Package org.forgerock.openidm.util
Class CertUtil
java.lang.Object
org.forgerock.openidm.util.CertUtil
Utilities for generating, serializing, and deserializing
Certificates.-
Method Summary
Modifier and TypeMethodDescriptionstatic <T> TReturns an object from a PEM String representationstatic org.apache.commons.lang3.tuple.Pair<X509Certificate,PrivateKey> generateCertificate(String commonName, String algorithm, int keySize, String signatureAlgorithm, String validFrom, String validTo) Generates a self signed certificate using the given properties.static org.apache.commons.lang3.tuple.Pair<X509Certificate,PrivateKey> generateCertificate(String commonName, String organization, String organizationUnit, String stateOrProvince, String country, String locality, String algorithm, int keySize, String signatureAlgorithm, String validFrom, String validTo) Generates a self signed certificate using the given properties.static StringgetCertString(Object object) Returns a PEM formatted string representation of an objectstatic CertificatereadCertificate(String certString) Reads a certificate from a supplied string representation, and a supplied type.static Certificate[]readCertificateChain(List<String> certStringChain) Reads a certificate chain from a supplied string array representation, and a supplied type.
-
Method Details
-
generateCertificate
public static org.apache.commons.lang3.tuple.Pair<X509Certificate,PrivateKey> generateCertificate(String commonName, String algorithm, int keySize, String signatureAlgorithm, String validFrom, String validTo) throws Exception Generates a self signed certificate using the given properties.- Parameters:
commonName- the common name to use for the new certificatealgorithm- the algorithm to usekeySize- the keysize to usesignatureAlgorithm- the signature algorithm to usevalidFrom- when the certificate is valid fromvalidTo- when the certificate is valid until- Returns:
- The generated certificate
- Throws:
Exception
-
generateCertificate
public static org.apache.commons.lang3.tuple.Pair<X509Certificate,PrivateKey> generateCertificate(String commonName, String organization, String organizationUnit, String stateOrProvince, String country, String locality, String algorithm, int keySize, String signatureAlgorithm, String validFrom, String validTo) throws Exception Generates a self signed certificate using the given properties.- Parameters:
commonName- the subject's common nameorganization- the subject's organization nameorganizationUnit- the subject's organization unit namestateOrProvince- the subject's state or provincecountry- the subject's country codelocality- the subject's localityalgorithm- the algorithm to usekeySize- the keysize to usesignatureAlgorithm- the signature algorithm to usevalidFrom- when the certificate is valid fromvalidTo- when the certificate is valid until- Returns:
- The generated certificate
- Throws:
Exception
-
getCertString
Returns a PEM formatted string representation of an object- Parameters:
object- the object to write- Returns:
- a PEM formatted string representation of the object
- Throws:
Exception
-
fromPem
Returns an object from a PEM String representation- Parameters:
pem- the PEM String representation- Returns:
- the object
- Throws:
Exception
-
readCertificate
Reads a certificate from a supplied string representation, and a supplied type.- Parameters:
certString- A String representation of a certificate- Returns:
- The certificate
- Throws:
Exception
-
readCertificateChain
Reads a certificate chain from a supplied string array representation, and a supplied type.- Parameters:
certStringChain- an array of strings representing a certificate chain- Returns:
- the certificate chain
- Throws:
Exception
-