org.signal.libsignal.metadata.certificate.InvalidCertificateException Java Examples

The following examples show how to use org.signal.libsignal.metadata.certificate.InvalidCertificateException. You can vote up the ones you like or vote down the ones you don't like, and go to the original project or source file by following the links above each example. You may check out the related API usage on the sidebar.
Example #1
Source File: UnidentifiedAccessUtil.java    From mollyim-android with GNU General Public License v3.0 6 votes vote down vote up
public static Optional<UnidentifiedAccessPair> getAccessForSync(@NonNull Context context) {
  try {
    byte[] ourUnidentifiedAccessKey         = UnidentifiedAccess.deriveAccessKeyFrom(ProfileKeyUtil.getSelfProfileKey());
    byte[] ourUnidentifiedAccessCertificate = TextSecurePreferences.getUnidentifiedAccessCertificate(context);

    if (TextSecurePreferences.isUniversalUnidentifiedAccess(context)) {
      ourUnidentifiedAccessKey = Util.getSecretBytes(16);
    }

    if (ourUnidentifiedAccessKey != null && ourUnidentifiedAccessCertificate != null) {
      return Optional.of(new UnidentifiedAccessPair(new UnidentifiedAccess(ourUnidentifiedAccessKey,
                                                                           ourUnidentifiedAccessCertificate),
                                                    new UnidentifiedAccess(ourUnidentifiedAccessKey,
                                                                           ourUnidentifiedAccessCertificate)));
    }

    return Optional.absent();
  } catch (InvalidCertificateException e) {
    Log.w(TAG, e);
    return Optional.absent();
  }
}
 
Example #2
Source File: PushSendJob.java    From mollyim-android with GNU General Public License v3.0 6 votes vote down vote up
protected void rotateSenderCertificateIfNecessary() throws IOException {
  try {
    byte[] certificateBytes = TextSecurePreferences.getUnidentifiedAccessCertificate(context);

    if (certificateBytes == null) {
      throw new InvalidCertificateException("No certificate was present.");
    }

    SenderCertificate certificate = new SenderCertificate(certificateBytes);

    if (System.currentTimeMillis() > (certificate.getExpiration() - CERTIFICATE_EXPIRATION_BUFFER)) {
      throw new InvalidCertificateException("Certificate is expired, or close to it. Expires on: " + certificate.getExpiration() + ", currently: " + System.currentTimeMillis());
    }

    Log.d(TAG, "Certificate is valid.");
  } catch (InvalidCertificateException e) {
    Log.w(TAG, "Certificate was invalid at send time. Fetching a new one.", e);
    RotateCertificateJob certificateJob = new RotateCertificateJob(context);
    certificateJob.onRun();
  }
}
 
Example #3
Source File: Manager.java    From signal-cli with GNU General Public License v3.0 6 votes vote down vote up
private Optional<UnidentifiedAccessPair> getAccessForSync() {
    byte[] selfUnidentifiedAccessKey = getSelfUnidentifiedAccessKey();
    byte[] selfUnidentifiedAccessCertificate = getSenderCertificate();

    if (selfUnidentifiedAccessKey == null || selfUnidentifiedAccessCertificate == null) {
        return Optional.absent();
    }

    try {
        return Optional.of(new UnidentifiedAccessPair(
                new UnidentifiedAccess(selfUnidentifiedAccessKey, selfUnidentifiedAccessCertificate),
                new UnidentifiedAccess(selfUnidentifiedAccessKey, selfUnidentifiedAccessCertificate)
        ));
    } catch (InvalidCertificateException e) {
        return Optional.absent();
    }
}
 
Example #4
Source File: Manager.java    From signal-cli with GNU General Public License v3.0 6 votes vote down vote up
private Optional<UnidentifiedAccessPair> getAccessFor(SignalServiceAddress recipient) {
    byte[] recipientUnidentifiedAccessKey = getTargetUnidentifiedAccessKey(recipient);
    byte[] selfUnidentifiedAccessKey = getSelfUnidentifiedAccessKey();
    byte[] selfUnidentifiedAccessCertificate = getSenderCertificate();

    if (recipientUnidentifiedAccessKey == null || selfUnidentifiedAccessKey == null || selfUnidentifiedAccessCertificate == null) {
        return Optional.absent();
    }

    try {
        return Optional.of(new UnidentifiedAccessPair(
                new UnidentifiedAccess(recipientUnidentifiedAccessKey, selfUnidentifiedAccessCertificate),
                new UnidentifiedAccess(selfUnidentifiedAccessKey, selfUnidentifiedAccessCertificate)
        ));
    } catch (InvalidCertificateException e) {
        return Optional.absent();
    }
}
 
Example #5
Source File: UnidentifiedAccessUtil.java    From mollyim-android with GNU General Public License v3.0 5 votes vote down vote up
@WorkerThread
public static Optional<UnidentifiedAccessPair> getAccessFor(@NonNull Context context,
                                                            @NonNull Recipient recipient)
{
  try {
    byte[] theirUnidentifiedAccessKey       = getTargetUnidentifiedAccessKey(recipient);
    byte[] ourUnidentifiedAccessKey         = UnidentifiedAccess.deriveAccessKeyFrom(ProfileKeyUtil.getSelfProfileKey());
    byte[] ourUnidentifiedAccessCertificate = TextSecurePreferences.getUnidentifiedAccessCertificate(context);

    if (TextSecurePreferences.isUniversalUnidentifiedAccess(context)) {
      ourUnidentifiedAccessKey = Util.getSecretBytes(16);
    }

    Log.i(TAG, "Their access key present? " + (theirUnidentifiedAccessKey != null) +
               " | Our access key present? " + (ourUnidentifiedAccessKey != null) +
               " | Our certificate present? " + (ourUnidentifiedAccessCertificate != null) +
               " | UUID certificate supported? " + recipient.isUuidSupported());

    if (theirUnidentifiedAccessKey != null &&
        ourUnidentifiedAccessKey != null   &&
        ourUnidentifiedAccessCertificate != null)
    {
      return Optional.of(new UnidentifiedAccessPair(new UnidentifiedAccess(theirUnidentifiedAccessKey,
                                                                           ourUnidentifiedAccessCertificate),
                                                    new UnidentifiedAccess(ourUnidentifiedAccessKey,
                                                                           ourUnidentifiedAccessCertificate)));
    }

    return Optional.absent();
  } catch (InvalidCertificateException e) {
    Log.w(TAG, e);
    return Optional.absent();
  }
}
 
Example #6
Source File: UnidentifiedAccess.java    From mollyim-android with GNU General Public License v3.0 4 votes vote down vote up
public UnidentifiedAccess(byte[] unidentifiedAccessKey, byte[] unidentifiedCertificate)
    throws InvalidCertificateException
{
  this.unidentifiedAccessKey   = unidentifiedAccessKey;
  this.unidentifiedCertificate = new SenderCertificate(unidentifiedCertificate);
}
 
Example #7
Source File: UnidentifiedAccess.java    From libsignal-service-java with GNU General Public License v3.0 4 votes vote down vote up
public UnidentifiedAccess(byte[] unidentifiedAccessKey, byte[] unidentifiedCertificate)
    throws InvalidCertificateException
{
  this.unidentifiedAccessKey   = unidentifiedAccessKey;
  this.unidentifiedCertificate = new SenderCertificate(unidentifiedCertificate);
}