Class SSLContextBuilder


  • public final class SSLContextBuilder
    extends Object
    An SSL context builder provides an interface for incrementally constructing SSLContext instances for use when securing connections with SSL or the StartTLS extended operation. The getSSLContext() should be called in order to obtain the SSLContext.

    For example, use the SSL context builder when setting up LDAP options needed to use StartTLS. TrustManagers has methods you can use to set the trust manager for the SSL context builder.

     LDAPOptions options = new LDAPOptions();
     SSLContext sslContext =
             new SSLContextBuilder().setTrustManager(...).getSSLContext();
     options.setSSLContext(sslContext);
     options.setUseStartTLS(true);
    
     String host = ...;
     int port = ...;
     LDAPConnectionFactory factory = new LDAPConnectionFactory(host, port, options);
     Connection connection = factory.getConnection();
     // Connection uses StartTLS...
     
    • Field Detail

      • PROTOCOL_SSL

        public static final String PROTOCOL_SSL
        SSL protocol: supports some version of SSL; may support other versions.
        See Also:
        Constant Field Values
      • PROTOCOL_SSL2

        public static final String PROTOCOL_SSL2
        SSL protocol: supports SSL version 2 or higher; may support other versions.
        See Also:
        Constant Field Values
      • PROTOCOL_SSL3

        public static final String PROTOCOL_SSL3
        SSL protocol: supports SSL version 3; may support other versions.
        See Also:
        Constant Field Values
      • PROTOCOL_TLS

        public static final String PROTOCOL_TLS
        SSL protocol: supports some version of TLS; may support other versions.
        See Also:
        Constant Field Values
      • PROTOCOL_TLS1

        public static final String PROTOCOL_TLS1
        SSL protocol: supports RFC 2246: TLS version 1.0 ; may support other versions.

        This is the default version.

        See Also:
        Constant Field Values
      • PROTOCOL_TLS1_1

        public static final String PROTOCOL_TLS1_1
        SSL protocol: supports RFC 4346: TLS version 1.1 ; may support other versions.
        See Also:
        Constant Field Values
      • PROTOCOL_TLS1_2

        public static final String PROTOCOL_TLS1_2
        SSL protocol: supports RFC 5246: TLS version 1.2 ; may support other versions.
        See Also:
        Constant Field Values
    • Constructor Detail

      • SSLContextBuilder

        public SSLContextBuilder()
        Creates a new SSL context builder using default parameters.
    • Method Detail

      • getSSLContext

        public SSLContext getSSLContext()
                                 throws GeneralSecurityException
        Creates a SSLContext using the parameters of this SSL context builder.
        Returns:
        A SSLContext using the parameters of this SSL context builder.
        Throws:
        GeneralSecurityException - If the SSL context could not be created, perhaps due to missing algorithms.
      • setKeyManager

        public SSLContextBuilder setKeyManager​(KeyManager keyManager)
        Sets the key manager which the SSL context should use. By default, the JVM's key manager is used.
        Parameters:
        keyManager - The key manager which the SSL context should use, which may be null indicating that no certificates will be used.
        Returns:
        This SSL context builder.
      • setProtocol

        public SSLContextBuilder setProtocol​(String protocol)
        Sets the protocol which the SSL context should use. By default, TLSv1 will be used.
        Parameters:
        protocol - The protocol which the SSL context should use, which may be null indicating that TLSv1 will be used.
        Returns:
        This SSL context builder.
      • setProvider

        public SSLContextBuilder setProvider​(Provider provider)
        Sets the provider which the SSL context should use. By default, the default provider associated with this JVM will be used.
        Parameters:
        provider - The provider which the SSL context should use, which may be null indicating that the default provider associated with this JVM will be used.
        Returns:
        This SSL context builder.
      • setProvider

        public SSLContextBuilder setProvider​(String providerName)
        Sets the provider which the SSL context should use. By default, the default provider associated with this JVM will be used.
        Parameters:
        providerName - The name of the provider which the SSL context should use, which may be null indicating that the default provider associated with this JVM will be used.
        Returns:
        This SSL context builder.
      • setSecureRandom

        public SSLContextBuilder setSecureRandom​(SecureRandom random)
        Sets the secure random number generator which the SSL context should use. By default, the default secure random number generator associated with this JVM will be used.
        Parameters:
        random - The secure random number generator which the SSL context should use, which may be null indicating that the default secure random number generator associated with this JVM will be used.
        Returns:
        This SSL context builder.
      • setTrustManager

        public SSLContextBuilder setTrustManager​(TrustManager trustManager)
        Sets the trust manager which the SSL context should use. By default, no trust manager is specified indicating that only certificates signed by the authorities associated with this JVM will be accepted.
        Parameters:
        trustManager - The trust manager which the SSL context should use, which may be null indicating that only certificates signed by the authorities associated with this JVM will be accepted.
        Returns:
        This SSL context builder.