Package org.opends.server.util
Class CertificateManager
- java.lang.Object
-
- org.opends.server.util.CertificateManager
-
@PublicAPI(stability=VOLATILE, mayInstantiate=true, mayExtend=false, mayInvoke=true) public final class CertificateManager extends Object
This class provides an interface for generating self-signed certificates and certificate signing requests, and for importing, exporting, and deleting certificates from a key store. It supports JKS, PKCS11, and PKCS12 key store types.
This code uses the Platform class to perform all of the certificate management.
-
-
Field Summary
Fields Modifier and Type Field Description static StringKEY_STORE_PATH_PKCS11The key store path value that must be used in conjunction with the PKCS11 key store type.static StringKEY_STORE_TYPE_BCFKSThe key store type value that should be used for the "BCFKS" key store.static StringKEY_STORE_TYPE_JCEKSThe key store type value that should be used for the "JCEKS" key store.static StringKEY_STORE_TYPE_JKSThe key store type value that should be used for the "JKS" key store.static StringKEY_STORE_TYPE_PKCS11The key store type value that should be used for the "PKCS11" key store.static StringKEY_STORE_TYPE_PKCS12The key store type value that should be used for the "PKCS12" key store.
-
Constructor Summary
Constructors Constructor Description CertificateManager(String keyStorePath, String keyStoreType, char[] keyStorePassword)Creates a new certificate manager instance with the provided information.CertificateManager(String keyStorePath, String keyStoreType, String keyStorePassword)Creates a new certificate manager instance with the provided information.
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description voidaddCertificate(String alias, File certificateFile)Adds the provided certificate to the key store.voidaddTrustedCertificate(String alias, Certificate certificate)Adds the provided certificate to the key store as a trusted certificate entry.booleanaliasInUse(String alias)Indicates whether the provided alias is in use in the key store.voidgenerateSelfSignedCertificate(Platform.KeyType keyType, String alias, String subjectDN, int validity)Generates a self-signed certificate using the provided information.CertificategetCertificate(String alias)Retrieves the certificate with the specified alias from the key store.String[]getCertificateAliases()Retrieves the aliases of the certificates in the specified key store.Certificate[]getCertificateChain(String alias)Retrieves the certificate chain of the key entry with the specified alias from the key store, the certificate the key belongs to first and its issuers next.StringgetKeyStorePath()Retrieves the path of the key store this certificate manager works on.booleanhasRealAliases()Returns whether this certificate manager contains 'real' aliases or not.voidimportKeyEntry(String alias, CertificateManager sourceManager, String sourceAlias)Copies the key entry with the specified alias from the provided key store into this one, with its whole certificate chain.static booleanmayUseCertificateManager()Always return true.voidremoveCertificate(String alias)Removes the specified certificate from the key store.
-
-
-
Field Detail
-
KEY_STORE_TYPE_JKS
public static final String KEY_STORE_TYPE_JKS
The key store type value that should be used for the "JKS" key store.- See Also:
- Constant Field Values
-
KEY_STORE_TYPE_JCEKS
public static final String KEY_STORE_TYPE_JCEKS
The key store type value that should be used for the "JCEKS" key store.- See Also:
- Constant Field Values
-
KEY_STORE_TYPE_PKCS11
public static final String KEY_STORE_TYPE_PKCS11
The key store type value that should be used for the "PKCS11" key store.- See Also:
- Constant Field Values
-
KEY_STORE_TYPE_PKCS12
public static final String KEY_STORE_TYPE_PKCS12
The key store type value that should be used for the "PKCS12" key store.- See Also:
- Constant Field Values
-
KEY_STORE_TYPE_BCFKS
public static final String KEY_STORE_TYPE_BCFKS
The key store type value that should be used for the "BCFKS" key store.- See Also:
- Constant Field Values
-
KEY_STORE_PATH_PKCS11
public static final String KEY_STORE_PATH_PKCS11
The key store path value that must be used in conjunction with the PKCS11 key store type.- See Also:
- Constant Field Values
-
-
Constructor Detail
-
CertificateManager
public CertificateManager(String keyStorePath, String keyStoreType, String keyStorePassword) throws IllegalArgumentException
Creates a new certificate manager instance with the provided information.- Parameters:
keyStorePath- The path to the key store file, or "NONE" if the key store type is "PKCS11". For the other key store types, the file does not need to exist if a new self-signed certificate or certificate signing request is to be generated, although the directory containing the file must exist. The key store file must exist if import or export operations are to be performed.keyStoreType- The key store type to use. It should be one ofKEY_STORE_TYPE_JKS,KEY_STORE_TYPE_JCEKS,KEY_STORE_TYPE_PKCS11, orKEY_STORE_TYPE_PKCS12.keyStorePassword- The password required to access the key store. It may benull.- Throws:
IllegalArgumentException- If an argument is invalid ornull.
-
CertificateManager
public CertificateManager(String keyStorePath, String keyStoreType, char[] keyStorePassword) throws IllegalArgumentException
Creates a new certificate manager instance with the provided information.- Parameters:
keyStorePath- The path to the key store file, or "NONE" if the key store type is "PKCS11". For the other key store types, the file does not need to exist if a new self-signed certificate or certificate signing request is to be generated, although the directory containing the file must exist. The key store file must exist if import or export operations are to be performed.keyStoreType- The key store type to use. It should be one ofKEY_STORE_TYPE_JKS,KEY_STORE_TYPE_JCEKS,KEY_STORE_TYPE_PKCS11, orKEY_STORE_TYPE_PKCS12.keyStorePassword- The password required to access the key store. It may benull.- Throws:
IllegalArgumentException- If an argument is invalid ornull.
-
-
Method Detail
-
mayUseCertificateManager
public static boolean mayUseCertificateManager()
Always return true.- Returns:
- This always returns true;
-
getKeyStorePath
public String getKeyStorePath()
Retrieves the path of the key store this certificate manager works on.- Returns:
- The path of the key store.
-
aliasInUse
public boolean aliasInUse(String alias) throws KeyStoreException
Indicates whether the provided alias is in use in the key store.- Parameters:
alias- The alias for which to make the determination. It must not benullor empty.- Returns:
trueif the key store exist and already contains a certificate with the given alias, orfalseif not.- Throws:
KeyStoreException- If a problem occurs while attempting to interact with the key store.
-
getCertificateAliases
public String[] getCertificateAliases() throws KeyStoreException
Retrieves the aliases of the certificates in the specified key store.- Returns:
- The aliases of the certificates in the specified key store, or
nullif the key store does not exist. - Throws:
KeyStoreException- If a problem occurs while attempting to interact with the key store.
-
getCertificate
public Certificate getCertificate(String alias) throws KeyStoreException
Retrieves the certificate with the specified alias from the key store.- Parameters:
alias- The alias of the certificate to retrieve. It must not benullor empty.- Returns:
- The requested certificate, or
nullif the specified certificate does not exist. - Throws:
KeyStoreException- If a problem occurs while interacting with the key store, or the key store does not exist..
-
getCertificateChain
public Certificate[] getCertificateChain(String alias) throws KeyStoreException
Retrieves the certificate chain of the key entry with the specified alias from the key store, the certificate the key belongs to first and its issuers next.- Parameters:
alias- The alias of the key entry whose chain to retrieve. It must not benullor empty.- Returns:
- The certificate chain, or
nullif the key store holds no key entry under the specified alias. - Throws:
KeyStoreException- If a problem occurs while interacting with the key store, or the key store does not exist.
-
importKeyEntry
public void importKeyEntry(String alias, CertificateManager sourceManager, String sourceAlias) throws KeyStoreException
Copies the key entry with the specified alias from the provided key store into this one, with its whole certificate chain. The private key is re-encrypted with the password of this key store: the key managers of the server are initialised with the store password only, so a key which kept the password of the key store it comes from could not be read back.The certificates of the chain are not added as trusted certificates, as only a trusted certificate entry is a trust anchor. Use
addTrustedCertificate(java.lang.String, java.security.cert.Certificate)for the issuers which have to be trusted.- Parameters:
alias- The alias to store the key entry under in this key store. It must not benullor empty.sourceManager- The certificate manager of the key store holding the key entry to copy. It must not benull.sourceAlias- The alias of the key entry to copy. It must not benullor empty.- Throws:
KeyStoreException- If the source key store holds no key entry under the provided alias, if its private key is protected by a password other than the one of the source key store, if the alias is already in use in this key store, or a problem occurs while interacting with either key store.
-
addTrustedCertificate
public void addTrustedCertificate(String alias, Certificate certificate) throws KeyStoreException
Adds the provided certificate to the key store as a trusted certificate entry. Only such an entry is a trust anchor: of a key entry, the trust managers take the certificate the key belongs to and none of its issuers.- Parameters:
alias- The alias to use for the certificate. It must not benullor empty.certificate- The certificate to trust. It must not benull.- Throws:
KeyStoreException- If the alias is already in use, or a problem occurs while interacting with the key store.
-
generateSelfSignedCertificate
public void generateSelfSignedCertificate(Platform.KeyType keyType, String alias, String subjectDN, int validity) throws KeyStoreException, IllegalArgumentException
Generates a self-signed certificate using the provided information.- Parameters:
keyType- Specifies the key size, key and signature algorithms.alias- The nickname to use for the certificate in the key store. For the server certificate, it should generally be "server-cert". It must not benullor empty.subjectDN- The subject DN to use for the certificate. It must not benullor empty.validity- The length of time in days that the certificate should be valid, starting from the time the certificate is generated. It must be a positive integer value.- Throws:
KeyStoreException- If a problem occurs while actually attempting to generate the certificate in the key store.IllegalArgumentException- If the validity parameter is not a positive integer, or the alias is already in the keystore.
-
addCertificate
public void addCertificate(String alias, File certificateFile) throws KeyStoreException, IllegalArgumentException
Adds the provided certificate to the key store. This may be used to associate an externally-signed certificate with an existing private key with the given alias.- Parameters:
alias- The alias to use for the certificate. It must not benullor empty.certificateFile- The file containing the encoded certificate. It must not benull, and the file must exist.- Throws:
KeyStoreException- If a problem occurs while interacting with the key store.IllegalArgumentException- If the certificate file is not valid.
-
removeCertificate
public void removeCertificate(String alias) throws KeyStoreException, IllegalArgumentException
Removes the specified certificate from the key store.- Parameters:
alias- The alias to use for the certificate to remove. It must not benullor an empty string, and it must exist in the key store.- Throws:
KeyStoreException- If a problem occurs while interacting with the key store.IllegalArgumentException- If the alias is in use and cannot be deleted.
-
hasRealAliases
public boolean hasRealAliases() throws KeyStoreExceptionReturns whether this certificate manager contains 'real' aliases or not. For instance, the certificate manager can contain a PKCS12 certificate with no alias.- Returns:
- whether this certificate manager contains 'real' aliases or not.
- Throws:
KeyStoreException- if there is a problem accessing the key store.
-
-