Package org.opends.server.util
Class SelectableCertificateKeyManager
- java.lang.Object
-
- javax.net.ssl.X509ExtendedKeyManager
-
- org.opends.server.util.SelectableCertificateKeyManager
-
- All Implemented Interfaces:
KeyManager,X509KeyManager
@PublicAPI(stability=UNCOMMITTED, mayInstantiate=true, mayExtend=false, mayInvoke=true) public final class SelectableCertificateKeyManager extends X509ExtendedKeyManager
This class implements an X.509 key manager that will be used to wrap an existing key manager and makes it possible to configure which certificate(s) should be used for client and/or server operations. The certificate selection will be based on the alias (also called the nickname) of the certificate.
-
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description StringchooseClientAlias(String[] keyType, Principal[] issuers, Socket socket)Chooses the alias of the client certificate that should be used based on the provided criteria.StringchooseEngineClientAlias(String[] keyType, Principal[] issuers, SSLEngine engine)Chooses the alias of the client certificate that should be used based on the provided criteria.StringchooseEngineServerAlias(String keyType, Principal[] issuers, SSLEngine engine)Chooses the alias of the server certificate that should be used based on the provided criteria.StringchooseServerAlias(String keyType, Principal[] issuers, Socket socket)Chooses the alias of the server certificate that should be used based on the provided criteria.X509Certificate[]getCertificateChain(String alias)Retrieves the certificate chain for the provided alias.String[]getClientAliases(String keyType, Principal[] issuers)Retrieves the set of certificate aliases that may be used for client authentication with the given public key type and set of issuers.PrivateKeygetPrivateKey(String alias)Retrieves the private key for the provided alias.String[]getServerAliases(String keyType, Principal[] issuers)Retrieves the set of certificate aliases that may be used for server authentication with the given public key type and set of issuers.static KeyManager[]wrap(KeyManager[] keyManagers, SortedSet<String> aliases)Wraps the provided set of key managers in selectable certificate key managers using the provided alias.static KeyManager[]wrap(KeyManager[] keyManagers, SortedSet<String> aliases, String componentName)Wraps the provided set of key managers in selectable certificate key managers using the provided alias.
-
-
-
Method Detail
-
chooseClientAlias
public String chooseClientAlias(String[] keyType, Principal[] issuers, Socket socket)
Chooses the alias of the client certificate that should be used based on the provided criteria. This will either return the preferred alias configured for this key manager, ornullif no client certificate with that alias is configured in the underlying key manager.- Parameters:
keyType- The set of key algorithm names, ordered with the most preferred key type first.issuers- The list of acceptable issuer subject names, ornullif any issuer may be used.socket- The socket to be used for this connection.- Returns:
- The alias configured for this key manager, or
nullif no such client certificate is available with that alias.
-
chooseEngineClientAlias
public String chooseEngineClientAlias(String[] keyType, Principal[] issuers, SSLEngine engine)
Chooses the alias of the client certificate that should be used based on the provided criteria. This will either return the preferred alias configured for this key manager, ornullif no client certificate with that alias is configured in the underlying key manager.- Overrides:
chooseEngineClientAliasin classX509ExtendedKeyManager- Parameters:
keyType- The set of key algorithm names, ordered with the most preferred key type first.issuers- The list of acceptable issuer subject names, ornullif any issuer may be used.engine- The SSL engine to be used for this connection.- Returns:
- The alias configured for this key manager, or
nullif no such client certificate is available with that alias.
-
chooseServerAlias
public String chooseServerAlias(String keyType, Principal[] issuers, Socket socket)
Chooses the alias of the server certificate that should be used based on the provided criteria. This will either return the preferred alias configured for this key manager, ornullif no server certificate with that alias is configured in the underlying key manager.- Parameters:
keyType- The public key type for the certificate.issuers- The list of acceptable issuer subject names, ornullif any issuer may be used.socket- The socket to be used for this connection.- Returns:
- The alias configured for this key manager, or
nullif no such server certificate is available with that alias.
-
chooseEngineServerAlias
public String chooseEngineServerAlias(String keyType, Principal[] issuers, SSLEngine engine)
Chooses the alias of the server certificate that should be used based on the provided criteria. This will either return the preferred alias configured for this key manager, ornullif no server certificate with that alias is configured in the underlying key manager. Note that the returned alias can be transformed in lowercase, depending on the KeyStore implementation. It is recommended not to use aliases in a KeyStore that only differ in case.- Overrides:
chooseEngineServerAliasin classX509ExtendedKeyManager- Parameters:
keyType- The public key type for the certificate.issuers- The list of acceptable issuer subject names, ornullif any issuer may be used.engine- The SSL engine to be used for this connection.- Returns:
- The alias configured for this key manager, or
nullif no such server certificate is available with that alias.
-
getCertificateChain
public X509Certificate[] getCertificateChain(String alias)
Retrieves the certificate chain for the provided alias.- Parameters:
alias- The alias for the certificate chain to retrieve.- Returns:
- The certificate chain for the provided alias, or
nullif no certificate is associated with the provided alias.
-
getClientAliases
public String[] getClientAliases(String keyType, Principal[] issuers)
Retrieves the set of certificate aliases that may be used for client authentication with the given public key type and set of issuers.- Parameters:
keyType- The public key type for the aliases to retrieve.issuers- The list of acceptable issuer subject names, ornullif any issuer may be used.- Returns:
- The set of certificate aliases that may be used for client
authentication with the given public key type and set of issuers,
or
nullif there were none.
-
getPrivateKey
public PrivateKey getPrivateKey(String alias)
Retrieves the private key for the provided alias.- Parameters:
alias- The alias for the private key to return.- Returns:
- The private key for the provided alias, or
nullif no private key is available for the provided alias.
-
getServerAliases
public String[] getServerAliases(String keyType, Principal[] issuers)
Retrieves the set of certificate aliases that may be used for server authentication with the given public key type and set of issuers.- Parameters:
keyType- The public key type for the aliases to retrieve.issuers- The list of acceptable issuer subject names, ornullif any issuer may be used.- Returns:
- The set of certificate aliases that may be used for server
authentication with the given public key type and set of issuers,
or
nullif there were none.
-
wrap
public static KeyManager[] wrap(KeyManager[] keyManagers, SortedSet<String> aliases, String componentName)
Wraps the provided set of key managers in selectable certificate key managers using the provided alias.- Parameters:
keyManagers- The set of key managers to be wrapped.aliases- The aliases to use for selecting the desired certificate.componentName- Name of the component to which is associated this key manager- Returns:
- A key manager array
-
wrap
public static KeyManager[] wrap(KeyManager[] keyManagers, SortedSet<String> aliases)
Wraps the provided set of key managers in selectable certificate key managers using the provided alias.- Parameters:
keyManagers- The set of key managers to be wrapped.aliases- The aliases to use for selecting the desired certificate.- Returns:
- A key manager array
-
-