summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
author Chad Brubaker <cbrubaker@google.com> 2018-04-26 11:20:16 -0700
committer Ecco Park <eccopark@google.com> 2018-04-26 19:33:06 +0000
commit8bfbc6e710d1cc3334f080dbd698d51b6299ba87 (patch)
tree4227926f97773d74b1eff5b2441d93643db4609b
parent0c0739093ba993f7412c344a10a26dcc18ed4ba6 (diff)
Add nsconfig support for WFA CAs
Bug: 78643773 Test: manually verified Change-Id: Ib7d2b24669074b74bbda7ab7163ef25584e95a11
-rw-r--r--core/java/android/security/net/config/WfaCertificateSource.java42
-rw-r--r--core/java/android/security/net/config/XmlConfigSource.java2
2 files changed, 44 insertions, 0 deletions
diff --git a/core/java/android/security/net/config/WfaCertificateSource.java b/core/java/android/security/net/config/WfaCertificateSource.java
new file mode 100644
index 000000000000..f212ef8bf447
--- /dev/null
+++ b/core/java/android/security/net/config/WfaCertificateSource.java
@@ -0,0 +1,42 @@
+/*
+ * Copyright (C) 2018 The Android Open Source Project
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package android.security.net.config;
+
+import java.io.File;
+
+/**
+ * {@link CertificateSource} based on the system WFA CA store.
+ * @hide
+ */
+public final class WfaCertificateSource extends DirectoryCertificateSource {
+ private static class NoPreloadHolder {
+ private static final WfaCertificateSource INSTANCE = new WfaCertificateSource();
+ }
+
+ private WfaCertificateSource() {
+ super(new File(System.getenv("ANDROID_ROOT") + "/etc/security/cacerts_wfa"));
+ }
+
+ public static WfaCertificateSource getInstance() {
+ return NoPreloadHolder.INSTANCE;
+ }
+
+ @Override
+ protected boolean isCertMarkedAsRemoved(String caFile) {
+ return false;
+ }
+}
diff --git a/core/java/android/security/net/config/XmlConfigSource.java b/core/java/android/security/net/config/XmlConfigSource.java
index 02be403ae150..311a8d23b964 100644
--- a/core/java/android/security/net/config/XmlConfigSource.java
+++ b/core/java/android/security/net/config/XmlConfigSource.java
@@ -189,6 +189,8 @@ public class XmlConfigSource implements ConfigSource {
source = SystemCertificateSource.getInstance();
} else if ("user".equals(sourceString)) {
source = UserCertificateSource.getInstance();
+ } else if ("wfa".equals(sourceString)) {
+ source = WfaCertificateSource.getInstance();
} else {
throw new ParserException(parser, "Unknown certificates src. "
+ "Should be one of system|user|@resourceVal");