Package org.opends.admin.ads.util
Class ApplicationTrustManager
- java.lang.Object
-
- org.opends.admin.ads.util.ApplicationTrustManager
-
- All Implemented Interfaces:
TrustManager,X509TrustManager
- Direct Known Subclasses:
BlindApplicationTrustManager
public class ApplicationTrustManager extends Object implements X509TrustManager
This class is in charge of checking whether the certificates that are presented are trusted or not. This implementation tries to check also that the subject DN of the certificate corresponds to the host passed using the setHostName method. The constructor tries to use a default TrustManager from the system and if it cannot be retrieved this class will only accept the certificates explicitly accepted by the user (and specified by calling acceptCertificate). NOTE: this class is not aimed to be used when we have connections in parallel.
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description static classApplicationTrustManager.CauseThe enumeration for the different causes for which the trust manager can refuse to accept a certificate.
-
Constructor Summary
Constructors Constructor Description ApplicationTrustManager(KeyStore keystore)The default constructor.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidacceptCertificate(X509Certificate[] chain, String authType, String host)This method is called when the user accepted a certificate.voidcheckClientTrusted(X509Certificate[] chain, String authType)voidcheckServerTrusted(X509Certificate[] chain, String authType)ApplicationTrustManagercreateCopy()Creates a copy of this ApplicationTrustManager.X509Certificate[]getAcceptedIssuers()StringgetLastRefusedAuthType()Returns the authentication type for the last refused certificate.ApplicationTrustManager.CausegetLastRefusedCause()Returns the last cause for refusal of a certificate.X509Certificate[]getLastRefusedChain()Returns the certificate chain for the last refused certificate.X509TrustManagergetX509TrustManager()voidresetLastRefusedItems()This is a method used to set to null the different members that provide information about the last refused certificate.voidsetHost(String host)Sets the host name we are trying to contact in a secure mode.
-
-
-
Constructor Detail
-
ApplicationTrustManager
public ApplicationTrustManager(KeyStore keystore)
The default constructor.- Parameters:
keystore- The keystore to use for this trustmanager.
-
-
Method Detail
-
checkClientTrusted
public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException
- Specified by:
checkClientTrustedin interfaceX509TrustManager- Throws:
CertificateException
-
checkServerTrusted
public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException
- Specified by:
checkServerTrustedin interfaceX509TrustManager- Throws:
CertificateException
-
getAcceptedIssuers
public X509Certificate[] getAcceptedIssuers()
- Specified by:
getAcceptedIssuersin interfaceX509TrustManager
-
acceptCertificate
public void acceptCertificate(X509Certificate[] chain, String authType, String host)
This method is called when the user accepted a certificate.- Parameters:
chain- the certificate chain accepted by the user.authType- the authentication type.host- the host we tried to connect and that presented the certificate.
-
setHost
public void setHost(String host)
Sets the host name we are trying to contact in a secure mode. This method is used if we want to verify the correspondence between the hostname and the subject DN of the certificate that is being presented. If this method is never called (or called passing null) no verification will be made on the host name.- Parameters:
host- the host name we are trying to contact in a secure mode.
-
resetLastRefusedItems
public void resetLastRefusedItems()
This is a method used to set to null the different members that provide information about the last refused certificate. It is recommended to call this method before trying to establish a connection using this trust manager.
-
createCopy
public ApplicationTrustManager createCopy()
Creates a copy of this ApplicationTrustManager.- Returns:
- a copy of this ApplicationTrustManager.
-
getLastRefusedAuthType
public String getLastRefusedAuthType()
Returns the authentication type for the last refused certificate.- Returns:
- the authentication type for the last refused certificate.
-
getLastRefusedCause
public ApplicationTrustManager.Cause getLastRefusedCause()
Returns the last cause for refusal of a certificate.- Returns:
- the last cause for refusal of a certificate.
-
getLastRefusedChain
public X509Certificate[] getLastRefusedChain()
Returns the certificate chain for the last refused certificate.- Returns:
- the certificate chain for the last refused certificate.
-
getX509TrustManager
public X509TrustManager getX509TrustManager()
-
-