Package org.opends.quicksetup
Class SecurityOptions
- java.lang.Object
-
- org.opends.quicksetup.SecurityOptions
-
public class SecurityOptions extends Object
Class used to describe the Security Options specified by the user.
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description static classSecurityOptions.CertificateTypeThe different type of security options that we can have.
-
Field Summary
Fields Modifier and Type Field Description static StringSELF_SIGNED_CERT_ALIASAlias of a self-signed certificate.static StringSELF_SIGNED_EC_CERT_ALIASAlias of a self-signed certificate using elliptic curve.
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description static SecurityOptionscreateBCFKSCertificateOptions(String keystorePath, String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)Creates a new instance of a SecurityOptions using a BCFKS Key Store.static SecurityOptionscreateJCEKSCertificateOptions(String keystorePath, String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)Creates a new instance of a SecurityOptions using a JCE Key Store.static SecurityOptionscreateJKSCertificateOptions(String keystorePath, String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)Creates a new instance of a SecurityOptions using a Java Key Store.static SecurityOptionscreateNoCertificateOptions()Creates a new instance of a SecurityOptions representing for no certificate (no SSL or Start TLS).static SecurityOptionscreateOptionsForCertificatType(SecurityOptions.CertificateType certType, String keystorePath, String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)Creates a new instance of a SecurityOptions using the provided type Key Store.static SecurityOptionscreatePKCS11CertificateOptions(String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)Creates a new instance of a SecurityOptions using a PKCS#11 Key Store.static SecurityOptionscreatePKCS12CertificateOptions(String keystorePath, String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)Creates a new instance of a SecurityOptions using a PKCS#12 Key Store.static SecurityOptionscreateSelfSignedCertificateOptions(boolean enableSSL, boolean enableStartTLS, int sslPort)Creates a new instance of a SecurityOptions using a self-signed certificate.Set<String>getAliasesToUse()Returns the alias of the certificate in the key store to be used.SecurityOptions.CertificateTypegetCertificateType()Returns the CertificateType for this instance.booleangetEnableSSL()Returns whether SSL is enabled or not.booleangetEnableStartTLS()Returns whether StartTLS is enabled or not.StringgetKeystorePassword()Returns the key store password.StringgetKeystorePath()Returns the key store path.List<File>getReplicationCaCertFiles()Returns the files holding certificates to trust on the replication port, on top of the issuers found in the certificate chains of the key pairs to use.booleangetReplicationUsesKeyStore()Tells whether the key pairs of this key store are to secure replication as well.intgetSslPort()Returns the SSL port.voidsetReplicationCaCertFiles(Collection<File> replicationCaCertFiles)Sets the files holding certificates to trust on the replication port.voidsetReplicationUsesKeyStore(boolean replicationUsesKeyStore)Sets whether the key pairs of this key store are to secure replication as well.
-
-
-
Field Detail
-
SELF_SIGNED_CERT_ALIAS
public static final String SELF_SIGNED_CERT_ALIAS
Alias of a self-signed certificate.- See Also:
- Constant Field Values
-
SELF_SIGNED_EC_CERT_ALIAS
public static final String SELF_SIGNED_EC_CERT_ALIAS
Alias of a self-signed certificate using elliptic curve.- See Also:
- Constant Field Values
-
-
Method Detail
-
createNoCertificateOptions
public static SecurityOptions createNoCertificateOptions()
Creates a new instance of a SecurityOptions representing for no certificate (no SSL or Start TLS).- Returns:
- a new instance of a SecurityOptions representing for no certificate (no SSL or Start TLS).
-
createSelfSignedCertificateOptions
public static SecurityOptions createSelfSignedCertificateOptions(boolean enableSSL, boolean enableStartTLS, int sslPort)
Creates a new instance of a SecurityOptions using a self-signed certificate.- Parameters:
enableSSL- whether SSL is enabled or not.enableStartTLS- whether Start TLS is enabled or not.sslPort- the value of the LDAPS port.- Returns:
- a new instance of a SecurityOptions using a self-signed certificate.
-
createJKSCertificateOptions
public static SecurityOptions createJKSCertificateOptions(String keystorePath, String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)
Creates a new instance of a SecurityOptions using a Java Key Store.- Parameters:
keystorePath- the path of the key store.keystorePwd- the password of the key store.enableSSL- whether SSL is enabled or not.enableStartTLS- whether Start TLS is enabled or not.sslPort- the value of the LDAPS port.aliasesToUse- the aliases of the certificates in the key store to be used.- Returns:
- a new instance of a SecurityOptions using a Java Key Store.
-
createJCEKSCertificateOptions
public static SecurityOptions createJCEKSCertificateOptions(String keystorePath, String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)
Creates a new instance of a SecurityOptions using a JCE Key Store.- Parameters:
keystorePath- the path of the key store.keystorePwd- the password of the key store.enableSSL- whether SSL is enabled or not.enableStartTLS- whether Start TLS is enabled or not.sslPort- the value of the LDAPS port.aliasesToUse- the aliases of the certificates in the keystore to be used.- Returns:
- a new instance of a SecurityOptions using a JCE Key Store.
-
createPKCS11CertificateOptions
public static SecurityOptions createPKCS11CertificateOptions(String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)
Creates a new instance of a SecurityOptions using a PKCS#11 Key Store.- Parameters:
keystorePwd- the password of the key store.enableSSL- whether SSL is enabled or not.enableStartTLS- whether Start TLS is enabled or not.sslPort- the value of the LDAPS port.aliasesToUse- the aliases of the certificates in the keystore to be used.- Returns:
- a new instance of a SecurityOptions using a PKCS#11 Key Store.
-
createPKCS12CertificateOptions
public static SecurityOptions createPKCS12CertificateOptions(String keystorePath, String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)
Creates a new instance of a SecurityOptions using a PKCS#12 Key Store.- Parameters:
keystorePath- the path of the key store.keystorePwd- the password of the key store.enableSSL- whether SSL is enabled or not.enableStartTLS- whether Start TLS is enabled or not.sslPort- the value of the LDAPS port.aliasesToUse- the aliases of the certificates in the keystore to be used.- Returns:
- a new instance of a SecurityOptions using a PKCS#12 Key Store.
-
createBCFKSCertificateOptions
public static SecurityOptions createBCFKSCertificateOptions(String keystorePath, String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)
Creates a new instance of a SecurityOptions using a BCFKS Key Store.- Parameters:
keystorePath- the path of the key store.keystorePwd- the password of the key store.enableSSL- whether SSL is enabled or not.enableStartTLS- whether Start TLS is enabled or not.sslPort- the value of the LDAPS port.aliasesToUse- the aliases of the certificates in the keystore to be used.- Returns:
- a new instance of a SecurityOptions using a PKCS#12 Key Store.
-
createOptionsForCertificatType
public static SecurityOptions createOptionsForCertificatType(SecurityOptions.CertificateType certType, String keystorePath, String keystorePwd, boolean enableSSL, boolean enableStartTLS, int sslPort, Collection<String> aliasesToUse)
Creates a new instance of a SecurityOptions using the provided type Key Store.- Parameters:
certType- The Key Store type.keystorePath- The path of the key store (may be @null).keystorePwd- The password of the key store.enableSSL- Whether SSL is enabled or not.enableStartTLS- Whether Start TLS is enabled or not.sslPort- The value of the LDAPS port.aliasesToUse- The aliases of the certificates in the keystore to be used.- Returns:
- a new instance of a SecurityOptions.
-
getCertificateType
public SecurityOptions.CertificateType getCertificateType()
Returns the CertificateType for this instance.- Returns:
- the CertificateType for this instance.
-
getEnableSSL
public boolean getEnableSSL()
Returns whether SSL is enabled or not.- Returns:
trueif SSL is enabled andfalseotherwise.
-
getEnableStartTLS
public boolean getEnableStartTLS()
Returns whether StartTLS is enabled or not.- Returns:
trueif StartTLS is enabled andfalseotherwise.
-
getKeystorePassword
public String getKeystorePassword()
Returns the key store password.- Returns:
- the key store password.
-
getKeystorePath
public String getKeystorePath()
Returns the key store path.- Returns:
- the key store path.
-
getSslPort
public int getSslPort()
Returns the SSL port.- Returns:
- the SSL port.
-
getAliasesToUse
public Set<String> getAliasesToUse()
Returns the alias of the certificate in the key store to be used.- Returns:
- the alias of the certificate in the key store to be used.
-
getReplicationUsesKeyStore
public boolean getReplicationUsesKeyStore()
Tells whether the key pairs of this key store are to secure replication as well. Replication reads the key pair it presents, and the certificates it trusts, from the trust store used for server to server communication and from nowhere else, so the key pairs have to be copied there.- Returns:
trueif replication is to present the key pairs of this key store.
-
setReplicationUsesKeyStore
public void setReplicationUsesKeyStore(boolean replicationUsesKeyStore)
Sets whether the key pairs of this key store are to secure replication as well.- Parameters:
replicationUsesKeyStore- whether replication is to present these key pairs.
-
getReplicationCaCertFiles
public List<File> getReplicationCaCertFiles()
Returns the files holding certificates to trust on the replication port, on top of the issuers found in the certificate chains of the key pairs to use.- Returns:
- the files holding certificates to trust, empty if there is none.
-
setReplicationCaCertFiles
public void setReplicationCaCertFiles(Collection<File> replicationCaCertFiles)
Sets the files holding certificates to trust on the replication port.- Parameters:
replicationCaCertFiles- the files holding certificates to trust.
-
-