blob: e7b161b75896ce99390912024b0475ff36f2c4b1 [file] [log] [blame]
Brian Carlstrom3e6251d2011-04-11 09:05:06 -07001/*
2 * Copyright (C) 2011 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package com.android.keychain;
18
Brian Carlstrom65e649e2011-06-24 02:13:28 -070019import android.app.Activity;
20import android.app.AlertDialog;
21import android.app.Dialog;
22import android.app.PendingIntent;
23import android.content.DialogInterface;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070024import android.content.Intent;
Brian Carlstrom65e649e2011-06-24 02:13:28 -070025import android.content.pm.PackageManager;
26import android.content.res.Resources;
27import android.os.AsyncTask;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070028import android.os.Bundle;
29import android.security.Credentials;
Brian Carlstromf5b50a42011-06-09 16:05:09 -070030import android.security.IKeyChainAliasCallback;
Brian Carlstrombb04f702011-05-24 21:54:51 -070031import android.security.KeyChain;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070032import android.security.KeyStore;
Fred Quintanafb2e18e2011-07-13 14:54:05 -070033import android.util.Log;
Brian Carlstrom65e649e2011-06-24 02:13:28 -070034import android.view.LayoutInflater;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070035import android.view.View;
Brian Carlstrom65e649e2011-06-24 02:13:28 -070036import android.view.ViewGroup;
Selim Gurun9c2b71c2012-03-22 15:51:14 -070037import android.widget.AdapterView;
Brian Carlstrom65e649e2011-06-24 02:13:28 -070038import android.widget.BaseAdapter;
39import android.widget.Button;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070040import android.widget.ListView;
Brian Carlstrom65e649e2011-06-24 02:13:28 -070041import android.widget.RadioButton;
42import android.widget.TextView;
43import com.android.org.bouncycastle.asn1.x509.X509Name;
44import java.io.ByteArrayInputStream;
45import java.io.InputStream;
46import java.security.cert.CertificateException;
47import java.security.cert.CertificateFactory;
48import java.security.cert.X509Certificate;
49import java.util.ArrayList;
50import java.util.Arrays;
51import java.util.Collections;
52import java.util.List;
Fred Quintanafb2e18e2011-07-13 14:54:05 -070053
Brian Carlstrom65e649e2011-06-24 02:13:28 -070054import javax.security.auth.x500.X500Principal;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070055
Brian Carlstrom65e649e2011-06-24 02:13:28 -070056public class KeyChainActivity extends Activity {
Fred Quintanafb2e18e2011-07-13 14:54:05 -070057 private static final String TAG = "KeyChain";
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070058
59 private static String KEY_STATE = "state";
60
61 private static final int REQUEST_UNLOCK = 1;
62
Fred Quintanafb2e18e2011-07-13 14:54:05 -070063 private int mSenderUid;
64
65 private PendingIntent mSender;
66
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070067 private static enum State { INITIAL, UNLOCK_REQUESTED };
68
69 private State mState;
70
Brian Carlstrom65e649e2011-06-24 02:13:28 -070071 // beware that some of these KeyStore operations such as saw and
72 // get do file I/O in the remote keystore process and while they
73 // do not cause StrictMode violations, they logically should not
74 // be done on the UI thread.
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070075 private KeyStore mKeyStore = KeyStore.getInstance();
76
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070077 @Override public void onCreate(Bundle savedState) {
78 super.onCreate(savedState);
79 if (savedState == null) {
80 mState = State.INITIAL;
81 } else {
82 mState = (State) savedState.getSerializable(KEY_STATE);
83 if (mState == null) {
84 mState = State.INITIAL;
85 }
86 }
87 }
88
89 @Override public void onResume() {
90 super.onResume();
91
Fred Quintanafb2e18e2011-07-13 14:54:05 -070092 mSender = getIntent().getParcelableExtra(KeyChain.EXTRA_SENDER);
93 if (mSender == null) {
94 // if no sender, bail, we need to identify the app to the user securely.
95 finish(null);
96 return;
97 }
98 try {
99 mSenderUid = getPackageManager().getPackageInfo(
100 mSender.getIntentSender().getTargetPackage(), 0).applicationInfo.uid;
101 } catch (PackageManager.NameNotFoundException e) {
102 // if unable to find the sender package info bail,
103 // we need to identify the app to the user securely.
104 finish(null);
105 return;
106 }
107
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700108 // see if KeyStore has been unlocked, if not start activity to do so
109 switch (mState) {
110 case INITIAL:
Kenny Root4ff22962013-02-14 10:17:06 -0800111 if (!mKeyStore.isUnlocked()) {
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700112 mState = State.UNLOCK_REQUESTED;
113 this.startActivityForResult(new Intent(Credentials.UNLOCK_ACTION),
114 REQUEST_UNLOCK);
115 // Note that Credentials.unlock will start an
116 // Activity and we will be paused but then resumed
117 // when the unlock Activity completes and our
118 // onActivityResult is called with REQUEST_UNLOCK
119 return;
120 }
Brian Carlstrom91940e72011-06-28 20:37:31 -0700121 showCertChooserDialog();
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700122 return;
123 case UNLOCK_REQUESTED:
124 // we've already asked, but have not heard back, probably just rotated.
125 // wait to hear back via onActivityResult
126 return;
127 default:
128 throw new AssertionError();
129 }
130 }
131
Brian Carlstrom91940e72011-06-28 20:37:31 -0700132 private void showCertChooserDialog() {
133 new AliasLoader().execute();
134 }
135
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700136 private class AliasLoader extends AsyncTask<Void, Void, CertificateAdapter> {
137 @Override protected CertificateAdapter doInBackground(Void... params) {
138 String[] aliasArray = mKeyStore.saw(Credentials.USER_PRIVATE_KEY);
139 List<String> aliasList = ((aliasArray == null)
140 ? Collections.<String>emptyList()
141 : Arrays.asList(aliasArray));
142 Collections.sort(aliasList);
143 return new CertificateAdapter(aliasList);
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700144 }
Brian Carlstrom91940e72011-06-28 20:37:31 -0700145 @Override protected void onPostExecute(CertificateAdapter adapter) {
146 displayCertChooserDialog(adapter);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700147 }
148 }
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700149
Brian Carlstrom91940e72011-06-28 20:37:31 -0700150 private void displayCertChooserDialog(final CertificateAdapter adapter) {
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700151 AlertDialog.Builder builder = new AlertDialog.Builder(this);
Brian Carlstromdf172302011-06-26 17:13:54 -0700152
Brian Carlstrom4bf9e1a2011-06-28 21:45:31 -0700153 TextView contextView = (TextView) View.inflate(this, R.layout.cert_chooser_header, null);
154 View footer = View.inflate(this, R.layout.cert_chooser_footer, null);
155
156 final ListView lv = (ListView) View.inflate(this, R.layout.cert_chooser, null);
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700157 lv.addHeaderView(contextView, null, false);
158 lv.addFooterView(footer, null, false);
Brian Carlstrom4bf9e1a2011-06-28 21:45:31 -0700159 lv.setAdapter(adapter);
160 builder.setView(lv);
Brian Carlstromdf172302011-06-26 17:13:54 -0700161
Selim Gurun9c2b71c2012-03-22 15:51:14 -0700162 lv.setOnItemClickListener(new AdapterView.OnItemClickListener() {
163
164 public void onItemClick(AdapterView<?> parent, View view, int position, long id) {
165 lv.setItemChecked(position, true);
166 }
167 });
168
Brian Carlstrom91940e72011-06-28 20:37:31 -0700169 boolean empty = adapter.mAliases.isEmpty();
Brian Carlstromdf172302011-06-26 17:13:54 -0700170 int negativeLabel = empty ? android.R.string.cancel : R.string.deny_button;
171 builder.setNegativeButton(negativeLabel, new DialogInterface.OnClickListener() {
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700172 @Override public void onClick(DialogInterface dialog, int id) {
173 dialog.cancel(); // will cause OnDismissListener to be called
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700174 }
175 });
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700176
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700177 String title;
Brian Carlstromdf172302011-06-26 17:13:54 -0700178 Resources res = getResources();
179 if (empty) {
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700180 title = res.getString(R.string.title_no_certs);
181 } else {
182 title = res.getString(R.string.title_select_cert);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700183 String alias = getIntent().getStringExtra(KeyChain.EXTRA_ALIAS);
184 if (alias != null) {
Brian Carlstrom62316552011-07-10 12:26:12 -0700185 // if alias was requested, set it if found
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700186 int adapterPosition = adapter.mAliases.indexOf(alias);
187 if (adapterPosition != -1) {
188 int listViewPosition = adapterPosition+1;
189 lv.setItemChecked(listViewPosition, true);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700190 }
Brian Carlstrom62316552011-07-10 12:26:12 -0700191 } else if (adapter.mAliases.size() == 1) {
192 // if only one choice, preselect it
193 int adapterPosition = 0;
194 int listViewPosition = adapterPosition+1;
195 lv.setItemChecked(listViewPosition, true);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700196 }
197
198 builder.setPositiveButton(R.string.allow_button, new DialogInterface.OnClickListener() {
199 @Override public void onClick(DialogInterface dialog, int id) {
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700200 int listViewPosition = lv.getCheckedItemPosition();
201 int adapterPosition = listViewPosition-1;
202 String alias = ((adapterPosition >= 0)
203 ? adapter.getItem(adapterPosition)
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700204 : null);
205 finish(alias);
206 }
207 });
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700208 }
209 builder.setTitle(title);
Brian Carlstrom91940e72011-06-28 20:37:31 -0700210 final Dialog dialog = builder.create();
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700211
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700212
213 // getTargetPackage guarantees that the returned string is
214 // supplied by the system, so that an application can not
215 // spoof its package.
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700216 String pkg = mSender.getIntentSender().getTargetPackage();
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700217 PackageManager pm = getPackageManager();
218 CharSequence applicationLabel;
219 try {
220 applicationLabel = pm.getApplicationLabel(pm.getApplicationInfo(pkg, 0)).toString();
221 } catch (PackageManager.NameNotFoundException e) {
222 applicationLabel = pkg;
223 }
224 String appMessage = String.format(res.getString(R.string.requesting_application),
225 applicationLabel);
226
227 String contextMessage = appMessage;
228 String host = getIntent().getStringExtra(KeyChain.EXTRA_HOST);
229 if (host != null) {
230 String hostString = host;
231 int port = getIntent().getIntExtra(KeyChain.EXTRA_PORT, -1);
232 if (port != -1) {
233 hostString += ":" + port;
234 }
235 String hostMessage = String.format(res.getString(R.string.requesting_server),
236 hostString);
237 if (contextMessage == null) {
238 contextMessage = hostMessage;
239 } else {
240 contextMessage += " " + hostMessage;
241 }
242 }
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700243 contextView.setText(contextMessage);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700244
245 String installMessage = String.format(res.getString(R.string.install_new_cert_message),
246 Credentials.EXTENSION_PFX, Credentials.EXTENSION_P12);
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700247 TextView installText = (TextView) footer.findViewById(R.id.cert_chooser_install_message);
248 installText.setText(installMessage);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700249
Brian Carlstrom4bf9e1a2011-06-28 21:45:31 -0700250 Button installButton = (Button) footer.findViewById(R.id.cert_chooser_install_button);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700251 installButton.setOnClickListener(new View.OnClickListener() {
252 @Override public void onClick(View v) {
253 // remove dialog so that we will recreate with
254 // possibly new content after install returns
Brian Carlstrom91940e72011-06-28 20:37:31 -0700255 dialog.dismiss();
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700256 Credentials.getInstance().install(KeyChainActivity.this);
257 }
258 });
259
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700260 dialog.setOnCancelListener(new DialogInterface.OnCancelListener() {
261 @Override public void onCancel(DialogInterface dialog) {
262 finish(null);
263 }
264 });
Brian Carlstrom91940e72011-06-28 20:37:31 -0700265 dialog.show();
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700266 }
267
268 private class CertificateAdapter extends BaseAdapter {
269 private final List<String> mAliases;
270 private final List<String> mSubjects = new ArrayList<String>();
271 private CertificateAdapter(List<String> aliases) {
272 mAliases = aliases;
273 mSubjects.addAll(Collections.nCopies(aliases.size(), (String) null));
274 }
275 @Override public int getCount() {
276 return mAliases.size();
277 }
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700278 @Override public String getItem(int adapterPosition) {
279 return mAliases.get(adapterPosition);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700280 }
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700281 @Override public long getItemId(int adapterPosition) {
282 return adapterPosition;
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700283 }
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700284 @Override public View getView(final int adapterPosition, View view, ViewGroup parent) {
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700285 ViewHolder holder;
286 if (view == null) {
287 LayoutInflater inflater = LayoutInflater.from(KeyChainActivity.this);
288 view = inflater.inflate(R.layout.cert_item, parent, false);
289 holder = new ViewHolder();
290 holder.mAliasTextView = (TextView) view.findViewById(R.id.cert_item_alias);
291 holder.mSubjectTextView = (TextView) view.findViewById(R.id.cert_item_subject);
292 holder.mRadioButton = (RadioButton) view.findViewById(R.id.cert_item_selected);
293 view.setTag(holder);
294 } else {
295 holder = (ViewHolder) view.getTag();
296 }
297
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700298 String alias = mAliases.get(adapterPosition);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700299
300 holder.mAliasTextView.setText(alias);
301
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700302 String subject = mSubjects.get(adapterPosition);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700303 if (subject == null) {
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700304 new CertLoader(adapterPosition, holder.mSubjectTextView).execute();
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700305 } else {
306 holder.mSubjectTextView.setText(subject);
307 }
308
309 ListView lv = (ListView)parent;
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700310 int listViewCheckedItemPosition = lv.getCheckedItemPosition();
311 int adapterCheckedItemPosition = listViewCheckedItemPosition-1;
312 holder.mRadioButton.setChecked(adapterPosition == adapterCheckedItemPosition);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700313 return view;
314 }
315
316 private class CertLoader extends AsyncTask<Void, Void, String> {
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700317 private final int mAdapterPosition;
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700318 private final TextView mSubjectView;
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700319 private CertLoader(int adapterPosition, TextView subjectView) {
320 mAdapterPosition = adapterPosition;
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700321 mSubjectView = subjectView;
322 }
323 @Override protected String doInBackground(Void... params) {
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700324 String alias = mAliases.get(mAdapterPosition);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700325 byte[] bytes = mKeyStore.get(Credentials.USER_CERTIFICATE + alias);
326 if (bytes == null) {
327 return null;
328 }
329 InputStream in = new ByteArrayInputStream(bytes);
330 X509Certificate cert;
331 try {
332 CertificateFactory cf = CertificateFactory.getInstance("X.509");
333 cert = (X509Certificate)cf.generateCertificate(in);
334 } catch (CertificateException ignored) {
335 return null;
336 }
337 // bouncycastle can handle the emailAddress OID of 1.2.840.113549.1.9.1
338 X500Principal subjectPrincipal = cert.getSubjectX500Principal();
339 X509Name subjectName = X509Name.getInstance(subjectPrincipal.getEncoded());
340 String subjectString = subjectName.toString(true, X509Name.DefaultSymbols);
341 return subjectString;
342 }
343 @Override protected void onPostExecute(String subjectString) {
Brian Carlstrom5dd41f62011-06-29 18:51:34 -0700344 mSubjects.set(mAdapterPosition, subjectString);
Brian Carlstrom65e649e2011-06-24 02:13:28 -0700345 mSubjectView.setText(subjectString);
346 }
347 }
348 }
349
350 private static class ViewHolder {
351 TextView mAliasTextView;
352 TextView mSubjectTextView;
353 RadioButton mRadioButton;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700354 }
355
356 @Override protected void onActivityResult(int requestCode, int resultCode, Intent data) {
357 switch (requestCode) {
358 case REQUEST_UNLOCK:
Kenny Root4ff22962013-02-14 10:17:06 -0800359 if (mKeyStore.isUnlocked()) {
Brian Carlstrom91940e72011-06-28 20:37:31 -0700360 showCertChooserDialog();
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700361 } else {
362 // user must have canceled unlock, give up
Brian Carlstrombb04f702011-05-24 21:54:51 -0700363 finish(null);
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700364 }
365 return;
366 default:
367 throw new AssertionError();
368 }
369 }
370
Brian Carlstrombb04f702011-05-24 21:54:51 -0700371 private void finish(String alias) {
372 if (alias == null) {
373 setResult(RESULT_CANCELED);
374 } else {
375 Intent result = new Intent();
376 result.putExtra(Intent.EXTRA_TEXT, alias);
377 setResult(RESULT_OK, result);
378 }
Brian Carlstromf5b50a42011-06-09 16:05:09 -0700379 IKeyChainAliasCallback keyChainAliasResponse
380 = IKeyChainAliasCallback.Stub.asInterface(
Brian Carlstrombb04f702011-05-24 21:54:51 -0700381 getIntent().getIBinderExtra(KeyChain.EXTRA_RESPONSE));
382 if (keyChainAliasResponse != null) {
Brian Carlstrom7d9aa752011-07-07 11:52:27 -0700383 new ResponseSender(keyChainAliasResponse, alias).execute();
384 return;
385 }
386 finish();
387 }
388
389 private class ResponseSender extends AsyncTask<Void, Void, Void> {
390 private IKeyChainAliasCallback mKeyChainAliasResponse;
391 private String mAlias;
392 private ResponseSender(IKeyChainAliasCallback keyChainAliasResponse, String alias) {
393 mKeyChainAliasResponse = keyChainAliasResponse;
394 mAlias = alias;
395 }
396 @Override protected Void doInBackground(Void... unused) {
Brian Carlstrombb04f702011-05-24 21:54:51 -0700397 try {
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700398 if (mAlias != null) {
399 KeyChain.KeyChainConnection connection = KeyChain.bind(KeyChainActivity.this);
400 try {
401 connection.getService().setGrant(mSenderUid, mAlias, true);
402 } finally {
403 connection.close();
404 }
405 }
Brian Carlstrom7d9aa752011-07-07 11:52:27 -0700406 mKeyChainAliasResponse.alias(mAlias);
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700407 } catch (InterruptedException ignored) {
408 Thread.currentThread().interrupt();
409 Log.d(TAG, "interrupted while granting access", ignored);
Brian Carlstrom2a858832011-05-26 09:30:26 -0700410 } catch (Exception ignored) {
411 // don't just catch RemoteException, caller could
412 // throw back a RuntimeException across processes
413 // which we should protect against.
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700414 Log.e(TAG, "error while granting access", ignored);
Brian Carlstrombb04f702011-05-24 21:54:51 -0700415 }
Brian Carlstrom7d9aa752011-07-07 11:52:27 -0700416 return null;
Brian Carlstrombb04f702011-05-24 21:54:51 -0700417 }
Brian Carlstrom7d9aa752011-07-07 11:52:27 -0700418 @Override protected void onPostExecute(Void unused) {
419 finish();
420 }
Brian Carlstrombb04f702011-05-24 21:54:51 -0700421 }
422
Brian Carlstrom9e606df2011-06-07 12:03:08 -0700423 @Override public void onBackPressed() {
424 finish(null);
425 }
426
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700427 @Override protected void onSaveInstanceState(Bundle savedState) {
428 super.onSaveInstanceState(savedState);
429 if (mState != State.INITIAL) {
430 savedState.putSerializable(KEY_STATE, mState);
431 }
432 }
433}