Class CertificateManager


  • @PublicAPI(stability=VOLATILE,
               mayInstantiate=true,
               mayExtend=false,
               mayInvoke=true)
    public final class CertificateManager
    extends Object
    This class provides an interface for generating self-signed certificates and certificate signing requests, and for importing, exporting, and deleting certificates from a key store. It supports JKS, PKCS11, and PKCS12 key store types.

    This code uses the Platform class to perform all of the certificate management.
    • Field Detail

      • KEY_STORE_TYPE_JKS

        public static final String KEY_STORE_TYPE_JKS
        The key store type value that should be used for the "JKS" key store.
        See Also:
        Constant Field Values
      • KEY_STORE_TYPE_JCEKS

        public static final String KEY_STORE_TYPE_JCEKS
        The key store type value that should be used for the "JCEKS" key store.
        See Also:
        Constant Field Values
      • KEY_STORE_TYPE_PKCS11

        public static final String KEY_STORE_TYPE_PKCS11
        The key store type value that should be used for the "PKCS11" key store.
        See Also:
        Constant Field Values
      • KEY_STORE_TYPE_PKCS12

        public static final String KEY_STORE_TYPE_PKCS12
        The key store type value that should be used for the "PKCS12" key store.
        See Also:
        Constant Field Values
      • KEY_STORE_TYPE_BCFKS

        public static final String KEY_STORE_TYPE_BCFKS
        The key store type value that should be used for the "BCFKS" key store.
        See Also:
        Constant Field Values
      • KEY_STORE_PATH_PKCS11

        public static final String KEY_STORE_PATH_PKCS11
        The key store path value that must be used in conjunction with the PKCS11 key store type.
        See Also:
        Constant Field Values
    • Constructor Detail

      • CertificateManager

        public CertificateManager​(String keyStorePath,
                                  String keyStoreType,
                                  String keyStorePassword)
                           throws IllegalArgumentException
        Creates a new certificate manager instance with the provided information.
        Parameters:
        keyStorePath - The path to the key store file, or "NONE" if the key store type is "PKCS11". For the other key store types, the file does not need to exist if a new self-signed certificate or certificate signing request is to be generated, although the directory containing the file must exist. The key store file must exist if import or export operations are to be performed.
        keyStoreType - The key store type to use. It should be one of KEY_STORE_TYPE_JKS, KEY_STORE_TYPE_JCEKS, KEY_STORE_TYPE_PKCS11, or KEY_STORE_TYPE_PKCS12.
        keyStorePassword - The password required to access the key store. It may be null.
        Throws:
        IllegalArgumentException - If an argument is invalid or null.
      • CertificateManager

        public CertificateManager​(String keyStorePath,
                                  String keyStoreType,
                                  char[] keyStorePassword)
                           throws IllegalArgumentException
        Creates a new certificate manager instance with the provided information.
        Parameters:
        keyStorePath - The path to the key store file, or "NONE" if the key store type is "PKCS11". For the other key store types, the file does not need to exist if a new self-signed certificate or certificate signing request is to be generated, although the directory containing the file must exist. The key store file must exist if import or export operations are to be performed.
        keyStoreType - The key store type to use. It should be one of KEY_STORE_TYPE_JKS, KEY_STORE_TYPE_JCEKS, KEY_STORE_TYPE_PKCS11, or KEY_STORE_TYPE_PKCS12.
        keyStorePassword - The password required to access the key store. It may be null.
        Throws:
        IllegalArgumentException - If an argument is invalid or null.
    • Method Detail

      • mayUseCertificateManager

        public static boolean mayUseCertificateManager()
        Always return true.
        Returns:
        This always returns true;
      • getKeyStorePath

        public String getKeyStorePath()
        Retrieves the path of the key store this certificate manager works on.
        Returns:
        The path of the key store.
      • aliasInUse

        public boolean aliasInUse​(String alias)
                           throws KeyStoreException
        Indicates whether the provided alias is in use in the key store.
        Parameters:
        alias - The alias for which to make the determination. It must not be null or empty.
        Returns:
        true if the key store exist and already contains a certificate with the given alias, or false if not.
        Throws:
        KeyStoreException - If a problem occurs while attempting to interact with the key store.
      • getCertificateAliases

        public String[] getCertificateAliases()
                                       throws KeyStoreException
        Retrieves the aliases of the certificates in the specified key store.
        Returns:
        The aliases of the certificates in the specified key store, or null if the key store does not exist.
        Throws:
        KeyStoreException - If a problem occurs while attempting to interact with the key store.
      • getCertificate

        public Certificate getCertificate​(String alias)
                                   throws KeyStoreException
        Retrieves the certificate with the specified alias from the key store.
        Parameters:
        alias - The alias of the certificate to retrieve. It must not be null or empty.
        Returns:
        The requested certificate, or null if the specified certificate does not exist.
        Throws:
        KeyStoreException - If a problem occurs while interacting with the key store, or the key store does not exist..
      • getCertificateChain

        public Certificate[] getCertificateChain​(String alias)
                                          throws KeyStoreException
        Retrieves the certificate chain of the key entry with the specified alias from the key store, the certificate the key belongs to first and its issuers next.
        Parameters:
        alias - The alias of the key entry whose chain to retrieve. It must not be null or empty.
        Returns:
        The certificate chain, or null if the key store holds no key entry under the specified alias.
        Throws:
        KeyStoreException - If a problem occurs while interacting with the key store, or the key store does not exist.
      • importKeyEntry

        public void importKeyEntry​(String alias,
                                   CertificateManager sourceManager,
                                   String sourceAlias)
                            throws KeyStoreException
        Copies the key entry with the specified alias from the provided key store into this one, with its whole certificate chain. The private key is re-encrypted with the password of this key store: the key managers of the server are initialised with the store password only, so a key which kept the password of the key store it comes from could not be read back.

        The certificates of the chain are not added as trusted certificates, as only a trusted certificate entry is a trust anchor. Use addTrustedCertificate(java.lang.String, java.security.cert.Certificate) for the issuers which have to be trusted.

        Parameters:
        alias - The alias to store the key entry under in this key store. It must not be null or empty.
        sourceManager - The certificate manager of the key store holding the key entry to copy. It must not be null.
        sourceAlias - The alias of the key entry to copy. It must not be null or empty.
        Throws:
        KeyStoreException - If the source key store holds no key entry under the provided alias, if its private key is protected by a password other than the one of the source key store, if the alias is already in use in this key store, or a problem occurs while interacting with either key store.
      • addTrustedCertificate

        public void addTrustedCertificate​(String alias,
                                          Certificate certificate)
                                   throws KeyStoreException
        Adds the provided certificate to the key store as a trusted certificate entry. Only such an entry is a trust anchor: of a key entry, the trust managers take the certificate the key belongs to and none of its issuers.
        Parameters:
        alias - The alias to use for the certificate. It must not be null or empty.
        certificate - The certificate to trust. It must not be null.
        Throws:
        KeyStoreException - If the alias is already in use, or a problem occurs while interacting with the key store.
      • generateSelfSignedCertificate

        public void generateSelfSignedCertificate​(Platform.KeyType keyType,
                                                  String alias,
                                                  String subjectDN,
                                                  int validity)
                                           throws KeyStoreException,
                                                  IllegalArgumentException
        Generates a self-signed certificate using the provided information.
        Parameters:
        keyType - Specifies the key size, key and signature algorithms.
        alias - The nickname to use for the certificate in the key store. For the server certificate, it should generally be "server-cert". It must not be null or empty.
        subjectDN - The subject DN to use for the certificate. It must not be null or empty.
        validity - The length of time in days that the certificate should be valid, starting from the time the certificate is generated. It must be a positive integer value.
        Throws:
        KeyStoreException - If a problem occurs while actually attempting to generate the certificate in the key store.
        IllegalArgumentException - If the validity parameter is not a positive integer, or the alias is already in the keystore.
      • addCertificate

        public void addCertificate​(String alias,
                                   File certificateFile)
                            throws KeyStoreException,
                                   IllegalArgumentException
        Adds the provided certificate to the key store. This may be used to associate an externally-signed certificate with an existing private key with the given alias.
        Parameters:
        alias - The alias to use for the certificate. It must not be null or empty.
        certificateFile - The file containing the encoded certificate. It must not be null, and the file must exist.
        Throws:
        KeyStoreException - If a problem occurs while interacting with the key store.
        IllegalArgumentException - If the certificate file is not valid.
      • removeCertificate

        public void removeCertificate​(String alias)
                               throws KeyStoreException,
                                      IllegalArgumentException
        Removes the specified certificate from the key store.
        Parameters:
        alias - The alias to use for the certificate to remove. It must not be null or an empty string, and it must exist in the key store.
        Throws:
        KeyStoreException - If a problem occurs while interacting with the key store.
        IllegalArgumentException - If the alias is in use and cannot be deleted.
      • hasRealAliases

        public boolean hasRealAliases()
                               throws KeyStoreException
        Returns whether this certificate manager contains 'real' aliases or not. For instance, the certificate manager can contain a PKCS12 certificate with no alias.
        Returns:
        whether this certificate manager contains 'real' aliases or not.
        Throws:
        KeyStoreException - if there is a problem accessing the key store.