Chris Rankin c545a58c1d
Remote Attestation Phase 2 (#235)
* Initial host server skeleton.
* Create IASProxy project, and skeleton for attestation host.
* Fix up tests
* Extend attestation host skeleton, and make test ports configurable.
* Enhance MockIAS to make pseManifestStatus optional.
* Make IASProxy endpoints asynchronous.
* Add sub-modules for challenger and for common code.
* Create integration test for host's provisioning endpoint.
* Flesh out attestation challenger WAR.
* Package refactoring, to be more Java9 friendly.
* Refactor more messages into attestation-common.
* Remove our private key from the repository.
* Declare an empty PSE Manifest to be invalid.
* Fix basic integration test issues for challenger and host.
* Integrate keystore scripts into the build properly.
* Name keystore targets explicitly for Gradle.
* Allow HTTP conversation between Challenger, Host and ISV using session ID.
* Add MockHost for challenger's integration tests.
* Reconcile HTTP port numbers between Phase1 and Phase2 components.
* Remove elements that can be inherited from root project.
* Add placeholder README.
* Add convenient extension functions to ObjectMapper.
* Extend integration test coverage for challenger/host/isv.
* Catch IOException from HttpClient for challenger.
* Integrate host sub-module with remote-attestation project.
* Begin integrating host/enclave code from Phase I.
* Rename challenger's HTTP endpoint.
* Generate keystore for challenger "on the fly".
* Add native JNI code for accessing the SGX enclave.
* Point Gradle to the correct enclave object.
* Fixes for generating a Quote for this enclave.
* Return the IAS report to the challenger for verification.
* Begin populating the challenger's AttestationResponse message.
* Enable the challenger to pass encrypted secrets into the enclave.
* Align challenger, host and isv ports.
* Refactor challenger as a fat-jar application.
* AttestationResponse is not shared, so refactor into challenger.
* Move HttpClientContext objects into HttpClient blocks.
* Remove unused Message2 and Message3 objects.
* Add realistic dummy value for reportID from IAS.
* Small tidy-up on attestation host.
* First set of review comments.
* Add missing exception message.
* Update location of environment file.
* Use empty mock revocation lists by default.
* Improve logging and add "happy path" test for provisioning secrets.
* Update Gradle files so that we can run attestation-host from IntelliJ.
* The platformInfo field from IAS can be null, so allow this.
Also protect other JNI pointer parameters from NPE.
* Allow Gradle to build hardware enclave.
2017-12-22 14:42:42 +00:00

186 lines
6.2 KiB
Groovy

buildscript {
ext.keyStoreDir = "$buildDir/keystore"
ext.nativeBuildDir = "$projectDir/native/build"
ext.enclaveBuildDir = "$projectDir/../enclave/build"
ext.hardware = project.hasProperty("hardware") && (ext.hardware == "1" || ext.hardware == "yes" || ext.hardware == "true")
ext.debug = project.hasProperty("debug") && (ext.debug == "1" || ext.debug == "yes" || ext.debug == "true")
if (!project.hasProperty("debugPort")) {
ext.debugPort = 5005
} else {
ext.debugPort = Integer.parseInt(ext.debugPort.toString())
}
if (ext.debug) {
ext.debugArgs = "-agentlib:jdwp=transport=dt_socket,server=y,suspend=y,timeout=10000,address=$debugPort"
} else {
ext.debugArgs = "-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=$debugPort"
}
}
apply from: 'utilities.gradle'
apply plugin: 'kotlin'
apply plugin: 'war'
apply plugin: 'org.akhikhl.gretty'
description 'Proof-of-Concept Remote Attestation Host'
import org.akhikhl.gretty.AppStartTask
import org.akhikhl.gretty.AppStopTask
configurations {
integrationTestCompile.extendsFrom testCompile
integrationTestRuntime.extendsFrom testRuntime
}
sourceSets {
integrationTest {
kotlin {
compileClasspath += main.compileClasspath + test.compileClasspath
runtimeClasspath += main.runtimeClasspath + test.runtimeClasspath
//noinspection GroovyAssignabilityCheck
srcDir file('src/integration-test/kotlin')
}
}
}
dependencies {
compile project(':attestation-common')
compile "org.jetbrains.kotlin:kotlin-stdlib-jre8:$kotlin_version"
compile "org.jetbrains.kotlin:kotlin-reflect:$kotlin_version"
testCompile "org.jetbrains.kotlin:kotlin-test-junit:$kotlin_version"
testCompile "junit:junit:$junit_version"
compile "org.bouncycastle:bcpkix-jdk15on:$bouncycastle_version"
compile "org.jboss.resteasy:resteasy-jaxrs:$resteasy_version"
compile "org.jboss.resteasy:resteasy-jackson2-provider:$resteasy_version"
compile "org.jboss.resteasy:resteasy-servlet-initializer:$resteasy_version"
compile "com.fasterxml.jackson.core:jackson-core:$jackson_version"
compile "com.fasterxml.jackson.core:jackson-databind:$jackson_version"
compile "com.fasterxml.jackson.core:jackson-annotations:$jackson_version"
compile "com.fasterxml.jackson.datatype:jackson-datatype-jsr310:$jackson_version"
compile "org.apache.httpcomponents:httpclient:$httpclient_version"
compile "org.apache.logging.log4j:log4j-slf4j-impl:$log4j_version"
compile "org.apache.logging.log4j:log4j-core:$log4j_version"
runtime "org.apache.logging.log4j:log4j-web:$log4j_version"
compile "org.slf4j:jcl-over-slf4j:$slf4j_version"
testCompile project(path: ':attestation-common', configuration: 'testArtifacts')
}
task createMockKeyStores(type: Exec) {
doFirst {
mkdir keyStoreDir
}
inputs.dir "$projectDir/src/main/ssl/mockisv"
outputs.files "$keyStoreDir/dummyIAS.pfx", "$keyStoreDir/dummyIAS-trust.pfx"
workingDir keyStoreDir
commandLine "$projectDir/src/main/ssl/mockisv/generate-keystores.sh"
}
processResources {
dependsOn createMockKeyStores
from keyStoreDir
}
tasks.withType(Test) {
// Enable "unlimited" encryption.
systemProperties["java.security.properties"] = "$projectDir/src/main/security.properties"
// Location of JNI object.
systemProperties["java.library.path"] = nativeBuildDir
// Location of enclave object.
systemProperties["corda.sgx.enclave.path"] = enclaveBuildDir
// Allow us to connect to JVM within enclave
jvmArgs debugArgs
}
task integrationTest(type: Test) {
testClassesDirs = sourceSets.integrationTest.output.classesDirs
classpath = sourceSets.integrationTest.runtimeClasspath
systemProperties["test.httpPort"] = testHttpPort
}
gretty {
httpPort = testHttpPort
contextPath = "/"
servletContainer = 'tomcat8'
logDir = "$buildDir/logs"
logFileName = "gretty-test"
integrationTestTask = 'integrationTest'
jvmArgs = [
"-Dorg.jboss.logging.provider=slf4j",
"-Djava.security.properties=$projectDir/src/main/security.properties",
"-Dattestation.home=$buildDir/logs",
"-Disv.host=localhost:$testHttpPort/mockisv",
"-Djava.library.path=$nativeBuildDir",
"-Dcorda.sgx.enclave.path=$enclaveBuildDir",
]
}
task('startHost', type: AppStartTask, dependsOn: war) {
prepareServerConfig {
httpPort = hostHttpPort
servletContainer = 'tomcat8'
logDir = "$buildDir/logs"
logFileName = "gretty-host"
jvmArgs = [
"-Dorg.jboss.logging.provider=slf4j",
"-Djava.security.properties=$projectDir/src/main/security.properties",
"-Dattestation.home=$buildDir/logs",
"-Disv.host=localhost:$isvHttpPort",
"-Djava.library.path=$nativeBuildDir",
"-Dcorda.sgx.enclave.path=$enclaveBuildDir",
]
}
prepareWebAppConfig {
contextPath = "/"
inplace = false
}
interactive = false
}
task("stopHost", type: AppStopTask)
task cleanEnclave(type: Exec) {
commandLine containerArgs("enclave", "clean")
}
task cleanJniLibrary(type: Exec) {
commandLine containerArgs("attestation-host/native", "clean")
}
clean.dependsOn.addAll cleanEnclave, cleanJniLibrary
task buildEnclave(type: Exec) {
commandLine containerArgs("enclave", "all")
}
task buildJniLibrary(type: Exec, dependsOn: [buildEnclave, classes]) {
commandLine containerArgs("attestation-host/native", "all")
}
build.dependsOn.addAll buildJniLibrary
task runUnitTestsInContainer(type: Task, dependsOn: buildJniLibrary) {
doLast { containerDebugWait(projectDir, "attestation-host", "unit-tests") }
}
task runIntegrationTestsInContainer(type: Task, dependsOn: buildJniLibrary) {
doLast { containerDebugWait(projectDir, "attestation-host", "integration-tests") }
}
task debugUnitTestsInContainer(type: Task, dependsOn: buildJniLibrary) {
doLast { containerDebugWait(projectDir, "attestation-host", "DEBUG=1", "unit-tests") }
}
task debugIntegrationTestsInContainer(type: Task, dependsOn: buildJniLibrary) {
doLast { containerDebugWait(projectDir, "attestation-host", "DEBUG=1", "integration-tests") }
}