-x86_64Windowsx86_64 (64-bit)

Maven

Use the os-maven-plugin to add the dependency:

<build>
  <extensions>
    <extension>
      <groupId>kr.motd.maven</groupId>
      <artifactId>os-maven-plugin</artifactId>
      <version>1.4.1.Final</version>
    </extension>
  </extensions>
</build>

<dependency>
  <groupId>org.conscrypt</groupId>
  <artifactId>conscrypt-openjdk</artifactId>
  <version>2.0.0</version>
  <classifier>${os.detected.classifier}</classifier>
</dependency>

Gradle

Use the osdetector-gradle-plugin (which is a wrapper around the os-maven-plugin) to add the dependency:

buildscript {
  repositories {
    mavenCentral()
  }
  dependencies {
    classpath 'com.google.gradle:osdetector-gradle-plugin:1.4.0'
  }
}

// Use the osdetector-gradle-plugin
apply plugin: "com.google.osdetector"

dependencies {
  compile 'org.conscrypt:conscrypt-openjdk:2.0.0:' + osdetector.classifier
}

Uber JAR

For convenience, we also publish an Uber JAR to Maven Central that contains the shared libraries for all of the published platforms. While the overall size of the JAR is larger than depending on a platform-specific artifact, it greatly simplifies the task of dependency management for most platforms.

To depend on the uber jar, simply use the conscrypt-openjdk-uber artifacts.

Maven
<dependency>
  <groupId>org.conscrypt</groupId>
  <artifactId>conscrypt-openjdk-uber</artifactId>
  <version>2.0.0</version>
</dependency>
Gradle
dependencies {
  compile 'org.conscrypt:conscrypt-openjdk-uber:2.0.0'
}

Android

The Android AAR file contains native libraries for x86, x86_64, armeabi-v7a, and arm64-v8a.

Gradle

dependencies {
  compile 'org.conscrypt:conscrypt-android:2.0.0'
}

How to Build

If you are making changes to Conscrypt, see the building instructions.