/*
 * Copyright 2002 Sun Microsystems, Inc. All rights reserved.
 * SUN PROPRIETARY/CONFIDENTIAL. Use is subject to license terms.
 */

/*
 * @(#)SunRILoginContext.java	1.9 02/01/12
 */

package com.sun.cts.implementation.sun;

import com.sun.cts.porting.*;

// Implementation Specific Classes
import com.sun.enterprise.security.LoginContext;
import com.sun.enterprise.security.LoginException;
import com.sun.cts.util.*;
import java.io.*;
import java.security.KeyStore;
import java.security.cert.*;

/**
 * CTSLoginContext provides the implementation specific code for
 * allowing a program to login as a specific user. This class is
 * implemented as a wrapper class around Sun's login implementation
 * code.
 */
public class SunRILoginContext implements CTSLoginContextInterface {

    private LoginContext lctx;

    /**
     * Provides the LoginContext needed to perform a login.
     * 
     */
    public SunRILoginContext() throws Exception
    {
	lctx = new LoginContext();
    }

    /** 
     * Performs the login functionality.
     * 
     *  @param usr	the username to login
     *  @param pwd	the password of user
     */ 
    public void login(String usr, String pwd) throws Exception
    {
		lctx.login(usr, pwd);
    }


    /** This login method is used for Certificate based login
     * 
     *  Note: This method also uses keystore and keystore password from
     *        the CTS configuration file
     *  
     *  @param alias - alias is used to pick up the certificate from keystore
     */
    public void login(String useralias) throws Exception
    { 

       // get  keystore instance
	KeyStore ks = KeyStore.getInstance("JKS");

       // get keystore file 
        String keystoreFile = System.getProperty("javax.net.ssl.keyStore");

        if(keystoreFile == null)
		throw new Exception("Client authentication keystore  not found");

        // get keystore password
        String keyPass= System.getProperty("javax.net.ssl.keyStorePassword");

        if(keyPass ==null)
                keyPass="changeit"; //use default keystore password

        login(useralias, keystoreFile, keyPass);

    }

    /** This login method is used for Certificate based login
     * 
     *  @param alias - alias is used to pick up the certificate from keystore
     *  @param keystore - keystore file
     *  @param keyPass - keystore password
     */ 
    public void login(String useralias, String keystore, String keyPass) throws Exception
    { 
        FileInputStream istream=null; 
        char[] passphrase = null;

       // get  keystore instance
	KeyStore ks = KeyStore.getInstance("JKS");

       // get keystore file 
        String keystoreFile = keystore;
        TestUtil.logMsg("Client authentication key store file = " + keystoreFile);

        if(keystoreFile != null)
        	istream = new FileInputStream(keystoreFile);
	else
		throw new Exception("Client authentication keystore  not found");

        // Check for key password 
        if(keyPass ==null)
                keyPass="changeit"; //use default keystore password
        passphrase = keyPass.toCharArray();

        // load keystore
        ks.load(new FileInputStream(keystoreFile), passphrase);
        istream.close();

        // get Certificate from useralias
        TestUtil.logMsg("Useralias " + useralias);
        X509Certificate certificate = (X509Certificate)ks.getCertificate(useralias);
	if (certificate !=null)
	{
        	TestUtil.logMsg("Certificate type" + certificate.getType());
        	TestUtil.logMsg("Certificate IssuerDN" + certificate.getIssuerDN().getName());
	}
	else
	{
		TestUtil.logMsg("Certificate not found");
		throw new Exception("Certificate with useralias "+useralias+ " not found");
	}

        // Calls to RI's LoginContext.login(useralias, authdata[])
        // is removed because now the authentication takes place over JSSE 
        //
        // ---Removed method calls to LoginContext.java ----- 
        //
        //call login with username and authdata 
        //lctx.setRealmName("certificate");
        //lctx.setAuthenticationMethod("certificate");
        //lctx.login(useralias, certificate.getEncoded() );
  }


}
