Class CertificateValidator
- java.lang.Object
-
- com.floragunn.searchguard.ssl.util.CertificateValidator
-
public class CertificateValidator extends Object
Convenience class to handle validation of certificates, aliases and keystores Allows specifying Certificate Revocation List (CRL), as well as enabling CRL Distribution Points Protocol (CRLDP) certificate extension support, and also enabling On-Line Certificate Status Protocol (OCSP) support. IMPORTANT: at least one of the above mechanisms *MUST* be configured and operational, otherwise certificate validation *WILL FAIL* unconditionally.
-
-
Constructor Summary
Constructors Constructor Description CertificateValidator(X509Certificate[] trustedCert, Collection<? extends CRL> crls)CertificateValidator(KeyStore trustStore, Collection<? extends CRL> crls)creates an instance of the certificate validator
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description Collection<? extends CRL>getCrls()DategetDate()intgetMaxCertPathLength()StringgetOcspResponderURL()booleanisEnableCRLDP()booleanisEnableOCSP()voidsetDate(Date date)voidsetEnableCRLDP(boolean enableCRLDP)Enables CRL Distribution Points SupportvoidsetEnableOCSP(boolean enableOCSP)Enables On-Line Certificate Status Protocol supportvoidsetMaxCertPathLength(int maxCertPathLength)voidsetOcspResponderURL(String ocspResponderURL)Set the location of the OCSP Responder.voidvalidate(Certificate[] certChain)
-
-
-
Constructor Detail
-
CertificateValidator
public CertificateValidator(KeyStore trustStore, Collection<? extends CRL> crls)
creates an instance of the certificate validator- Parameters:
trustStore- the truststore to usecrls- the Certificate Revocation List to use
-
CertificateValidator
public CertificateValidator(X509Certificate[] trustedCert, Collection<? extends CRL> crls)
-
-
Method Detail
-
validate
public void validate(Certificate[] certChain) throws CertificateException
- Throws:
CertificateException
-
getCrls
public Collection<? extends CRL> getCrls()
-
getMaxCertPathLength
public int getMaxCertPathLength()
- Returns:
- Maximum number of intermediate certificates in the certification path (-1 for unlimited)
-
setMaxCertPathLength
public void setMaxCertPathLength(int maxCertPathLength)
- Parameters:
maxCertPathLength- maximum number of intermediate certificates in the certification path (-1 for unlimited)
-
isEnableCRLDP
public boolean isEnableCRLDP()
- Returns:
- true if CRL Distribution Points support is enabled
-
setEnableCRLDP
public void setEnableCRLDP(boolean enableCRLDP)
Enables CRL Distribution Points Support- Parameters:
enableCRLDP- true - turn on, false - turns off
-
isEnableOCSP
public boolean isEnableOCSP()
- Returns:
- true if On-Line Certificate Status Protocol support is enabled
-
setEnableOCSP
public void setEnableOCSP(boolean enableOCSP)
Enables On-Line Certificate Status Protocol support- Parameters:
enableOCSP- true - turn on, false - turn off
-
getOcspResponderURL
public String getOcspResponderURL()
- Returns:
- Location of the OCSP Responder
-
setOcspResponderURL
public void setOcspResponderURL(String ocspResponderURL)
Set the location of the OCSP Responder.- Parameters:
ocspResponderURL- location of the OCSP Responder
-
getDate
public Date getDate()
-
setDate
public void setDate(Date date)
-
-