summaryrefslogtreecommitdiffstats
path: root/pki/base/common/src/com/netscape/cms/profile/constraint/RenewGracePeriodConstraint.java
blob: da2498b15853d741909cf9c045940a1be08cccd1 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
// --- BEGIN COPYRIGHT BLOCK ---
// This program is free software; you can redistribute it and/or modify
// it under the terms of the GNU General Public License as published by
// the Free Software Foundation; version 2 of the License.
//
// This program is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
// GNU General Public License for more details.
//
// You should have received a copy of the GNU General Public License along
// with this program; if not, write to the Free Software Foundation, Inc.,
// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
//
// (C) 2007 Red Hat, Inc.
// All rights reserved.
// --- END COPYRIGHT BLOCK ---
package com.netscape.cms.profile.constraint;


import java.util.*;
import java.io.*;
import java.math.BigInteger;
import com.netscape.certsrv.base.*;
import com.netscape.certsrv.ca.*;
import com.netscape.certsrv.profile.*;
import com.netscape.certsrv.request.*;
import com.netscape.certsrv.property.*;
import com.netscape.certsrv.apps.*;

import com.netscape.cms.profile.def.*;
import netscape.security.x509.*;


/**
 * This class supports renewal grace period, which has two
 * parameters: graceBefore and graceAfter
 *
 * @author Christina Fu
 * @version $Revision$, $Date$
 */
public class RenewGracePeriodConstraint extends EnrollConstraint {

    // for renewal: # of days before the orig cert expiration date 
    public static final String CONFIG_RENEW_GRACE_BEFORE = "renewal.graceBefore";
    // for renewal: # of days after the orig cert expiration date
    public static final String CONFIG_RENEW_GRACE_AFTER = "renewal.graceAfter";

    public RenewGracePeriodConstraint() {
        super();
        addConfigName(CONFIG_RENEW_GRACE_BEFORE);
        addConfigName(CONFIG_RENEW_GRACE_AFTER);
    }

    public void init(IProfile profile, IConfigStore config)
        throws EProfileException {
        super.init(profile, config);
    }

    public void setConfig(String name, String value)
        throws EPropertyException {
        if ( name.equals(CONFIG_RENEW_GRACE_BEFORE) ||
            name.equals(CONFIG_RENEW_GRACE_AFTER)) {
          try {
            Integer.parseInt(value);
          } catch (Exception e) {
                throw new EPropertyException(CMS.getUserMessage(
                            "CMS_INVALID_PROPERTY", CONFIG_RENEW_GRACE_BEFORE +" or "+ CONFIG_RENEW_GRACE_AFTER));
          }
        }
        super.setConfig(name, value);
    }

    public IDescriptor getConfigDescriptor(Locale locale, String name) {
        if (name.equals(CONFIG_RENEW_GRACE_BEFORE)) {
            return new Descriptor(IDescriptor.INTEGER, null, "30",
                    CMS.getUserMessage(locale, "CMS_PROFILE_RENEW_GRACE_BEFORE"));
        } else if (name.equals(CONFIG_RENEW_GRACE_AFTER)) {
            return new Descriptor(IDescriptor.INTEGER, null, "30",
                    CMS.getUserMessage(locale, "CMS_PROFILE_RENEW_GRACE_AFTER"));
        }
        return null;
    }

    public void validate(IRequest req, X509CertInfo info)
        throws ERejectException {
           String origExpDate_s = req.getExtDataInString("origNotAfter");
           // probably not for renewal
           if (origExpDate_s == null) {
               return;
           } else {
               CMS.debug("validate RenewGracePeriod: original cert expiration date found... renewing");
           }
           CMS.debug("ValidilityConstraint: validateRenewGraceperiod begins");
           BigInteger origExpDate_BI = new BigInteger(origExpDate_s);
           Date origExpDate = new Date(origExpDate_BI.longValue());
           String renew_grace_before_s = getConfig(CONFIG_RENEW_GRACE_BEFORE);
           String renew_grace_after_s = getConfig(CONFIG_RENEW_GRACE_AFTER);
           int renew_grace_before = 0;
           int renew_grace_after = 0;
           BigInteger renew_grace_before_BI = new BigInteger(renew_grace_before_s);
           BigInteger renew_grace_after_BI= new BigInteger(renew_grace_after_s);

           // -1 means no limit
           if (renew_grace_before_s == "")
               renew_grace_before = -1;
           else
               renew_grace_before = Integer.parseInt(renew_grace_before_s);

           if (renew_grace_after_s == "")
               renew_grace_after = -1;
           else
               renew_grace_after = Integer.parseInt(renew_grace_after_s);

           if (renew_grace_before > 0)
               renew_grace_before_BI = renew_grace_before_BI.multiply(BigInteger.valueOf(1000 * 86400));
           if (renew_grace_after > 0)
               renew_grace_after_BI = renew_grace_after_BI.multiply(BigInteger.valueOf(1000 * 86400));

           Date current = CMS.getCurrentDate();
           long millisDiff = origExpDate.getTime() - current.getTime();
           CMS.debug("validateRenewGracePeriod: millisDiff=" + millisDiff + " origExpDate=" + origExpDate.getTime() + " current=" + current.getTime());

           /*
            * "days", if positive, has to be less than renew_grace_before
            * "days", if negative, means already past expiration date,
            *     (abs value) has to be less than renew_grace_after
            * if renew_grace_before or renew_grace_after are negative
            *    the one with negative value is ignored
            */
           if (millisDiff >= 0) {
               if ((renew_grace_before>0) && (millisDiff > renew_grace_before_BI.longValue())) {
                   throw new ERejectException(CMS.getUserMessage(getLocale(req),
                        "CMS_PROFILE_RENEW_OUTSIDE_GRACE_PERIOD", 
                        renew_grace_before+" days before and "+
                        renew_grace_after+" days after original cert expiration date"));
               }
           } else {
               if ((renew_grace_after > 0) && ((0-millisDiff) > renew_grace_after_BI.longValue())) {
                   throw new ERejectException(CMS.getUserMessage(getLocale(req),
                        "CMS_PROFILE_RENEW_OUTSIDE_GRACE_PERIOD", 
                        renew_grace_before+" days before and "+
                        renew_grace_after+" days after original cert expiration date"));
               }
           }
    }


    public String getText(Locale locale) {
        String renew_grace_before_s = getConfig(CONFIG_RENEW_GRACE_BEFORE);
        String renew_grace_after_s= getConfig(CONFIG_RENEW_GRACE_AFTER);
        return CMS.getUserMessage(locale, "CMS_PROFILE_CONSTRAINT_VALIDITY_TEXT", 
                        renew_grace_before_s+" days before and "+
                        renew_grace_after_s+" days after original cert expiration date");
    }

    public boolean isApplicable(IPolicyDefault def) {
        if (def instanceof NoDefault)
            return true;
        return false;
    }
}