Package org.opends.server.extensions
Class SubjectAttributeToUserAttributeCertificateMapper
- java.lang.Object
-
- org.opends.server.api.CertificateMapper<SubjectAttributeToUserAttributeCertificateMapperCfg>
-
- org.opends.server.extensions.SubjectAttributeToUserAttributeCertificateMapper
-
- All Implemented Interfaces:
ConfigurationChangeListener<SubjectAttributeToUserAttributeCertificateMapperCfg>
public class SubjectAttributeToUserAttributeCertificateMapper extends CertificateMapper<SubjectAttributeToUserAttributeCertificateMapperCfg> implements ConfigurationChangeListener<SubjectAttributeToUserAttributeCertificateMapperCfg>
This class implements a very simple Directory Server certificate mapper that will map a certificate to a user based on attributes contained in both the certificate subject and the user's entry. The configuration may include mappings from certificate attributes to attributes in user entries, and all of those certificate attributes that are present in the subject will be used to search for matching user entries.
-
-
Constructor Summary
Constructors Constructor Description SubjectAttributeToUserAttributeCertificateMapper()Creates a new instance of this certificate mapper.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description ConfigChangeResultapplyConfigurationChange(SubjectAttributeToUserAttributeCertificateMapperCfg configuration)Applies the configuration changes to this change listener.voidfinalizeCertificateMapper()Performs any finalization that may be necessary for this certificate mapper.voidinitializeCertificateMapper(SubjectAttributeToUserAttributeCertificateMapperCfg configuration)Initializes this certificate mapper based on the information in the provided configuration entry.booleanisConfigurationAcceptable(CertificateMapperCfg configuration, List<org.forgerock.i18n.LocalizableMessage> unacceptableReasons)Indicates whether the provided configuration is acceptable for this certificate mapper.booleanisConfigurationChangeAcceptable(SubjectAttributeToUserAttributeCertificateMapperCfg configuration, List<org.forgerock.i18n.LocalizableMessage> unacceptableReasons)Indicates whether the proposed change to the configuration is acceptable to this change listener.EntrymapCertificateToUser(Certificate[] certificateChain)Establishes a mapping between the information in the provided certificate chain and a single user entry in the Directory Server.
-
-
-
Method Detail
-
initializeCertificateMapper
public void initializeCertificateMapper(SubjectAttributeToUserAttributeCertificateMapperCfg configuration) throws ConfigException, InitializationException
Description copied from class:CertificateMapperInitializes this certificate mapper based on the information in the provided configuration entry.- Specified by:
initializeCertificateMapperin classCertificateMapper<SubjectAttributeToUserAttributeCertificateMapperCfg>- Parameters:
configuration- The configuration that should be used to intialize this certificate mapper.- Throws:
ConfigException- If the provided entry does not contain a valid certificate mapper configuration.InitializationException- If a problem occurs during initialization that is not related to the server configuration.
-
finalizeCertificateMapper
public void finalizeCertificateMapper()
Description copied from class:CertificateMapperPerforms any finalization that may be necessary for this certificate mapper. By default, no finalization is performed.
-
mapCertificateToUser
public Entry mapCertificateToUser(Certificate[] certificateChain) throws DirectoryException
Description copied from class:CertificateMapperEstablishes a mapping between the information in the provided certificate chain and a single user entry in the Directory Server.- Specified by:
mapCertificateToUserin classCertificateMapper<SubjectAttributeToUserAttributeCertificateMapperCfg>- Parameters:
certificateChain- The certificate chain presented by the client during SSL negotiation. The peer certificate will be listed first, followed by the ordered issuer chain as appropriate.- Returns:
- The entry for the user to whom the mapping was
established, or
nullif no mapping was established and no special message is required to send back to the client. - Throws:
DirectoryException- If a problem occurred while attempting to establish the mapping. This may include internal failures, a mapping which matches multiple users, or any other case in which an error message should be returned to the client.
-
isConfigurationAcceptable
public boolean isConfigurationAcceptable(CertificateMapperCfg configuration, List<org.forgerock.i18n.LocalizableMessage> unacceptableReasons)
Description copied from class:CertificateMapperIndicates whether the provided configuration is acceptable for this certificate mapper. It should be possible to call this method on an uninitialized certificate mapper instance in order to determine whether the certificate mapper would be able to use the provided configuration.
Note that implementations which use a subclass of the provided configuration class will likely need to cast the configuration to the appropriate subclass type.- Overrides:
isConfigurationAcceptablein classCertificateMapper<SubjectAttributeToUserAttributeCertificateMapperCfg>- Parameters:
configuration- The certificate mapper configuration for which to make the determination.unacceptableReasons- A list that may be used to hold the reasons that the provided configuration is not acceptable.- Returns:
trueif the provided configuration is acceptable for this certificate mapper, orfalseif not.
-
isConfigurationChangeAcceptable
public boolean isConfigurationChangeAcceptable(SubjectAttributeToUserAttributeCertificateMapperCfg configuration, List<org.forgerock.i18n.LocalizableMessage> unacceptableReasons)
Description copied from interface:ConfigurationChangeListenerIndicates whether the proposed change to the configuration is acceptable to this change listener.- Specified by:
isConfigurationChangeAcceptablein interfaceConfigurationChangeListener<SubjectAttributeToUserAttributeCertificateMapperCfg>- Parameters:
configuration- The new configuration containing the changes.unacceptableReasons- A list that can be used to hold messages about why the provided configuration is not acceptable.- Returns:
- Returns
trueif the proposed change is acceptable, orfalseif it is not.
-
applyConfigurationChange
public ConfigChangeResult applyConfigurationChange(SubjectAttributeToUserAttributeCertificateMapperCfg configuration)
Description copied from interface:ConfigurationChangeListenerApplies the configuration changes to this change listener.- Specified by:
applyConfigurationChangein interfaceConfigurationChangeListener<SubjectAttributeToUserAttributeCertificateMapperCfg>- Parameters:
configuration- The new configuration containing the changes.- Returns:
- Returns information about the result of changing the configuration.
-
-