Class ExpirationCheckTrustManager

    • Constructor Detail

      • ExpirationCheckTrustManager

        public ExpirationCheckTrustManager​(X509TrustManager trustManager)
        Creates a new instance of this trust manager that will wrap the provided trust manager.
        Parameters:
        trustManager - The trust manager to be wrapped by this trust manager.
    • Method Detail

      • checkClientTrusted

        public void checkClientTrusted​(X509Certificate[] chain,
                                       String authType)
                                throws CertificateException
        Determines whether to trust the peer based on the provided certificate chain. In this case, the peer will only be trusted if all certificates in the chain are within the validity window and the parent trust manager also accepts the certificate.
        Specified by:
        checkClientTrusted in interface X509TrustManager
        Parameters:
        chain - The peer certificate chain.
        authType - The authentication type based on the client certificate.
        Throws:
        CertificateException - If the client certificate chain is not trusted.
      • checkServerTrusted

        public void checkServerTrusted​(X509Certificate[] chain,
                                       String authType)
                                throws CertificateException
        Determines whether to trust the peer based on the provided certificate chain. In this case, the peer will only be trusted if all certificates in the chain are within the validity window and the parent trust manager also accepts the certificate.
        Specified by:
        checkServerTrusted in interface X509TrustManager
        Parameters:
        chain - The peer certificate chain.
        authType - The key exchange algorithm used.
        Throws:
        CertificateException - If the server certificate chain is not trusted.
      • getAcceptedIssuers

        public X509Certificate[] getAcceptedIssuers()
        Retrieves the set of CA certificates which are trusted for authenticating peers. This will be taken from the parent trust manager.
        Specified by:
        getAcceptedIssuers in interface X509TrustManager
        Returns:
        A non-null (possibly empty) array of acceptable CA issuer certificates.