Package org.opends.server.util
Class ExpirationCheckTrustManager
- java.lang.Object
-
- org.opends.server.util.ExpirationCheckTrustManager
-
- All Implemented Interfaces:
TrustManager,X509TrustManager
@PublicAPI(stability=UNCOMMITTED, mayInstantiate=true, mayExtend=false, mayInvoke=true) public final class ExpirationCheckTrustManager extends Object implements X509TrustManager
This class implements an X.509 trust manager that will be used to wrap an existing trust manager and makes it possible to reject a presented certificate if that certificate is outside the validity window.
-
-
Constructor Summary
Constructors Constructor Description ExpirationCheckTrustManager(X509TrustManager trustManager)Creates a new instance of this trust manager that will wrap the provided trust manager.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description voidcheckClientTrusted(X509Certificate[] chain, String authType)Determines whether to trust the peer based on the provided certificate chain.voidcheckServerTrusted(X509Certificate[] chain, String authType)Determines whether to trust the peer based on the provided certificate chain.X509Certificate[]getAcceptedIssuers()Retrieves the set of CA certificates which are trusted for authenticating peers.
-
-
-
Constructor Detail
-
ExpirationCheckTrustManager
public ExpirationCheckTrustManager(X509TrustManager trustManager)
Creates a new instance of this trust manager that will wrap the provided trust manager.- Parameters:
trustManager- The trust manager to be wrapped by this trust manager.
-
-
Method Detail
-
checkClientTrusted
public void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException
Determines whether to trust the peer based on the provided certificate chain. In this case, the peer will only be trusted if all certificates in the chain are within the validity window and the parent trust manager also accepts the certificate.- Specified by:
checkClientTrustedin interfaceX509TrustManager- Parameters:
chain- The peer certificate chain.authType- The authentication type based on the client certificate.- Throws:
CertificateException- If the client certificate chain is not trusted.
-
checkServerTrusted
public void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException
Determines whether to trust the peer based on the provided certificate chain. In this case, the peer will only be trusted if all certificates in the chain are within the validity window and the parent trust manager also accepts the certificate.- Specified by:
checkServerTrustedin interfaceX509TrustManager- Parameters:
chain- The peer certificate chain.authType- The key exchange algorithm used.- Throws:
CertificateException- If the server certificate chain is not trusted.
-
getAcceptedIssuers
public X509Certificate[] getAcceptedIssuers()
Retrieves the set of CA certificates which are trusted for authenticating peers. This will be taken from the parent trust manager.- Specified by:
getAcceptedIssuersin interfaceX509TrustManager- Returns:
- A non-null (possibly empty) array of acceptable CA issuer certificates.
-
-