Package org.opends.server.extensions
Class BlindTrustManagerProvider
- java.lang.Object
-
- org.opends.server.api.TrustManagerProvider<BlindTrustManagerProviderCfg>
-
- org.opends.server.extensions.BlindTrustManagerProvider
-
- All Implemented Interfaces:
TrustManager,X509TrustManager
public class BlindTrustManagerProvider extends TrustManagerProvider<BlindTrustManagerProviderCfg> implements X509TrustManager
This class provides an implementation of a trust manager provider that will indicate that any certificate presented should be blindly trusted by the Directory Server. This can provide convenience and ease of use, but that added convenience will be at the expense of security and therefore it should not be used in environments in which the clients may not be considered trustworthy.
-
-
Constructor Summary
Constructors Constructor Description BlindTrustManagerProvider()Creates a new instance of this blind trust manager provider.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidcheckClientTrusted(X509Certificate[] chain, String authType)Determines whether an SSL client with the provided certificate chain should be trusted.voidcheckServerTrusted(X509Certificate[] chain, String authType)Determines whether an SSL server with the provided certificate chain should be trusted.voidfinalizeTrustManagerProvider()Performs any finalization that may be necessary for this trust manager provider.X509Certificate[]getAcceptedIssuers()Retrieves the set of certificate authority certificates which are trusted for authenticating peers.TrustManager[]getTrustManagers()Retrieves a set ofTrustManagerobjects that may be used for interactions requiring access to a trust manager.voidinitializeTrustManagerProvider(BlindTrustManagerProviderCfg configuration)Initializes this trust manager provider based on the information in the provided configuration entry.-
Methods inherited from class org.opends.server.api.TrustManagerProvider
isConfigurationAcceptable
-
-
-
-
Method Detail
-
initializeTrustManagerProvider
public void initializeTrustManagerProvider(BlindTrustManagerProviderCfg configuration) throws ConfigException, InitializationException
Description copied from class:TrustManagerProviderInitializes this trust manager provider based on the information in the provided configuration entry.- Specified by:
initializeTrustManagerProviderin classTrustManagerProvider<BlindTrustManagerProviderCfg>- Parameters:
configuration- The configuration to use for this trust manager provider.- Throws:
ConfigException- If an unrecoverable problem arises in the process of performing the initialization as a result of the server configuration.InitializationException- If a problem occurs during initialization that is not related to the server configuration.
-
finalizeTrustManagerProvider
public void finalizeTrustManagerProvider()
Description copied from class:TrustManagerProviderPerforms any finalization that may be necessary for this trust manager provider.- Specified by:
finalizeTrustManagerProviderin classTrustManagerProvider<BlindTrustManagerProviderCfg>
-
getTrustManagers
public TrustManager[] getTrustManagers() throws DirectoryException
Description copied from class:TrustManagerProviderRetrieves a set ofTrustManagerobjects that may be used for interactions requiring access to a trust manager.- Specified by:
getTrustManagersin classTrustManagerProvider<BlindTrustManagerProviderCfg>- Returns:
- A set of
TrustManagerobjects that may be used for interactions requiring access to a trust manager. - Throws:
DirectoryException- If a problem occurs while attempting to obtain the set of trust managers.
-
checkClientTrusted
public void checkClientTrusted(X509Certificate[] chain, String authType)
Determines whether an SSL client with the provided certificate chain should be trusted. In this case, all client certificates will be trusted.- Specified by:
checkClientTrustedin interfaceX509TrustManager- Parameters:
chain- The certificate chain for the SSL client.authType- The authentication type based on the client certificate.
-
checkServerTrusted
public void checkServerTrusted(X509Certificate[] chain, String authType)
Determines whether an SSL server with the provided certificate chain should be trusted. In this case, all server certificates will be trusted.- Specified by:
checkServerTrustedin interfaceX509TrustManager- Parameters:
chain- The certificate chain for the SSL server.authType- The key exchange algorithm used.
-
getAcceptedIssuers
public X509Certificate[] getAcceptedIssuers()
Retrieves the set of certificate authority certificates which are trusted for authenticating peers.- Specified by:
getAcceptedIssuersin interfaceX509TrustManager- Returns:
- An empty array, since we don't care what certificates are presented because we will trust them all.
-
-