public class org.apache.kafkaesqueesque.common.security.ssl.SslFactory extends java.lang.Object implements org.apache.kafkaesqueesque.common.Reconfigurable
{
private static final org.slf4j.Logger log;
private final org.apache.kafkaesqueesque.common.network.Mode mode;
private final java.lang.String clientAuthConfigOverride;
private final boolean keystoreVerifiableUsingTruststore;
private java.lang.String endpointIdentification;
private org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder;
public void <init>(org.apache.kafkaesqueesque.common.network.Mode)
{
org.apache.kafkaesqueesque.common.network.Mode v;
org.apache.kafkaesqueesque.common.security.ssl.SslFactory v;
v := @this: org.apache.kafkaesqueesque.common.security.ssl.SslFactory;
v := @parameter: org.apache.kafkaesqueesque.common.network.Mode;
specialinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: void <init>(org.apache.kafkaesqueesque.common.network.Mode,java.lang.String,boolean)>(v, null, 0);
return;
}
public void <init>(org.apache.kafkaesqueesque.common.network.Mode, java.lang.String, boolean)
{
org.apache.kafkaesqueesque.common.network.Mode v;
java.lang.String v;
org.apache.kafkaesqueesque.common.security.ssl.SslFactory v;
boolean v;
v := @this: org.apache.kafkaesqueesque.common.security.ssl.SslFactory;
v := @parameter: org.apache.kafkaesqueesque.common.network.Mode;
v := @parameter: java.lang.String;
v := @parameter: boolean;
specialinvoke v.<java.lang.Object: void <init>()>();
v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.network.Mode mode> = v;
v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: java.lang.String clientAuthConfigOverride> = v;
v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: boolean keystoreVerifiableUsingTruststore> = v;
return;
}
public void configure(java.util.Map) throws org.apache.kafkaesqueesque.common.KafkaException
{
java.lang.IllegalStateException v;
java.util.Set v, v;
java.util.HashMap v;
java.lang.Exception v;
org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder v, v;
java.util.Map v;
org.apache.kafkaesqueesque.common.config.ConfigException v;
java.lang.Object v;
java.lang.String v, v;
org.apache.kafkaesqueesque.common.security.ssl.SslFactory v;
boolean v;
v := @this: org.apache.kafkaesqueesque.common.security.ssl.SslFactory;
v := @parameter: java.util.Map;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
if v == null goto label;
v = new java.lang.IllegalStateException;
specialinvoke v.<java.lang.IllegalStateException: void <init>(java.lang.String)>("SslFactory was already configured.");
throw v;
label:
v = interfaceinvoke v.<java.util.Map: java.lang.Object get(java.lang.Object)>("ssl.endpoint.identification.algorithm");
v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: java.lang.String endpointIdentification> = v;
v = new java.util.HashMap;
specialinvoke v.<java.util.HashMap: void <init>()>();
v = <org.apache.kafkaesqueesque.common.config.SslConfigs: java.util.Set NON_RECONFIGURABLE_CONFIGS>;
staticinvoke <org.apache.kafkaesqueesque.common.security.ssl.SslFactory: void copyMapEntries(java.util.Map,java.util.Map,java.util.Set)>(v, v, v);
v = <org.apache.kafkaesqueesque.common.config.SslConfigs: java.util.Set RECONFIGURABLE_CONFIGS>;
staticinvoke <org.apache.kafkaesqueesque.common.security.ssl.SslFactory: void copyMapEntries(java.util.Map,java.util.Map,java.util.Set)>(v, v, v);
staticinvoke <org.apache.kafkaesqueesque.common.security.ssl.SslFactory: void copyMapEntry(java.util.Map,java.util.Map,java.lang.Object)>(v, v, "security.providers");
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: java.lang.String clientAuthConfigOverride>;
if v == null goto label;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: java.lang.String clientAuthConfigOverride>;
interfaceinvoke v.<java.util.Map: java.lang.Object put(java.lang.Object,java.lang.Object)>("ssl.client.auth", v);
label:
v = new org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder;
specialinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: void <init>(java.util.Map)>(v);
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: boolean keystoreVerifiableUsingTruststore>;
if v == 0 goto label;
label:
staticinvoke <org.apache.kafkaesqueesque.common.security.ssl.SslFactory$SslEngineValidator: void validate(org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder,org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder)>(v, v);
label:
goto label;
label:
v := @caughtexception;
v = new org.apache.kafkaesqueesque.common.config.ConfigException;
specialinvoke v.<org.apache.kafkaesqueesque.common.config.ConfigException: void <init>(java.lang.String,java.lang.Object)>("A client SSLEngine created with the provided settings can\'t connect to a server SSLEngine created with those settings.", v);
throw v;
label:
v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder> = v;
return;
catch java.lang.Exception from label to label with label;
}
public java.util.Set reconfigurableConfigs()
{
java.util.Set v;
org.apache.kafkaesqueesque.common.security.ssl.SslFactory v;
v := @this: org.apache.kafkaesqueesque.common.security.ssl.SslFactory;
v = <org.apache.kafkaesqueesque.common.config.SslConfigs: java.util.Set RECONFIGURABLE_CONFIGS>;
return v;
}
public void validateReconfiguration(java.util.Map)
{
org.apache.kafkaesqueesque.common.security.ssl.SslFactory v;
java.util.Map v;
v := @this: org.apache.kafkaesqueesque.common.security.ssl.SslFactory;
v := @parameter: java.util.Map;
specialinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder createNewSslEngineBuilder(java.util.Map)>(v);
return;
}
public void reconfigure(java.util.Map) throws org.apache.kafkaesqueesque.common.KafkaException
{
java.lang.Object[] v;
org.slf4j.Logger v;
org.apache.kafkaesqueesque.common.network.Mode v;
org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore v, v;
org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder v, v;
java.util.Map v;
org.apache.kafkaesqueesque.common.security.ssl.SslFactory v;
v := @this: org.apache.kafkaesqueesque.common.security.ssl.SslFactory;
v := @parameter: java.util.Map;
v = specialinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder createNewSslEngineBuilder(java.util.Map)>(v);
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
if v == v goto label;
v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder> = v;
v = <org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.slf4j.Logger log>;
v = newarray (java.lang.Object)[3];
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.network.Mode mode>;
v[0] = v;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore keystore()>();
v[1] = v;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore truststore()>();
v[2] = v;
interfaceinvoke v.<org.slf4j.Logger: void info(java.lang.String,java.lang.Object[])>("Created new {} SSL engine builder with keystore {} truststore {}", v);
label:
return;
}
private org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder createNewSslEngineBuilder(java.util.Map)
{
java.lang.IllegalStateException v;
java.util.Map v, v;
org.apache.kafkaesqueesque.common.security.ssl.SslFactory v;
boolean v, v, v;
java.util.Set v;
java.security.KeyStore v, v;
java.lang.Exception v;
java.util.List v, v;
java.util.HashMap v;
org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder v, v, v, v, v, v, v, v, v, v, v;
java.lang.String v, v, v;
org.slf4j.Logger v;
org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore v, v, v, v, v, v, v, v, v;
org.apache.kafkaesqueesque.common.config.ConfigException v, v, v, v, v;
v := @this: org.apache.kafkaesqueesque.common.security.ssl.SslFactory;
v := @parameter: java.util.Map;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
if v != null goto label;
v = new java.lang.IllegalStateException;
specialinvoke v.<java.lang.IllegalStateException: void <init>(java.lang.String)>("SslFactory has not been configured.");
throw v;
label:
v = new java.util.HashMap;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: java.util.Map configs()>();
specialinvoke v.<java.util.HashMap: void <init>(java.util.Map)>(v);
v = <org.apache.kafkaesqueesque.common.config.SslConfigs: java.util.Set RECONFIGURABLE_CONFIGS>;
staticinvoke <org.apache.kafkaesqueesque.common.security.ssl.SslFactory: void copyMapEntries(java.util.Map,java.util.Map,java.util.Set)>(v, v, v);
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: java.lang.String clientAuthConfigOverride>;
if v == null goto label;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: java.lang.String clientAuthConfigOverride>;
interfaceinvoke v.<java.util.Map: java.lang.Object put(java.lang.Object,java.lang.Object)>("ssl.client.auth", v);
label:
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: boolean shouldBeRebuilt(java.util.Map)>(v);
if v != 0 goto label;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
return v;
label:
v = new org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder;
specialinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: void <init>(java.util.Map)>(v);
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore keystore()>();
if v != null goto label;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore keystore()>();
if v == null goto label;
v = new org.apache.kafkaesqueesque.common.config.ConfigException;
specialinvoke v.<org.apache.kafkaesqueesque.common.config.ConfigException: void <init>(java.lang.String)>("Cannot add SSL keystore to an existing listener for which no keystore was configured.");
throw v;
label:
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore keystore()>();
if v != null goto label;
v = new org.apache.kafkaesqueesque.common.config.ConfigException;
specialinvoke v.<org.apache.kafkaesqueesque.common.config.ConfigException: void <init>(java.lang.String)>("Cannot remove the SSL keystore from an existing listener for which a keystore was configured.");
throw v;
label:
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore keystore()>();
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore: java.security.KeyStore load()>();
v = staticinvoke <org.apache.kafkaesqueesque.common.security.ssl.SslFactory$CertificateEntries: java.util.List create(java.security.KeyStore)>(v);
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore keystore()>();
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore: java.security.KeyStore load()>();
v = staticinvoke <org.apache.kafkaesqueesque.common.security.ssl.SslFactory$CertificateEntries: java.util.List create(java.security.KeyStore)>(v);
v = interfaceinvoke v.<java.util.List: boolean equals(java.lang.Object)>(v);
if v != 0 goto label;
v = new org.apache.kafkaesqueesque.common.config.ConfigException;
specialinvoke v.<org.apache.kafkaesqueesque.common.config.ConfigException: void <init>(java.lang.String)>("Keystore DistinguishedName or SubjectAltNames do not match");
throw v;
label:
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore truststore()>();
if v != null goto label;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore truststore()>();
if v == null goto label;
v = new org.apache.kafkaesqueesque.common.config.ConfigException;
specialinvoke v.<org.apache.kafkaesqueesque.common.config.ConfigException: void <init>(java.lang.String)>("Cannot add SSL truststore to an existing listener for which no truststore was configured.");
throw v;
label:
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: boolean keystoreVerifiableUsingTruststore>;
if v == 0 goto label;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore truststore()>();
if v != null goto label;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder$SecurityStore keystore()>();
if v == null goto label;
label:
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
staticinvoke <org.apache.kafkaesqueesque.common.security.ssl.SslFactory$SslEngineValidator: void validate(org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder,org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder)>(v, v);
label:
return v;
label:
v := @caughtexception;
v = <org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.slf4j.Logger log>;
interfaceinvoke v.<org.slf4j.Logger: void debug(java.lang.String,java.lang.Throwable)>("Validation of dynamic config update of SSLFactory failed.", v);
v = new org.apache.kafkaesqueesque.common.config.ConfigException;
v = dynamicinvoke "makeConcatWithConstants" <java.lang.String (java.lang.Exception)>(v) <java.lang.invoke.StringConcatFactory: java.lang.invoke.CallSite makeConcatWithConstants(java.lang.invoke.MethodHandles$Lookup,java.lang.String,java.lang.invoke.MethodType,java.lang.String,java.lang.Object[])>("Validation of dynamic config update of SSLFactory failed: \u0001");
specialinvoke v.<org.apache.kafkaesqueesque.common.config.ConfigException: void <init>(java.lang.String)>(v);
throw v;
catch java.lang.Exception from label to label with label;
}
public javax.net.ssl.SSLEngine createSslEngine(java.lang.String, int)
{
java.lang.IllegalStateException v;
org.apache.kafkaesqueesque.common.network.Mode v;
javax.net.ssl.SSLEngine v;
org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder v, v;
int v;
java.lang.String v, v;
org.apache.kafkaesqueesque.common.security.ssl.SslFactory v;
v := @this: org.apache.kafkaesqueesque.common.security.ssl.SslFactory;
v := @parameter: java.lang.String;
v := @parameter: int;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
if v != null goto label;
v = new java.lang.IllegalStateException;
specialinvoke v.<java.lang.IllegalStateException: void <init>(java.lang.String)>("SslFactory has not been configured.");
throw v;
label:
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.network.Mode mode>;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: java.lang.String endpointIdentification>;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: javax.net.ssl.SSLEngine createSslEngine(org.apache.kafkaesqueesque.common.network.Mode,java.lang.String,int,java.lang.String)>(v, v, v, v);
return v;
}
public javax.net.ssl.SSLContext sslContext()
{
javax.net.ssl.SSLContext v;
org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder v;
org.apache.kafkaesqueesque.common.security.ssl.SslFactory v;
v := @this: org.apache.kafkaesqueesque.common.security.ssl.SslFactory;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
v = virtualinvoke v.<org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder: javax.net.ssl.SSLContext sslContext()>();
return v;
}
public org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder()
{
org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder v;
org.apache.kafkaesqueesque.common.security.ssl.SslFactory v;
v := @this: org.apache.kafkaesqueesque.common.security.ssl.SslFactory;
v = v.<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.apache.kafkaesqueesque.common.security.ssl.SslEngineBuilder sslEngineBuilder>;
return v;
}
private static void copyMapEntries(java.util.Map, java.util.Map, java.util.Set)
{
java.util.Iterator v;
java.util.Map v, v;
java.util.Set v;
java.lang.Object v;
boolean v;
v := @parameter: java.util.Map;
v := @parameter: java.util.Map;
v := @parameter: java.util.Set;
v = interfaceinvoke v.<java.util.Set: java.util.Iterator iterator()>();
label:
v = interfaceinvoke v.<java.util.Iterator: boolean hasNext()>();
if v == 0 goto label;
v = interfaceinvoke v.<java.util.Iterator: java.lang.Object next()>();
staticinvoke <org.apache.kafkaesqueesque.common.security.ssl.SslFactory: void copyMapEntry(java.util.Map,java.util.Map,java.lang.Object)>(v, v, v);
goto label;
label:
return;
}
private static void copyMapEntry(java.util.Map, java.util.Map, java.lang.Object)
{
java.util.Map v, v;
java.lang.Object v, v;
boolean v;
v := @parameter: java.util.Map;
v := @parameter: java.util.Map;
v := @parameter: java.lang.Object;
v = interfaceinvoke v.<java.util.Map: boolean containsKey(java.lang.Object)>(v);
if v == 0 goto label;
v = interfaceinvoke v.<java.util.Map: java.lang.Object get(java.lang.Object)>(v);
interfaceinvoke v.<java.util.Map: java.lang.Object put(java.lang.Object,java.lang.Object)>(v, v);
label:
return;
}
static void <clinit>()
{
org.slf4j.Logger v;
v = staticinvoke <org.slf4j.LoggerFactory: org.slf4j.Logger getLogger(java.lang.Class)>(class "Lorg/apache/kafkaesqueesque/common/security/ssl/SslFactory;");
<org.apache.kafkaesqueesque.common.security.ssl.SslFactory: org.slf4j.Logger log> = v;
return;
}
}