List acceptable client certificate CA names

Viewed 394

I'm using the following code to retrieve and print the server certificates.

public class ExtractCertificate {

    public static void main(String[] args) throws Exception {

        if (args.length != 2) {
            System.out.println("Usage: java -jar sslextractor.jar host port");
            System.exit(1);
        }

        String host = args[0];
        Integer port = Integer.valueOf(Integer.parseInt(args[1]));

        final List certs = new ArrayList();

        X509TrustManager trust = new X509TrustManager() {

            public void checkClientTrusted(X509Certificate[] x509Certificates, String s) throws CertificateException {
                System.out.println(s);
            }

            public void checkServerTrusted(X509Certificate[] x509Certificates, String s) throws CertificateException {
                for (int i = 0; i < x509Certificates.length; i++) {
                    X509Certificate cert = x509Certificates[i];
                    System.out.println("Loading certificate " + cert.getSubjectDN() + " issued by: " + cert.getIssuerDN());
                    certs.add(x509Certificates[i]);
                }
            }

            public X509Certificate[] getAcceptedIssuers() {
                return new X509Certificate[0];
            }

        };

        SSLContext sslContext = SSLContext.getInstance("TLS");
        sslContext.init(null, new TrustManager[]{trust}, null);
        SSLSocket socket = (SSLSocket) sslContext.getSocketFactory().createSocket(host, port.intValue());

        socket.getInputStream();
        socket.getSession().getPeerCertificates();
        socket.close();

        Iterator iterator = certs.iterator();
        while (iterator.hasNext()) {
            X509Certificate cert = (X509Certificate) iterator.next();
            String outputFile = cert.getSubjectDN().getName().replaceAll("[^a-zA-Z0-9-=_\\.]", "_") + ".cer";
            System.out.println("Serializing certificate to: " + outputFile);
            FileOutputStream certfos = new FileOutputStream(outputFile);
            certfos.write(cert.getEncoded());
            certfos.close();
        }

    }

}

Is it possible to retrieve the acceptable client cert CA names using that code base?

I've typically used openssl to find these CA names but I would like to do it programmatically via Java. The following command openssl s_client -showcerts prints all the certificates within the chain, along with the acceptable client cert CA names.

Acceptable client certificate CA names
/C=AU/ST=VIC/L=MELBOURNE/O=MyCompany/OU=ITS/CN=nonprod-api.mycompany.com
/C=AU/ST=VIC/L=MELBOURNE/O=MyCompany/OU=ITS/CN=nonprod-api.mycompany.com
0 Answers
Related