HttpsURLConnectionTest.javaAPI DocAndroid 1.5 API61422Wed May 06 22:41:04 BST

 *  Licensed to the Apache Software Foundation (ASF) under one or more
 *  contributor license agreements.  See the NOTICE file distributed with
 *  this work for additional information regarding copyright ownership.
 *  The ASF licenses this file to You under the Apache License, Version 2.0
 *  (the "License"); you may not use this file except in compliance with
 *  the License.  You may obtain a copy of the License at
 *  Unless required by applicable law or agreed to in writing, software
 *  distributed under the License is distributed on an "AS IS" BASIS,
 *  WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 *  See the License for the specific language governing permissions and
 *  limitations under the License.


import dalvik.annotation.AndroidOnly;
import dalvik.annotation.KnownFailure;
import dalvik.annotation.TestTargetClass; 
import dalvik.annotation.TestTargets;
import dalvik.annotation.TestLevel;
import dalvik.annotation.TestTargetNew;

import java.util.Arrays;

import junit.framework.TestCase;

 * Implementation independent test for HttpsURLConnection.
 * The test needs certstore file placed in system classpath 
 * and named as "key_store." + the type of the
 * default KeyStore installed in the system in lower case.
 * <br>
 * For example: if default KeyStore type in the system is BKS
 * (i.e. file sets up the property keystore.type=BKS),
 * thus classpath should point to the directory with "key_store.bks"
 * file.
 * <br>
 * This certstore file should contain self-signed certificate
 * generated by keytool utility in a usual way.
 * <br>
 * The password to the certstore should be "password" (without quotes).
public class HttpsURLConnectionTest extends TestCase {

    // the password to the store
    private static final String KS_PASSWORD = "password";

    // turn on/off logging
    private static final boolean DO_LOG = false;

    // read/connection timeout value
    private static final int TIMEOUT = 5000;

    // OK response code
    private static final int OK_CODE = 200;

    // Not Found response code
    private static final int NOT_FOUND_CODE = 404;

    // Proxy authentication required response code
    private static final int AUTHENTICATION_REQUIRED_CODE = 407;

    // fields keeping the system values of corresponding properties
    private static String systemKeyStoreType;

    private static String systemKeyStore;

    private static String systemKeyStorePassword;

    private static String systemTrustStoreType;

    private static String systemTrustStore;

    private static String systemTrustStorePassword;
    private static File store;
    static {
        try {
            store = File.createTempFile("key_store", "bks");
        } catch (Exception e) {
            // ignore

     * Checks that HttpsURLConnection's default SSLSocketFactory is operable.
        level = TestLevel.PARTIAL_COMPLETE,
        notes = "Verifies that HttpsURLConnection's default SSLSocketFactory is operable.",
        method = "getDefaultSSLSocketFactory",
        args = {}
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void testGetDefaultSSLSocketFactory() throws Exception {
        // set up the properties defining the default values needed by SSL stuff

        try {
            SSLSocketFactory defaultSSLSF = HttpsURLConnection
            ServerSocket ss = new ServerSocket(0);
            Socket s = defaultSSLSF
                    .createSocket("localhost", ss.getLocalPort());
        } finally {
            // roll the properties back to system values

     * Checks if HTTPS connection performs initial SSL handshake with the
     * server working over SSL, sends encrypted HTTP request,
     * and receives expected HTTP response. After HTTPS session if finished
     * test checks connection state parameters established by
     * HttpsURLConnection.
        level = TestLevel.PARTIAL_COMPLETE,
        notes = "Verifies  if HTTPS connection performs initial SSL handshake with the server working over SSL, sends encrypted HTTP request, and receives expected HTTP response.",
        method = "setDefaultHostnameVerifier",
        args = {}
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void testHttpsConnection() throws Throwable {
        // set up the properties defining the default values needed by SSL stuff

        try {
            // create the SSL server socket acting as a server
            SSLContext ctx = getContext();
            ServerSocket ss = ctx.getServerSocketFactory()

            // create the HostnameVerifier to check hostname verification
            TestHostnameVerifier hnv = new TestHostnameVerifier();

            // create url connection to be tested
            URL url = new URL("https://localhost:" + ss.getLocalPort());
            HttpsURLConnection connection = (HttpsURLConnection) url

            // perform the interaction between the peers
            SSLSocket peerSocket = (SSLSocket) doInteraction(connection, ss);

            // check the connection state
            checkConnectionStateParameters(connection, peerSocket);

            // should silently exit
        } finally {
            // roll the properties back to system values

     * Tests the behaviour of HTTPS connection in case of unavailability
     * of requested resource.
            level = TestLevel.PARTIAL,
            notes = "Verifies the behaviour of HTTPS connection in case of unavailability of requested resource.",
            method = "setDoInput",
            args = {boolean.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies the behaviour of HTTPS connection in case of unavailability of requested resource.",
            method = "setConnectTimeout",
            args = {int.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies the behaviour of HTTPS connection in case of unavailability of requested resource.",
            method = "setReadTimeout",
            args = {int.class}
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void testHttpsConnection_Not_Found_Response() throws Throwable {
        // set up the properties defining the default values needed by SSL stuff

        try {
            // create the SSL server socket acting as a server
            SSLContext ctx = getContext();
            ServerSocket ss = ctx.getServerSocketFactory()

            // create the HostnameVerifier to check hostname verification
            TestHostnameVerifier hnv = new TestHostnameVerifier();

            // create url connection to be tested
            URL url = new URL("https://localhost:" + ss.getLocalPort());
            HttpsURLConnection connection = (HttpsURLConnection) url

            try {
                doInteraction(connection, ss, NOT_FOUND_CODE);
                fail("Expected exception was not thrown.");
            } catch (FileNotFoundException e) {
                if (DO_LOG) {
                    System.out.println("Expected exception was thrown: "
                            + e.getMessage());

            // should silently exit
        } finally {
            // roll the properties back to system values

     * Tests possibility to set up the default SSLSocketFactory
     * to be used by HttpsURLConnection.
        level = TestLevel.PARTIAL_COMPLETE,
        notes = "Verifies possibility to set up the default SSLSocketFactory to be used by HttpsURLConnection.",
        method = "setDefaultSSLSocketFactory",
        args = {}
    @AndroidOnly("we only have a .bks key store in the test resources")
    @KnownFailure("End to end test fails. No response data is transferred from server to client")
    public void testSetDefaultSSLSocketFactory() throws Throwable {
        // create the SSLServerSocket which will be used by server side
        SSLContext ctx = getContext();
        SSLServerSocket ss = (SSLServerSocket) ctx.getServerSocketFactory()

        SSLSocketFactory socketFactory = (SSLSocketFactory) ctx
        // set up the factory as default
        // check the result
        assertSame("Default SSLSocketFactory differs from expected",
                socketFactory, HttpsURLConnection.getDefaultSSLSocketFactory());

        // create the HostnameVerifier to check hostname verification
        TestHostnameVerifier hnv = new TestHostnameVerifier();

        // create HttpsURLConnection to be tested
        URL url = new URL("https://localhost:" + ss.getLocalPort());
        HttpsURLConnection connection = (HttpsURLConnection) url

        TestHostnameVerifier hnv_late = new TestHostnameVerifier();
        // late initialization: should not be used for created connection

        // perform the interaction between the peers
        SSLSocket peerSocket = (SSLSocket) doInteraction(connection, ss);
        // check the connection state
        checkConnectionStateParameters(connection, peerSocket);
        // check the verification process
        assertTrue("Hostname verification was not done", hnv.verified);
                "Hostname verification should not be done by this verifier",
        // check the used SSLSocketFactory
        assertSame("Default SSLSocketFactory should be used",
                HttpsURLConnection.getDefaultSSLSocketFactory(), connection

        // should silently exit

     * Tests possibility to set up the SSLSocketFactory
     * to be used by HttpsURLConnection.
        level = TestLevel.PARTIAL_COMPLETE,
        notes = "Verifies possibility to set up the SSLSocketFactory to be used by HttpsURLConnection.",
        method = "setSSLSocketFactory",
        args = {}
    @AndroidOnly("we only have a .bks key store in the test resources")
    @KnownFailure("End to end test fails. No response data is transferred from server to client")
    public void testSetSSLSocketFactory() throws Throwable {
        // create the SSLServerSocket which will be used by server side
        SSLContext ctx = getContext();
        SSLServerSocket ss = (SSLServerSocket) ctx.getServerSocketFactory()

        // create the HostnameVerifier to check hostname verification
        TestHostnameVerifier hnv = new TestHostnameVerifier();

        // create HttpsURLConnection to be tested
        URL url = new URL("https://localhost:" + ss.getLocalPort());
        HttpsURLConnection connection = (HttpsURLConnection) url

        SSLSocketFactory socketFactory = (SSLSocketFactory) ctx

        TestHostnameVerifier hnv_late = new TestHostnameVerifier();
        // late initialization: should not be used for created connection

        // perform the interaction between the peers
        SSLSocket peerSocket = (SSLSocket) doInteraction(connection, ss);
        // check the connection state
        checkConnectionStateParameters(connection, peerSocket);
        // check the verification process
        assertTrue("Hostname verification was not done", hnv.verified);
                "Hostname verification should not be done by this verifier",
        // check the used SSLSocketFactory
        assertNotSame("Default SSLSocketFactory should not be used",
                HttpsURLConnection.getDefaultSSLSocketFactory(), connection
        assertSame("Result differs from expected", socketFactory, connection

        // should silently exit

     * Tests the behaviour of HttpsURLConnection in case of retrieving
     * of the connection state parameters before connection has been made.
            level = TestLevel.PARTIAL_COMPLETE,
            notes = "Verifies the behaviour of HttpsURLConnection in case of retrieving of the connection state parameters before connection has been made.",
            method = "getCipherSuite",
            args = {}
            level = TestLevel.PARTIAL_COMPLETE,
            notes = "Verifies the behaviour of HttpsURLConnection in case of retrieving of the connection state parameters before connection has been made.",
            method = "getPeerPrincipal",
            args = {}
            level = TestLevel.PARTIAL_COMPLETE,
            notes = "Verifies the behaviour of HttpsURLConnection in case of retrieving of the connection state parameters before connection has been made.",
            method = "getLocalPrincipal",
            args = {}
            level = TestLevel.PARTIAL_COMPLETE,
            notes = "Verifies the behaviour of HttpsURLConnection in case of retrieving of the connection state parameters before connection has been made.",
            method = "getServerCertificates",
            args = {}
            level = TestLevel.PARTIAL_COMPLETE,
            notes = "Verifies the behaviour of HttpsURLConnection in case of retrieving of the connection state parameters before connection has been made.",
            method = "getLocalCertificates",
            args = {}
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void testUnconnectedStateParameters() throws Throwable {
        // create HttpsURLConnection to be tested
        URL url = new URL("https://localhost:55555");
        HttpsURLConnection connection = (HttpsURLConnection) url

        try {
            fail("Expected IllegalStateException was not thrown");
        } catch (IllegalStateException e) {}
        try {
            fail("Expected IllegalStateException was not thrown");
        } catch (IllegalStateException e) {}
        try {
            fail("Expected IllegalStateException was not thrown");
        } catch (IllegalStateException e) {}

        try {
            fail("Expected IllegalStateException was not thrown");
        } catch (IllegalStateException e) {}
        try {
            fail("Expected IllegalStateException was not thrown");
        } catch (IllegalStateException e) {}

     * Tests if setHostnameVerifier() method replaces default verifier.
        level = TestLevel.PARTIAL_COMPLETE,
        notes = "Verifies if setHostnameVerifier() method replaces default verifier.",
        method = "setHostnameVerifier",
        args = {}
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void testSetHostnameVerifier() throws Throwable {
        // setting up the properties pointing to the key/trust stores

        try {
            // create the SSLServerSocket which will be used by server side
            SSLServerSocket ss = (SSLServerSocket) getContext()

            // create the HostnameVerifier to check that Hostname verification
            // is done
            TestHostnameVerifier hnv = new TestHostnameVerifier();

            // create HttpsURLConnection to be tested
            URL url = new URL("https://localhost:" + ss.getLocalPort());
            HttpsURLConnection connection = (HttpsURLConnection) url

            TestHostnameVerifier hnv_late = new TestHostnameVerifier();
            // replace default verifier

            // perform the interaction between the peers and check the results
            SSLSocket peerSocket = (SSLSocket) doInteraction(connection, ss);
            assertTrue("Hostname verification was not done", hnv_late.verified);
                    "Hostname verification should not be done by this verifier",
            checkConnectionStateParameters(connection, peerSocket);

            // should silently exit
        } finally {
            // roll the properties back to system values

     * Tests the behaviour in case of sending the data to the server.
        level = TestLevel.PARTIAL,
        notes = "Verifies the behaviour in case of sending the data to the server.",
        method = "setDoOutput",
        args = {boolean.class}
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void test_doOutput() throws Throwable {
        // setting up the properties pointing to the key/trust stores

        try {
            // create the SSLServerSocket which will be used by server side
            SSLServerSocket ss = (SSLServerSocket) getContext()

            // create the HostnameVerifier to check that Hostname verification
            // is done
            TestHostnameVerifier hnv = new TestHostnameVerifier();

            // create HttpsURLConnection to be tested
            URL url = new URL("https://localhost:" + ss.getLocalPort());
            HttpsURLConnection connection = (HttpsURLConnection) url

            // perform the interaction between the peers and check the results
            SSLSocket peerSocket = (SSLSocket) doInteraction(connection, ss);
            checkConnectionStateParameters(connection, peerSocket);

            // should silently exit
        } finally {
            // roll the properties back to system values

     * Tests HTTPS connection process made through the proxy server.
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server.",
            method = "setDoInput",
            args = {boolean.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server.",
            method = "setConnectTimeout",
            args = {int.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server.",
            method = "setReadTimeout",
            args = {int.class}
    @KnownFailure("Handshake fails.")
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void testProxyConnection() throws Throwable {
        // setting up the properties pointing to the key/trust stores

        try {
            // create the SSLServerSocket which will be used by server side
            ServerSocket ss = new ServerSocket(0);

            // create the HostnameVerifier to check that Hostname verification
            // is done
            TestHostnameVerifier hnv = new TestHostnameVerifier();

            // create HttpsURLConnection to be tested
            URL url = new URL("");
            HttpsURLConnection connection = (HttpsURLConnection) url
                    .openConnection(new Proxy(Proxy.Type.HTTP,
                            new InetSocketAddress("localhost", ss

            // perform the interaction between the peers and check the results
            SSLSocket peerSocket = (SSLSocket) doInteraction(connection, ss);
            checkConnectionStateParameters(connection, peerSocket);

            // should silently exit
        } finally {
            // roll the properties back to system values

     * Tests HTTPS connection process made through the proxy server.
     * Proxy server needs authentication.
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server. Proxy server needs authentication.",
            method = "setDoInput",
            args = {boolean.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server. Proxy server needs authentication.",
            method = "setConnectTimeout",
            args = {int.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server. Proxy server needs authentication.",
            method = "setReadTimeout",
            args = {int.class}
    @KnownFailure("Handshake fails.")
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void testProxyAuthConnection() throws Throwable {
        // setting up the properties pointing to the key/trust stores

        try {
            // create the SSLServerSocket which will be used by server side
            ServerSocket ss = new ServerSocket(0);

            // create the HostnameVerifier to check that Hostname verification
            // is done
            TestHostnameVerifier hnv = new TestHostnameVerifier();

            Authenticator.setDefault(new Authenticator() {

                protected PasswordAuthentication getPasswordAuthentication() {
                    return new PasswordAuthentication("user", "password"

            // create HttpsURLConnection to be tested
            URL url = new URL("");
            HttpsURLConnection connection = (HttpsURLConnection) url
                    .openConnection(new Proxy(Proxy.Type.HTTP,
                            new InetSocketAddress("localhost", ss

            // perform the interaction between the peers and check the results
            SSLSocket peerSocket = (SSLSocket) doInteraction(connection, ss);
            checkConnectionStateParameters(connection, peerSocket);

            // should silently exit
        } finally {
            // roll the properties back to system values

     * Tests HTTPS connection process made through the proxy server.
     * 2 HTTPS connections are opened for one URL. For the first time
     * the connection is opened through one proxy,
     * for the second time through another.
            level = TestLevel.PARTIAL_COMPLETE,
            notes = "Verifies HTTPS connection process made through the proxy server.",
            method = "getCipherSuite",
            args = {}
            level = TestLevel.PARTIAL_COMPLETE,
            notes = "Verifies HTTPS connection process made through the proxy server.",
            method = "getLocalPrincipal",
            args = {}
            level = TestLevel.PARTIAL_COMPLETE,
            notes = "Verifies HTTPS connection process made through the proxy server.",
            method = "getPeerPrincipal",
            args = {}
    @KnownFailure("Handshake fails.")
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void testConsequentProxyConnection() throws Throwable {
        // setting up the properties pointing to the key/trust stores

        try {
            // create the SSLServerSocket which will be used by server side
            ServerSocket ss = new ServerSocket(0);

            // create the HostnameVerifier to check that Hostname verification
            // is done
            TestHostnameVerifier hnv = new TestHostnameVerifier();

            // create HttpsURLConnection to be tested
            URL url = new URL("");
            HttpsURLConnection connection = (HttpsURLConnection) url
                    .openConnection(new Proxy(Proxy.Type.HTTP,
                            new InetSocketAddress("localhost", ss

            // perform the interaction between the peers and check the results
            SSLSocket peerSocket = (SSLSocket) doInteraction(connection, ss);
            checkConnectionStateParameters(connection, peerSocket);

            // create another SSLServerSocket which will be used by server side
            ss = new ServerSocket(0);

            connection = (HttpsURLConnection) url.openConnection(new Proxy(
                    Proxy.Type.HTTP, new InetSocketAddress("localhost", ss

            // perform the interaction between the peers and check the results
            peerSocket = (SSLSocket) doInteraction(connection, ss);
            checkConnectionStateParameters(connection, peerSocket);
        } finally {
            // roll the properties back to system values

     * Tests HTTPS connection process made through the proxy server.
     * Proxy server needs authentication.
     * Client sends data to the server.
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server. Proxy server needs authentication. Client sends data to the server.",
            method = "setDoInput",
            args = {boolean.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server. Proxy server needs authentication. Client sends data to the server.",
            method = "setConnectTimeout",
            args = {int.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server. Proxy server needs authentication. Client sends data to the server.",
            method = "setReadTimeout",
            args = {int.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server. Proxy server needs authentication. Client sends data to the server.",
            method = "setDoOutput",
            args = {boolean.class}
    @KnownFailure("Handshake fails.")
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void testProxyAuthConnection_doOutput() throws Throwable {
        // setting up the properties pointing to the key/trust stores

        try {
            // create the SSLServerSocket which will be used by server side
            ServerSocket ss = new ServerSocket(0);

            // create the HostnameVerifier to check that Hostname verification
            // is done
            TestHostnameVerifier hnv = new TestHostnameVerifier();

            Authenticator.setDefault(new Authenticator() {

                protected PasswordAuthentication getPasswordAuthentication() {
                    return new PasswordAuthentication("user", "password"

            // create HttpsURLConnection to be tested
            URL url = new URL("");
            HttpsURLConnection connection = (HttpsURLConnection) url
                    .openConnection(new Proxy(Proxy.Type.HTTP,
                            new InetSocketAddress("localhost", ss

            // perform the interaction between the peers and check the results
            SSLSocket peerSocket = (SSLSocket) doInteraction(connection, ss,
                    OK_CODE, true);
            checkConnectionStateParameters(connection, peerSocket);
        } finally {
            // roll the properties back to system values

     * Tests HTTPS connection process made through the proxy server.
     * Proxy server needs authentication but client fails to authenticate
     * (Authenticator was not set up in the system).
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server. Proxy server needs authentication but client fails to authenticate (Authenticator was not set up in the system).",
            method = "setDoInput",
            args = {boolean.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server. Proxy server needs authentication but client fails to authenticate (Authenticator was not set up in the system).",
            method = "setConnectTimeout",
            args = {int.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies HTTPS connection process made through the proxy server. Proxy server needs authentication but client fails to authenticate (Authenticator was not set up in the system).",
            method = "setReadTimeout",
            args = {int.class}
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void testProxyAuthConnectionFailed() throws Throwable {
        // setting up the properties pointing to the key/trust stores

        try {
            // create the SSLServerSocket which will be used by server side
            ServerSocket ss = new ServerSocket(0);

            // create the HostnameVerifier to check that Hostname verification
            // is done
            TestHostnameVerifier hnv = new TestHostnameVerifier();

            // create HttpsURLConnection to be tested
            URL url = new URL("");
            HttpURLConnection connection = (HttpURLConnection) url
                    .openConnection(new Proxy(Proxy.Type.HTTP,
                            new InetSocketAddress("localhost", ss

            // perform the interaction between the peers and check the results
            try {
                doInteraction(connection, ss, AUTHENTICATION_REQUIRED_CODE,
            } catch (IOException e) {
                // SSL Tunnelling failed
                if (DO_LOG) {
                    System.out.println("Got expected IOException: "
                            + e.getMessage());
        } finally {
            // roll the properties back to system values

     * Tests the behaviour of HTTPS connection in case of unavailability
     * of requested resource.
            level = TestLevel.PARTIAL,
            notes = "Verifies the behaviour of HTTPS connection in case of unavailability of requested resource.",
            method = "setDoInput",
            args = {boolean.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies the behaviour of HTTPS connection in case of unavailability of requested resource.",
            method = "setConnectTimeout",
            args = {int.class}
            level = TestLevel.PARTIAL,
            notes = "Verifies the behaviour of HTTPS connection in case of unavailability of requested resource.",
            method = "setReadTimeout",
            args = {int.class}
    @KnownFailure("Handshake fails.")
    @AndroidOnly("we only have a .bks key store in the test resources")
    public void testProxyConnection_Not_Found_Response() throws Throwable {
        // setting up the properties pointing to the key/trust stores

        try {
            // create the SSLServerSocket which will be used by server side
            ServerSocket ss = new ServerSocket(0);

            // create the HostnameVerifier to check that Hostname verification
            // is done
            TestHostnameVerifier hnv = new TestHostnameVerifier();

            // create HttpsURLConnection to be tested
            URL url = new URL("https://localhost:" + ss.getLocalPort());
            HttpURLConnection connection = (HttpURLConnection) url
                    .openConnection(new Proxy(Proxy.Type.HTTP,
                            new InetSocketAddress("localhost", ss

            try {
                doInteraction(connection, ss, NOT_FOUND_CODE); // NOT FOUND
                fail("Expected exception was not thrown.");
            } catch (FileNotFoundException e) {
                if (DO_LOG) {
                    System.out.println("Expected exception was thrown: "
                            + e.getMessage());
        } finally {
            // roll the properties back to system values

    // ---------------------------------------------------------------------
    // ------------------------ Staff Methods ------------------------------
    // ---------------------------------------------------------------------

     * Log the name of the test case to be executed.
    public void setUp() throws Exception {
        if (DO_LOG) {
            System.out.println("------ " + getName());
        if (store != null) {
            String ksFileName = "org/apache/harmony/luni/tests/key_store."
                    + KeyStore.getDefaultType().toLowerCase();
            InputStream in = getClass().getClassLoader()
            FileOutputStream out = new FileOutputStream(store);
            BufferedInputStream bufIn = new BufferedInputStream(in, 8192);
            while (bufIn.available() > 0) {
                byte[] buf = new byte[128];
                int read =;
                out.write(buf, 0, read);
        } else {
            fail("couldn't set up key store");

    public void tearDown() {
        if (store != null) {
     * Checks the HttpsURLConnection getter's values and compares
     * them with actual corresponding values of remote peer.
    public static void checkConnectionStateParameters(
            HttpsURLConnection clientConnection, SSLSocket serverPeer)
            throws Exception {
        SSLSession session = serverPeer.getSession();

        assertEquals(session.getCipherSuite(), clientConnection

        assertEquals(session.getLocalPrincipal(), clientConnection

        assertEquals(session.getPeerPrincipal(), clientConnection

        Certificate[] serverCertificates = clientConnection
        Certificate[] localCertificates = session.getLocalCertificates();
        assertTrue("Server certificates differ from expected", Arrays.equals(
                serverCertificates, localCertificates));

        localCertificates = clientConnection.getLocalCertificates();
        serverCertificates = session.getPeerCertificates();
        assertTrue("Local certificates differ from expected", Arrays.equals(
                serverCertificates, localCertificates));

     * Returns the file name of the key/trust store. The key store file 
     * (named as "key_store." + extension equals to the default KeyStore
     * type installed in the system in lower case) is searched in classpath.
     * @throws AssertionFailedError if property was not set 
     * or file does not exist.
    private static String getKeyStoreFileName() {
        return store.getAbsolutePath();

     * Builds and returns the context used for secure socket creation.
    private static SSLContext getContext() throws Exception {
        String type = KeyStore.getDefaultType();
        SSLContext ctx;

        String keyStore = getKeyStoreFileName();
        File keyStoreFile = new File(keyStore);

        FileInputStream fis = new FileInputStream(keyStoreFile);

        KeyStore ks = KeyStore.getInstance(type);
        ks.load(fis, KS_PASSWORD.toCharArray());

        KeyManagerFactory kmf = KeyManagerFactory.getInstance(KeyManagerFactory
        kmf.init(ks, KS_PASSWORD.toCharArray());

        TrustManagerFactory tmf = TrustManagerFactory

        ctx = SSLContext.getInstance("TLSv1");
        ctx.init(kmf.getKeyManagers(), tmf.getTrustManagers(), null);

        return ctx;

     * Sets up the properties pointing to the key store and trust store
     * and used as default values by JSSE staff. This is needed to test
     * HTTPS behaviour in the case of default SSL Socket Factories.
    private static void setUpStoreProperties() throws Exception {
        String type = KeyStore.getDefaultType();

        systemKeyStoreType = System.getProperty("");
        systemKeyStore = System.getProperty("");
        systemKeyStorePassword = System

        systemTrustStoreType = System
        systemTrustStore = System.getProperty("");
        systemTrustStorePassword = System

        System.setProperty("", type);
        System.setProperty("", getKeyStoreFileName());
        System.setProperty("", KS_PASSWORD);

        System.setProperty("", type);
        System.setProperty("", getKeyStoreFileName());
        System.setProperty("", KS_PASSWORD);

     * Rolls back the values of system properties.
    private static void tearDownStoreProperties() {
        if (systemKeyStoreType == null) {
        } else {
        if (systemKeyStore == null) {
        } else {
            System.setProperty("", systemKeyStore);
        if (systemKeyStorePassword == null) {
        } else {

        if (systemTrustStoreType == null) {
        } else {
        if (systemTrustStore == null) {
        } else {
            System.setProperty("", systemTrustStore);
        if (systemTrustStorePassword == null) {
        } else {

     * Performs interaction between client's HttpURLConnection and
     * servers side (ServerSocket).
    public static Socket doInteraction(
            final HttpURLConnection clientConnection,
            final ServerSocket serverSocket) throws Throwable {
        return doInteraction(clientConnection, serverSocket, OK_CODE, false);

     * Performs interaction between client's HttpURLConnection and
     * servers side (ServerSocket). Server will response with specified
     * response code.
    public static Socket doInteraction(
            final HttpURLConnection clientConnection,
            final ServerSocket serverSocket, final int responseCode)
            throws Throwable {
        return doInteraction(clientConnection, serverSocket, responseCode,

     * Performs interaction between client's HttpURLConnection and
     * servers side (ServerSocket). Server will response with specified
     * response code.
     * @param doAuthentication specifies 
     * if the server needs client authentication.
    public static Socket doInteraction(
            final HttpURLConnection clientConnection,
            final ServerSocket serverSocket, final int responseCode,
            final boolean doAuthentication) throws Throwable {

        // set up the connection

        ServerWork server = new ServerWork(serverSocket, responseCode,

        ClientConnectionWork client = new ClientConnectionWork(clientConnection);



        if (client.thrown != null) {
            if (responseCode != OK_CODE) { // not OK response expected
                // it is probably expected exception, keep it as is
                throw client.thrown;
            if ((client.thrown instanceof SocketTimeoutException)
                    && (server.thrown != null)) {
                // server's exception is more informative in this case
                throw new Exception(server.thrown);
            } else {
                throw new Exception(client.thrown);
        if (server.thrown != null) {
            throw server.thrown;
        return server.peerSocket;

     * The host name verifier used in test.
    static class TestHostnameVerifier implements HostnameVerifier {

        boolean verified = false;

        public boolean verify(String hostname, SSLSession session) {
            if (DO_LOG) {
                System.out.println("***> verification " + hostname + " "
                        + session.getPeerHost());
            verified = true;
            return true;

     * The base class for mock Client and Server.
    static class Work extends Thread {

         * The header of OK HTTP response.
        static final String responseHead = "HTTP/1.1 200 OK\n";

         * The content of the response.
        static final String plainResponseContent = "<HTML>\n"
                + "<HEAD><TITLE>Plain Response Content</TITLE></HEAD>\n"
                + "</HTML>";

         * The tail of the response.
        static final String plainResponseTail = "Content-type: text/html\n"
                + "Content-length: " + plainResponseContent.length() + "\n\n"
                + plainResponseContent;

         * The response message to be sent in plain (HTTP) format.
        static final String plainResponse = responseHead + plainResponseTail;

         * The content of the response to be sent during HTTPS session.
        static final String httpsResponseContent = "<HTML>\n"
                + "<HEAD><TITLE>HTTPS Response Content</TITLE></HEAD>\n"
                + "</HTML>";

         * The tail of the response to be sent during HTTPS session.
        static final String httpsResponseTail = "Content-type: text/html\n"
                + "Content-length: " + httpsResponseContent.length() + "\n\n"
                + httpsResponseContent;

         * The response requiring client's proxy authentication.
        static final String respAuthenticationRequired = "HTTP/1.0 407 Proxy authentication required\n"
                + "Proxy-authenticate: Basic realm=\"localhost\"\n\n";

         * The data to be posted by client to the server.
        static final String clientsData = "_.-^ Client's Data ^-._";

         * The exception thrown during peers interaction.
        protected Throwable thrown;

         * The print stream used for debug log.
         * If it is null debug info will not be printed.
        private PrintStream out = new PrintStream(System.out);

         * Prints log message.
        public synchronized void log(String message) {
            if (DO_LOG && (out != null)) {
                System.out.println("[" + getName() + "]: " + message);

     * The class used for server side works.
    static class ServerWork extends Work {

        // the server socket used for connection
        private ServerSocket serverSocket;

        // the socket connected with client peer
        private Socket peerSocket;

        // indicates if the server acts as proxy server
        private boolean actAsProxy;

        // indicates if the server needs proxy authentication
        private boolean needProxyAuthentication;

        // response code to be send to the client peer
        private int responseCode;

         * Creates the thread acting as a server side.
        public ServerWork(ServerSocket serverSocket) {
            // the server does not require proxy authentication
            // and sends OK_CODE (OK) response code
            this(serverSocket, OK_CODE, false);

         * Creates the thread acting as a server side.
         * @param serverSocket the server socket to be used during connection
         * @param responseCode the response code to be sent to the client
         * @param needProxyAuthentication
         * indicates if the server needs proxy authentication
        public ServerWork(ServerSocket serverSocket, int responseCode,
                boolean needProxyAuthentication) {
            this.serverSocket = serverSocket;
            this.responseCode = responseCode;
            this.needProxyAuthentication = needProxyAuthentication;
            // will act as a proxy server if the specified server socket
            // is not a secure server socket
            if (serverSocket instanceof SSLServerSocket) {
                // demand client to send its certificate
                ((SSLServerSocket) serverSocket).setNeedClientAuth(true);
                // work as a HTTPS server, not as HTTP proxy
                this.actAsProxy = false;
            } else {
                this.actAsProxy = true;
            this.actAsProxy = !(serverSocket instanceof SSLServerSocket);
            setName(this.actAsProxy ? "Proxy Server" : "Server");

         * Closes the connection.
        public void closeSocket(Socket socket) {
            try {
            } catch (IOException e) {}
            try {
            } catch (IOException e) {}
            try {
            } catch (IOException e) {}

         * Performs the actual server work.
         * If some exception occurs during the work it will be
         * stored in the <code>thrown</code> field.
        public void run() {
            // the buffer used for reading the messages
            byte[] buff = new byte[2048];
            // the number of bytes read into the buffer
            int num;
            try {
                // configure the server socket to avoid blocking
                // accept client connection
                peerSocket = serverSocket.accept();
                // configure the client connection to avoid blocking
                log("Client connection ACCEPTED");

                InputStream is = peerSocket.getInputStream();
                OutputStream os = peerSocket.getOutputStream();

                num =;
                String message = new String(buff, 0, num);
                log("Got request:\n" + message);

                if (!actAsProxy) {
                    // Act as Server (not Proxy) side
                    if (message.startsWith("POST")) {
                        // client connection sent some data
                        log("try to read client data");
                        num =;
                        message = new String(buff, 0, num);
                        log("client's data: '" + message + "'");
                        // check the received data
                        assertEquals(clientsData, message);
                    // just send the response
                            .write(("HTTP/1.1 " + responseCode + "\n" + httpsResponseTail)
                    // and return
                    log("Work is DONE !actAsProxy");

                // Do proxy work
                if (needProxyAuthentication) {
                    log("Authentication required ...");
                    // send Authentication Request
                    // read response
                    num =;
                    if (num == -1) {
                        // this connection was closed, 
                        // do clean up and create new one:
                        peerSocket = serverSocket.accept();
                        log("New client connection ACCEPTED");
                        is = peerSocket.getInputStream();
                        os = peerSocket.getOutputStream();
                        num =;
                    message = new String(buff, 0, num);
                    log("Got authenticated request:\n" + message);
                    // check provided authorization credentials
                    assertTrue("Received message does not contain "
                            + "authorization credentials", message
                            .toLowerCase().indexOf("proxy-authorization:") > 0);

                // The content of this response will reach proxied HTTPUC
                // but will not reach proxied HTTPSUC
                // In case of HTTP connection it will be the final message,
                // in case of HTTPS connection this message will just indicate
                // that connection with remote host has been done
                // (i.e. SSL tunnel has been established).
                log("Sent OK RESPONSE");

                if (message.startsWith("CONNECT")) { // request for SSL tunnel
                    log("Perform SSL Handshake...");
                    // create sslSocket acting as a remote server peer
                    SSLSocket sslSocket = (SSLSocket) getContext()
                                    "localhost", peerSocket.getPort(), true); // do autoclose
                    // demand client authentication
                    peerSocket = sslSocket;
                    is = peerSocket.getInputStream();
                    os = peerSocket.getOutputStream();

                    // read the HTTP request sent by secure connection
                    // (HTTPS request)
                    num =;
                    message = new String(buff, 0, num);
                    log("[Remote Server] Request from SSL tunnel:\n" + message);

                    if (message.startsWith("POST")) {
                        // client connection sent some data
                        log("[Remote Server] try to read client data");
                        num =;
                        message = new String(buff, 0, num);
                        log("[Remote Server] client's data: '" + message + "'");
                        // check the received data
                        assertEquals(clientsData, message);

                    log("[Remote Server] Sending the response by SSL tunnel..");
                    // send the response with specified response code
                            .write(("HTTP/1.1 " + responseCode + "\n" + httpsResponseTail)
                log("Work is DONE actAsProxy");
            } catch (Throwable e) {
                if (DO_LOG) {
                thrown = e;
            } finally {
                try {
                } catch (IOException e) {}

     * The class used for client side works. It could be used to test
     * both HttpURLConnection and HttpsURLConnection.
    static class ClientConnectionWork extends Work {

        // connection to be used to contact the server side
        private HttpURLConnection connection;

         * Creates the thread acting as a client side.
         * @param connection connection to be used to contact the server side
        public ClientConnectionWork(HttpURLConnection connection) {
            this.connection = connection;
            setName("Client Connection");
            log("Created over connection: " + connection.getClass());

         * Performs the actual client work.
         * If some exception occurs during the work it will be
         * stored in the <code>thrown<code> field.
        public void run() {
            try {
                log("Opening the connection..");
                log("Connection has been ESTABLISHED, using proxy: "
                        + connection.usingProxy());
                if (connection.getDoOutput()) {
                    // connection configured to post data, do so
                // read the content of HTTP(s) response
                InputStream is = connection.getInputStream();
                log("Input Stream obtained");
                byte[] buff = new byte[2048];
                int num = 0;
                int byt = 0;
                while ((num < buff.length) && (is.available() > 0)
                        && ((byt = != -1)) {
                    buff[num++] = (byte) byt;
                String message = new String(buff, 0, num);
                log("Got content:\n" + message);
                log("Response code: " + connection.getResponseCode());

                if (connection instanceof HttpsURLConnection) {
                    assertEquals(httpsResponseContent, message);
                } else {
                    assertEquals(plainResponseContent, message);
            } catch (Throwable e) {
                if (DO_LOG) {
                thrown = e;