Class SecurityOptions


  • public class SecurityOptions
    extends Object
    Class used to describe the Security Options specified by the user.
    • Field Detail

      • SELF_SIGNED_CERT_ALIAS

        public static final String SELF_SIGNED_CERT_ALIAS
        Alias of a self-signed certificate.
        See Also:
        Constant Field Values
      • SELF_SIGNED_EC_CERT_ALIAS

        public static final String SELF_SIGNED_EC_CERT_ALIAS
        Alias of a self-signed certificate using elliptic curve.
        See Also:
        Constant Field Values
    • Method Detail

      • createNoCertificateOptions

        public static SecurityOptions createNoCertificateOptions()
        Creates a new instance of a SecurityOptions representing for no certificate (no SSL or Start TLS).
        Returns:
        a new instance of a SecurityOptions representing for no certificate (no SSL or Start TLS).
      • createSelfSignedCertificateOptions

        public static SecurityOptions createSelfSignedCertificateOptions​(boolean enableSSL,
                                                                         boolean enableStartTLS,
                                                                         int sslPort)
        Creates a new instance of a SecurityOptions using a self-signed certificate.
        Parameters:
        enableSSL - whether SSL is enabled or not.
        enableStartTLS - whether Start TLS is enabled or not.
        sslPort - the value of the LDAPS port.
        Returns:
        a new instance of a SecurityOptions using a self-signed certificate.
      • createJKSCertificateOptions

        public static SecurityOptions createJKSCertificateOptions​(String keystorePath,
                                                                  String keystorePwd,
                                                                  boolean enableSSL,
                                                                  boolean enableStartTLS,
                                                                  int sslPort,
                                                                  Collection<String> aliasesToUse)
        Creates a new instance of a SecurityOptions using a Java Key Store.
        Parameters:
        keystorePath - the path of the key store.
        keystorePwd - the password of the key store.
        enableSSL - whether SSL is enabled or not.
        enableStartTLS - whether Start TLS is enabled or not.
        sslPort - the value of the LDAPS port.
        aliasesToUse - the aliases of the certificates in the key store to be used.
        Returns:
        a new instance of a SecurityOptions using a Java Key Store.
      • createJCEKSCertificateOptions

        public static SecurityOptions createJCEKSCertificateOptions​(String keystorePath,
                                                                    String keystorePwd,
                                                                    boolean enableSSL,
                                                                    boolean enableStartTLS,
                                                                    int sslPort,
                                                                    Collection<String> aliasesToUse)
        Creates a new instance of a SecurityOptions using a JCE Key Store.
        Parameters:
        keystorePath - the path of the key store.
        keystorePwd - the password of the key store.
        enableSSL - whether SSL is enabled or not.
        enableStartTLS - whether Start TLS is enabled or not.
        sslPort - the value of the LDAPS port.
        aliasesToUse - the aliases of the certificates in the keystore to be used.
        Returns:
        a new instance of a SecurityOptions using a JCE Key Store.
      • createPKCS11CertificateOptions

        public static SecurityOptions createPKCS11CertificateOptions​(String keystorePwd,
                                                                     boolean enableSSL,
                                                                     boolean enableStartTLS,
                                                                     int sslPort,
                                                                     Collection<String> aliasesToUse)
        Creates a new instance of a SecurityOptions using a PKCS#11 Key Store.
        Parameters:
        keystorePwd - the password of the key store.
        enableSSL - whether SSL is enabled or not.
        enableStartTLS - whether Start TLS is enabled or not.
        sslPort - the value of the LDAPS port.
        aliasesToUse - the aliases of the certificates in the keystore to be used.
        Returns:
        a new instance of a SecurityOptions using a PKCS#11 Key Store.
      • createPKCS12CertificateOptions

        public static SecurityOptions createPKCS12CertificateOptions​(String keystorePath,
                                                                     String keystorePwd,
                                                                     boolean enableSSL,
                                                                     boolean enableStartTLS,
                                                                     int sslPort,
                                                                     Collection<String> aliasesToUse)
        Creates a new instance of a SecurityOptions using a PKCS#12 Key Store.
        Parameters:
        keystorePath - the path of the key store.
        keystorePwd - the password of the key store.
        enableSSL - whether SSL is enabled or not.
        enableStartTLS - whether Start TLS is enabled or not.
        sslPort - the value of the LDAPS port.
        aliasesToUse - the aliases of the certificates in the keystore to be used.
        Returns:
        a new instance of a SecurityOptions using a PKCS#12 Key Store.
      • createBCFKSCertificateOptions

        public static SecurityOptions createBCFKSCertificateOptions​(String keystorePath,
                                                                    String keystorePwd,
                                                                    boolean enableSSL,
                                                                    boolean enableStartTLS,
                                                                    int sslPort,
                                                                    Collection<String> aliasesToUse)
        Creates a new instance of a SecurityOptions using a BCFKS Key Store.
        Parameters:
        keystorePath - the path of the key store.
        keystorePwd - the password of the key store.
        enableSSL - whether SSL is enabled or not.
        enableStartTLS - whether Start TLS is enabled or not.
        sslPort - the value of the LDAPS port.
        aliasesToUse - the aliases of the certificates in the keystore to be used.
        Returns:
        a new instance of a SecurityOptions using a PKCS#12 Key Store.
      • createOptionsForCertificatType

        public static SecurityOptions createOptionsForCertificatType​(SecurityOptions.CertificateType certType,
                                                                     String keystorePath,
                                                                     String keystorePwd,
                                                                     boolean enableSSL,
                                                                     boolean enableStartTLS,
                                                                     int sslPort,
                                                                     Collection<String> aliasesToUse)
        Creates a new instance of a SecurityOptions using the provided type Key Store.
        Parameters:
        certType - The Key Store type.
        keystorePath - The path of the key store (may be @null).
        keystorePwd - The password of the key store.
        enableSSL - Whether SSL is enabled or not.
        enableStartTLS - Whether Start TLS is enabled or not.
        sslPort - The value of the LDAPS port.
        aliasesToUse - The aliases of the certificates in the keystore to be used.
        Returns:
        a new instance of a SecurityOptions.
      • getCertificateType

        public SecurityOptions.CertificateType getCertificateType()
        Returns the CertificateType for this instance.
        Returns:
        the CertificateType for this instance.
      • getEnableSSL

        public boolean getEnableSSL()
        Returns whether SSL is enabled or not.
        Returns:
        true if SSL is enabled and false otherwise.
      • getEnableStartTLS

        public boolean getEnableStartTLS()
        Returns whether StartTLS is enabled or not.
        Returns:
        true if StartTLS is enabled and false otherwise.
      • getKeystorePassword

        public String getKeystorePassword()
        Returns the key store password.
        Returns:
        the key store password.
      • getKeystorePath

        public String getKeystorePath()
        Returns the key store path.
        Returns:
        the key store path.
      • getSslPort

        public int getSslPort()
        Returns the SSL port.
        Returns:
        the SSL port.
      • getAliasesToUse

        public Set<String> getAliasesToUse()
        Returns the alias of the certificate in the key store to be used.
        Returns:
        the alias of the certificate in the key store to be used.
      • getReplicationUsesKeyStore

        public boolean getReplicationUsesKeyStore()
        Tells whether the key pairs of this key store are to secure replication as well. Replication reads the key pair it presents, and the certificates it trusts, from the trust store used for server to server communication and from nowhere else, so the key pairs have to be copied there.
        Returns:
        true if replication is to present the key pairs of this key store.
      • setReplicationUsesKeyStore

        public void setReplicationUsesKeyStore​(boolean replicationUsesKeyStore)
        Sets whether the key pairs of this key store are to secure replication as well.
        Parameters:
        replicationUsesKeyStore - whether replication is to present these key pairs.
      • getReplicationCaCertFiles

        public List<File> getReplicationCaCertFiles()
        Returns the files holding certificates to trust on the replication port, on top of the issuers found in the certificate chains of the key pairs to use.
        Returns:
        the files holding certificates to trust, empty if there is none.
      • setReplicationCaCertFiles

        public void setReplicationCaCertFiles​(Collection<File> replicationCaCertFiles)
        Sets the files holding certificates to trust on the replication port.
        Parameters:
        replicationCaCertFiles - the files holding certificates to trust.