final class oadd.org.apache.zookeeper.common.ZKHostnameVerifier extends java.lang.Object implements javax.net.ssl.HostnameVerifier
{
private final org.slf4j.Logger log;
void <init>()
{
org.slf4j.Logger v;
oadd.org.apache.zookeeper.common.ZKHostnameVerifier v;
v := @this: oadd.org.apache.zookeeper.common.ZKHostnameVerifier;
specialinvoke v.<java.lang.Object: void <init>()>();
v = staticinvoke <org.slf4j.LoggerFactory: org.slf4j.Logger getLogger(java.lang.Class)>(class "Loadd/org/apache/zookeeper/common/ZKHostnameVerifier;");
v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier: org.slf4j.Logger log> = v;
return;
}
public boolean verify(java.lang.String, javax.net.ssl.SSLSession)
{
org.slf4j.Logger v, v;
oadd.org.apache.zookeeper.common.ZKHostnameVerifier v;
javax.net.ssl.SSLException v;
java.security.cert.Certificate v;
javax.net.ssl.SSLSession v;
java.security.cert.Certificate[] v;
java.lang.String v, v;
boolean v;
v := @this: oadd.org.apache.zookeeper.common.ZKHostnameVerifier;
v := @parameter: java.lang.String;
v := @parameter: javax.net.ssl.SSLSession;
label:
v = interfaceinvoke v.<javax.net.ssl.SSLSession: java.security.cert.Certificate[] getPeerCertificates()>();
v = v[0];
virtualinvoke v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier: void verify(java.lang.String,java.security.cert.X509Certificate)>(v, v);
label:
return 1;
label:
v := @caughtexception;
v = v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier: org.slf4j.Logger log>;
v = interfaceinvoke v.<org.slf4j.Logger: boolean isDebugEnabled()>();
if v == 0 goto label;
v = v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier: org.slf4j.Logger log>;
v = virtualinvoke v.<javax.net.ssl.SSLException: java.lang.String getMessage()>();
interfaceinvoke v.<org.slf4j.Logger: void debug(java.lang.String,java.lang.Throwable)>(v, v);
label:
return 0;
catch javax.net.ssl.SSLException from label to label with label;
}
void verify(java.lang.String, java.security.cert.X509Certificate) throws javax.net.ssl.SSLException
{
java.security.cert.X509Certificate v;
javax.security.auth.x.X500Principal v;
oadd.org.apache.zookeeper.common.ZKHostnameVerifier$HostNameType v;
oadd.org.apache.zookeeper.common.ZKHostnameVerifier v;
java.util.List v;
javax.net.ssl.SSLException v;
int[] v;
int v, v;
java.lang.String v, v, v, v;
boolean v;
v := @this: oadd.org.apache.zookeeper.common.ZKHostnameVerifier;
v := @parameter: java.lang.String;
v := @parameter: java.security.cert.X509Certificate;
v = staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: oadd.org.apache.zookeeper.common.ZKHostnameVerifier$HostNameType determineHostFormat(java.lang.String)>(v);
v = staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: java.util.List getSubjectAltNames(java.security.cert.X509Certificate)>(v);
if v == null goto label;
v = interfaceinvoke v.<java.util.List: boolean isEmpty()>();
if v != 0 goto label;
v = <oadd.org.apache.zookeeper.common.ZKHostnameVerifier$1: int[] $SwitchMap$org$apache$zookeeper$common$ZKHostnameVerifier$HostNameType>;
v = virtualinvoke v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier$HostNameType: int ordinal()>();
v = v[v];
lookupswitch(v)
{
case 1: goto label;
case 2: goto label;
default: goto label;
};
label:
staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: void matchIPAddress(java.lang.String,java.util.List)>(v, v);
goto label;
label:
staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: void matchIPv6Address(java.lang.String,java.util.List)>(v, v);
goto label;
label:
staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: void matchDNSName(java.lang.String,java.util.List)>(v, v);
goto label;
label:
v = virtualinvoke v.<java.security.cert.X509Certificate: javax.security.auth.x.X500Principal getSubjectX500Principal()>();
v = virtualinvoke v.<javax.security.auth.x.X500Principal: java.lang.String getName(java.lang.String)>("RFC2253");
v = staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: java.lang.String extractCN(java.lang.String)>(v);
if v != null goto label;
v = new javax.net.ssl.SSLException;
v = dynamicinvoke "makeConcatWithConstants" <java.lang.String (java.lang.String)>(v) <java.lang.invoke.StringConcatFactory: java.lang.invoke.CallSite makeConcatWithConstants(java.lang.invoke.MethodHandles$Lookup,java.lang.String,java.lang.invoke.MethodType,java.lang.String,java.lang.Object[])>("Certificate subject for <\u0001> doesn\'t contain a common name and does not have alternative names");
specialinvoke v.<javax.net.ssl.SSLException: void <init>(java.lang.String)>(v);
throw v;
label:
staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: void matchCN(java.lang.String,java.lang.String)>(v, v);
label:
return;
}
private static void matchIPAddress(java.lang.String, java.util.List) throws javax.net.ssl.SSLException
{
java.util.List v;
int v, v, v;
java.lang.Object v;
java.lang.String v, v, v;
boolean v;
javax.net.ssl.SSLPeerUnverifiedException v;
v := @parameter: java.lang.String;
v := @parameter: java.util.List;
v = 0;
label:
v = interfaceinvoke v.<java.util.List: int size()>();
if v >= v goto label;
v = interfaceinvoke v.<java.util.List: java.lang.Object get(int)>(v);
v = virtualinvoke v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier$SubjectName: int getType()>();
if v != 7 goto label;
v = virtualinvoke v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier$SubjectName: java.lang.String getValue()>();
v = virtualinvoke v.<java.lang.String: boolean equals(java.lang.Object)>(v);
if v == 0 goto label;
return;
label:
v = v + 1;
goto label;
label:
v = new javax.net.ssl.SSLPeerUnverifiedException;
v = dynamicinvoke "makeConcatWithConstants" <java.lang.String (java.lang.String,java.util.List)>(v, v) <java.lang.invoke.StringConcatFactory: java.lang.invoke.CallSite makeConcatWithConstants(java.lang.invoke.MethodHandles$Lookup,java.lang.String,java.lang.invoke.MethodType,java.lang.String,java.lang.Object[])>("Certificate for <\u0001> doesn\'t match any of the subject alternative names: \u0001");
specialinvoke v.<javax.net.ssl.SSLPeerUnverifiedException: void <init>(java.lang.String)>(v);
throw v;
}
private static void matchIPv6Address(java.lang.String, java.util.List) throws javax.net.ssl.SSLException
{
java.util.List v;
int v, v, v;
java.lang.Object v;
java.lang.String v, v, v, v, v;
boolean v;
javax.net.ssl.SSLPeerUnverifiedException v;
v := @parameter: java.lang.String;
v := @parameter: java.util.List;
v = staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: java.lang.String normaliseAddress(java.lang.String)>(v);
v = 0;
label:
v = interfaceinvoke v.<java.util.List: int size()>();
if v >= v goto label;
v = interfaceinvoke v.<java.util.List: java.lang.Object get(int)>(v);
v = virtualinvoke v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier$SubjectName: int getType()>();
if v != 7 goto label;
v = virtualinvoke v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier$SubjectName: java.lang.String getValue()>();
v = staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: java.lang.String normaliseAddress(java.lang.String)>(v);
v = virtualinvoke v.<java.lang.String: boolean equals(java.lang.Object)>(v);
if v == 0 goto label;
return;
label:
v = v + 1;
goto label;
label:
v = new javax.net.ssl.SSLPeerUnverifiedException;
v = dynamicinvoke "makeConcatWithConstants" <java.lang.String (java.lang.String,java.util.List)>(v, v) <java.lang.invoke.StringConcatFactory: java.lang.invoke.CallSite makeConcatWithConstants(java.lang.invoke.MethodHandles$Lookup,java.lang.String,java.lang.invoke.MethodType,java.lang.String,java.lang.Object[])>("Certificate for <\u0001> doesn\'t match any of the subject alternative names: \u0001");
specialinvoke v.<javax.net.ssl.SSLPeerUnverifiedException: void <init>(java.lang.String)>(v);
throw v;
}
private static void matchDNSName(java.lang.String, java.util.List) throws javax.net.ssl.SSLException
{
java.util.List v;
java.util.Locale v, v;
int v, v, v;
java.lang.Object v;
java.lang.String v, v, v, v, v;
boolean v;
javax.net.ssl.SSLPeerUnverifiedException v;
v := @parameter: java.lang.String;
v := @parameter: java.util.List;
v = <java.util.Locale: java.util.Locale ROOT>;
v = virtualinvoke v.<java.lang.String: java.lang.String toLowerCase(java.util.Locale)>(v);
v = 0;
label:
v = interfaceinvoke v.<java.util.List: int size()>();
if v >= v goto label;
v = interfaceinvoke v.<java.util.List: java.lang.Object get(int)>(v);
v = virtualinvoke v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier$SubjectName: int getType()>();
if v != 2 goto label;
v = virtualinvoke v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier$SubjectName: java.lang.String getValue()>();
v = <java.util.Locale: java.util.Locale ROOT>;
v = virtualinvoke v.<java.lang.String: java.lang.String toLowerCase(java.util.Locale)>(v);
v = staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: boolean matchIdentityStrict(java.lang.String,java.lang.String)>(v, v);
if v == 0 goto label;
return;
label:
v = v + 1;
goto label;
label:
v = new javax.net.ssl.SSLPeerUnverifiedException;
v = dynamicinvoke "makeConcatWithConstants" <java.lang.String (java.lang.String,java.util.List)>(v, v) <java.lang.invoke.StringConcatFactory: java.lang.invoke.CallSite makeConcatWithConstants(java.lang.invoke.MethodHandles$Lookup,java.lang.String,java.lang.invoke.MethodType,java.lang.String,java.lang.Object[])>("Certificate for <\u0001> doesn\'t match any of the subject alternative names: \u0001");
specialinvoke v.<javax.net.ssl.SSLPeerUnverifiedException: void <init>(java.lang.String)>(v);
throw v;
}
private static void matchCN(java.lang.String, java.lang.String) throws javax.net.ssl.SSLException
{
java.util.Locale v, v;
java.lang.String v, v, v, v, v;
boolean v;
javax.net.ssl.SSLPeerUnverifiedException v;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v = <java.util.Locale: java.util.Locale ROOT>;
v = virtualinvoke v.<java.lang.String: java.lang.String toLowerCase(java.util.Locale)>(v);
v = <java.util.Locale: java.util.Locale ROOT>;
v = virtualinvoke v.<java.lang.String: java.lang.String toLowerCase(java.util.Locale)>(v);
v = staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: boolean matchIdentityStrict(java.lang.String,java.lang.String)>(v, v);
if v != 0 goto label;
v = new javax.net.ssl.SSLPeerUnverifiedException;
v = dynamicinvoke "makeConcatWithConstants" <java.lang.String (java.lang.String,java.lang.String)>(v, v) <java.lang.invoke.StringConcatFactory: java.lang.invoke.CallSite makeConcatWithConstants(java.lang.invoke.MethodHandles$Lookup,java.lang.String,java.lang.invoke.MethodType,java.lang.String,java.lang.Object[])>("Certificate for <\u0001> doesn\'t match common name of the certificate subject: \u0001");
specialinvoke v.<javax.net.ssl.SSLPeerUnverifiedException: void <init>(java.lang.String)>(v);
throw v;
label:
return;
}
private static boolean matchIdentity(java.lang.String, java.lang.String, boolean)
{
int v, v, v, v, v, v, v;
java.lang.String v, v, v, v, v;
boolean v, v, v, v, v, v, v;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v := @parameter: boolean;
v = virtualinvoke v.<java.lang.String: int indexOf(int)>(42);
v = (int) -1;
if v == v goto label;
v = virtualinvoke v.<java.lang.String: java.lang.String substring(int,int)>(0, v);
v = v + 1;
v = virtualinvoke v.<java.lang.String: java.lang.String substring(int)>(v);
v = virtualinvoke v.<java.lang.String: boolean isEmpty()>();
if v != 0 goto label;
v = virtualinvoke v.<java.lang.String: boolean startsWith(java.lang.String)>(v);
if v != 0 goto label;
return 0;
label:
v = virtualinvoke v.<java.lang.String: boolean isEmpty()>();
if v != 0 goto label;
v = virtualinvoke v.<java.lang.String: boolean endsWith(java.lang.String)>(v);
if v != 0 goto label;
return 0;
label:
if v == 0 goto label;
v = virtualinvoke v.<java.lang.String: int length()>();
v = virtualinvoke v.<java.lang.String: int length()>();
v = virtualinvoke v.<java.lang.String: int length()>();
v = v - v;
v = virtualinvoke v.<java.lang.String: java.lang.String substring(int,int)>(v, v);
v = virtualinvoke v.<java.lang.String: boolean contains(java.lang.CharSequence)>(".");
if v == 0 goto label;
return 0;
label:
return 1;
label:
v = virtualinvoke v.<java.lang.String: boolean equalsIgnoreCase(java.lang.String)>(v);
return v;
}
private static boolean matchIdentityStrict(java.lang.String, java.lang.String)
{
java.lang.String v, v;
boolean v;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v = staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier: boolean matchIdentity(java.lang.String,java.lang.String,boolean)>(v, v, 1);
return v;
}
private static java.lang.String extractCN(java.lang.String) throws javax.net.ssl.SSLException
{
javax.naming.ldap.LdapName v;
javax.naming.NamingException v;
javax.naming.directory.Attribute v;
java.util.List v;
javax.net.ssl.SSLException v;
javax.naming.InvalidNameException v;
javax.naming.directory.Attributes v;
int v, v;
java.lang.Object v, v;
java.lang.String v, v, v;
java.util.NoSuchElementException v;
v := @parameter: java.lang.String;
if v != null goto label;
return null;
label:
v = new javax.naming.ldap.LdapName;
specialinvoke v.<javax.naming.ldap.LdapName: void <init>(java.lang.String)>(v);
v = virtualinvoke v.<javax.naming.ldap.LdapName: java.util.List getRdns()>();
v = interfaceinvoke v.<java.util.List: int size()>();
v = v - 1;
label:
if v < 0 goto label;
v = interfaceinvoke v.<java.util.List: java.lang.Object get(int)>(v);
v = virtualinvoke v.<javax.naming.ldap.Rdn: javax.naming.directory.Attributes toAttributes()>();
v = interfaceinvoke v.<javax.naming.directory.Attributes: javax.naming.directory.Attribute get(java.lang.String)>("cn");
if v == null goto label;
label:
v = interfaceinvoke v.<javax.naming.directory.Attribute: java.lang.Object get()>();
if v == null goto label;
v = virtualinvoke v.<java.lang.Object: java.lang.String toString()>();
label:
return v;
label:
v := @caughtexception;
goto label;
label:
v := @caughtexception;
label:
v = v - 1;
goto label;
label:
return null;
label:
v := @caughtexception;
v = new javax.net.ssl.SSLException;
v = dynamicinvoke "makeConcatWithConstants" <java.lang.String (java.lang.String)>(v) <java.lang.invoke.StringConcatFactory: java.lang.invoke.CallSite makeConcatWithConstants(java.lang.invoke.MethodHandles$Lookup,java.lang.String,java.lang.invoke.MethodType,java.lang.String,java.lang.Object[])>("\u is not a valid X500 distinguished name");
specialinvoke v.<javax.net.ssl.SSLException: void <init>(java.lang.String)>(v);
throw v;
catch java.util.NoSuchElementException from label to label with label;
catch javax.naming.NamingException from label to label with label;
catch javax.naming.InvalidNameException from label to label with label;
catch javax.naming.InvalidNameException from label to label with label;
}
private static oadd.org.apache.zookeeper.common.ZKHostnameVerifier$HostNameType determineHostFormat(java.lang.String)
{
oadd.org.apache.zookeeper.common.ZKHostnameVerifier$HostNameType v, v, v;
int v, v;
java.lang.String v, v;
boolean v, v, v, v;
v := @parameter: java.lang.String;
v = staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier$InetAddressUtils: boolean isIPv4Address(java.lang.String)>(v);
if v == 0 goto label;
v = <oadd.org.apache.zookeeper.common.ZKHostnameVerifier$HostNameType: oadd.org.apache.zookeeper.common.ZKHostnameVerifier$HostNameType IPv4>;
return v;
label:
v = v;
v = virtualinvoke v.<java.lang.String: boolean startsWith(java.lang.String)>("[");
if v == 0 goto label;
v = virtualinvoke v.<java.lang.String: boolean endsWith(java.lang.String)>("]");
if v == 0 goto label;
v = virtualinvoke v.<java.lang.String: int length()>();
v = v - 1;
v = virtualinvoke v.<java.lang.String: java.lang.String substring(int,int)>(1, v);
label:
v = staticinvoke <oadd.org.apache.zookeeper.common.ZKHostnameVerifier$InetAddressUtils: boolean isIPv6Address(java.lang.String)>(v);
if v == 0 goto label;
v = <oadd.org.apache.zookeeper.common.ZKHostnameVerifier$HostNameType: oadd.org.apache.zookeeper.common.ZKHostnameVerifier$HostNameType IPv6>;
return v;
label:
v = <oadd.org.apache.zookeeper.common.ZKHostnameVerifier$HostNameType: oadd.org.apache.zookeeper.common.ZKHostnameVerifier$HostNameType DNS>;
return v;
}
private static java.util.List getSubjectAltNames(java.security.cert.X509Certificate)
{
java.security.cert.X509Certificate v;
java.util.Iterator v;
java.util.Collection v;
java.security.cert.CertificateParsingException v;
java.util.ArrayList v;
java.util.List v, v;
int v, v;
oadd.org.apache.zookeeper.common.ZKHostnameVerifier$SubjectName v;
java.lang.Object v, v, v;
boolean v;
v := @parameter: java.security.cert.X509Certificate;
label:
v = virtualinvoke v.<java.security.cert.X509Certificate: java.util.Collection getSubjectAlternativeNames()>();
if v != null goto label;
v = staticinvoke <java.util.Collections: java.util.List emptyList()>();
label:
return v;
label:
v = new java.util.ArrayList;
specialinvoke v.<java.util.ArrayList: void <init>()>();
v = interfaceinvoke v.<java.util.Collection: java.util.Iterator iterator()>();
label:
v = interfaceinvoke v.<java.util.Iterator: boolean hasNext()>();
if v == 0 goto label;
v = interfaceinvoke v.<java.util.Iterator: java.lang.Object next()>();
v = interfaceinvoke v.<java.util.List: int size()>();
if v < 2 goto label;
v = interfaceinvoke v.<java.util.List: java.lang.Object get(int)>(0);
goto label;
label:
v = null;
label:
if v == null goto label;
v = interfaceinvoke v.<java.util.List: java.lang.Object get(int)>(1);
v = new oadd.org.apache.zookeeper.common.ZKHostnameVerifier$SubjectName;
v = virtualinvoke v.<java.lang.Integer: int intValue()>();
specialinvoke v.<oadd.org.apache.zookeeper.common.ZKHostnameVerifier$SubjectName: void <init>(java.lang.String,int)>(v, v);
interfaceinvoke v.<java.util.List: boolean add(java.lang.Object)>(v);
goto label;
label:
return v;
label:
v := @caughtexception;
v = staticinvoke <java.util.Collections: java.util.List emptyList()>();
return v;
catch java.security.cert.CertificateParsingException from label to label with label;
catch java.security.cert.CertificateParsingException from label to label with label;
}
private static java.lang.String normaliseAddress(java.lang.String)
{
java.net.InetAddress v;
java.lang.String v, v;
java.net.UnknownHostException v;
v := @parameter: java.lang.String;
if v != null goto label;
return v;
label:
v = staticinvoke <java.net.InetAddress: java.net.InetAddress getByName(java.lang.String)>(v);
v = virtualinvoke v.<java.net.InetAddress: java.lang.String getHostAddress()>();
label:
return v;
label:
v := @caughtexception;
return v;
catch java.net.UnknownHostException from label to label with label;
}
}