Package org.forgerock.opendj.ldap
Class SSLContextBuilder
- java.lang.Object
-
- org.forgerock.opendj.ldap.SSLContextBuilder
-
public final class SSLContextBuilder extends Object
An SSL context builder provides an interface for incrementally constructingSSLContextinstances for use when securing connections with SSL or the StartTLS extended operation. ThegetSSLContext()should be called in order to obtain theSSLContext.For example, use the SSL context builder when setting up LDAP options needed to use StartTLS.
TrustManagershas methods you can use to set the trust manager for the SSL context builder.LDAPOptions options = new LDAPOptions(); SSLContext sslContext = new SSLContextBuilder().setTrustManager(...).getSSLContext(); options.setSSLContext(sslContext); options.setUseStartTLS(true); String host = ...; int port = ...; LDAPConnectionFactory factory = new LDAPConnectionFactory(host, port, options); Connection connection = factory.getConnection(); // Connection uses StartTLS...
-
-
Field Summary
Fields Modifier and Type Field Description static StringPROTOCOL_SSLSSL protocol: supports some version of SSL; may support other versions.static StringPROTOCOL_SSL2SSL protocol: supports SSL version 2 or higher; may support other versions.static StringPROTOCOL_SSL3SSL protocol: supports SSL version 3; may support other versions.static StringPROTOCOL_TLSSSL protocol: supports some version of TLS; may support other versions.static StringPROTOCOL_TLS1SSL protocol: supports RFC 2246: TLS version 1.0 ; may support other versions.static StringPROTOCOL_TLS1_1SSL protocol: supports RFC 4346: TLS version 1.1 ; may support other versions.static StringPROTOCOL_TLS1_2SSL protocol: supports RFC 5246: TLS version 1.2 ; may support other versions.
-
Constructor Summary
Constructors Constructor Description SSLContextBuilder()Creates a new SSL context builder using default parameters.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description SSLContextgetSSLContext()Creates aSSLContextusing the parameters of this SSL context builder.SSLContextBuildersetKeyManager(KeyManager keyManager)Sets the key manager which the SSL context should use.SSLContextBuildersetProtocol(String protocol)Sets the protocol which the SSL context should use.SSLContextBuildersetProvider(String providerName)Sets the provider which the SSL context should use.SSLContextBuildersetProvider(Provider provider)Sets the provider which the SSL context should use.SSLContextBuildersetSecureRandom(SecureRandom random)Sets the secure random number generator which the SSL context should use.SSLContextBuildersetTrustManager(TrustManager trustManager)Sets the trust manager which the SSL context should use.
-
-
-
Field Detail
-
PROTOCOL_SSL
public static final String PROTOCOL_SSL
SSL protocol: supports some version of SSL; may support other versions.- See Also:
- Constant Field Values
-
PROTOCOL_SSL2
public static final String PROTOCOL_SSL2
SSL protocol: supports SSL version 2 or higher; may support other versions.- See Also:
- Constant Field Values
-
PROTOCOL_SSL3
public static final String PROTOCOL_SSL3
SSL protocol: supports SSL version 3; may support other versions.- See Also:
- Constant Field Values
-
PROTOCOL_TLS
public static final String PROTOCOL_TLS
SSL protocol: supports some version of TLS; may support other versions.- See Also:
- Constant Field Values
-
PROTOCOL_TLS1
public static final String PROTOCOL_TLS1
SSL protocol: supports RFC 2246: TLS version 1.0 ; may support other versions.This is the default version.
- See Also:
- Constant Field Values
-
PROTOCOL_TLS1_1
public static final String PROTOCOL_TLS1_1
SSL protocol: supports RFC 4346: TLS version 1.1 ; may support other versions.- See Also:
- Constant Field Values
-
PROTOCOL_TLS1_2
public static final String PROTOCOL_TLS1_2
SSL protocol: supports RFC 5246: TLS version 1.2 ; may support other versions.- See Also:
- Constant Field Values
-
-
Method Detail
-
getSSLContext
public SSLContext getSSLContext() throws GeneralSecurityException
Creates aSSLContextusing the parameters of this SSL context builder.- Returns:
- A
SSLContextusing the parameters of this SSL context builder. - Throws:
GeneralSecurityException- If the SSL context could not be created, perhaps due to missing algorithms.
-
setKeyManager
public SSLContextBuilder setKeyManager(KeyManager keyManager)
Sets the key manager which the SSL context should use. By default, the JVM's key manager is used.- Parameters:
keyManager- The key manager which the SSL context should use, which may benullindicating that no certificates will be used.- Returns:
- This SSL context builder.
-
setProtocol
public SSLContextBuilder setProtocol(String protocol)
Sets the protocol which the SSL context should use. By default, TLSv1 will be used.- Parameters:
protocol- The protocol which the SSL context should use, which may benullindicating that TLSv1 will be used.- Returns:
- This SSL context builder.
-
setProvider
public SSLContextBuilder setProvider(Provider provider)
Sets the provider which the SSL context should use. By default, the default provider associated with this JVM will be used.- Parameters:
provider- The provider which the SSL context should use, which may benullindicating that the default provider associated with this JVM will be used.- Returns:
- This SSL context builder.
-
setProvider
public SSLContextBuilder setProvider(String providerName)
Sets the provider which the SSL context should use. By default, the default provider associated with this JVM will be used.- Parameters:
providerName- The name of the provider which the SSL context should use, which may benullindicating that the default provider associated with this JVM will be used.- Returns:
- This SSL context builder.
-
setSecureRandom
public SSLContextBuilder setSecureRandom(SecureRandom random)
Sets the secure random number generator which the SSL context should use. By default, the default secure random number generator associated with this JVM will be used.- Parameters:
random- The secure random number generator which the SSL context should use, which may benullindicating that the default secure random number generator associated with this JVM will be used.- Returns:
- This SSL context builder.
-
setTrustManager
public SSLContextBuilder setTrustManager(TrustManager trustManager)
Sets the trust manager which the SSL context should use. By default, no trust manager is specified indicating that only certificates signed by the authorities associated with this JVM will be accepted.- Parameters:
trustManager- The trust manager which the SSL context should use, which may benullindicating that only certificates signed by the authorities associated with this JVM will be accepted.- Returns:
- This SSL context builder.
-
-