Package tigase.io
Interface SSLContextContainerIfc
-
- All Superinterfaces:
Lifecycle
- All Known Implementing Classes:
SSLContextContainer,SSLContextContainer.Root,SSLContextContainerAbstract
public interface SSLContextContainerIfc extends Lifecycle
Describe interface SSLContextContainerIfc here.
Created: Tue Nov 20 11:43:32 2007- Version:
- $Rev$
- Author:
- Artur Hefczyc
-
-
Field Summary
Fields Modifier and Type Field Description static StringALLOW_INVALID_CERTS_KEYConstantALLOW_INVALID_CERTS_KEYis a key pointing to a configuration parameters specyfying if invalid certificates are acceptable by the server.static StringALLOW_INVALID_CERTS_VALConstantALLOW_INVALID_CERTS_VALis a default configuration parameter specifying if invalid certificates are acceptable by the server.static StringALLOW_SELF_SIGNED_CERTS_KEYConstantALLOW_SELF_SIGNED_CERTS_KEYis a key pointing to a configuration parameter specifying if self-signed certificates are acceptable for the server.static StringALLOW_SELF_SIGNED_CERTS_VALConstantALLOW_SELF_SIGNED_CERTS_VALis a default configuration value specifying if self-signed certificates are allowed by the server.static StringCERT_ALIAS_KEYstatic StringCERT_SAVE_TO_DISK_KEYstatic StringDEFAULT_DOMAIN_CERT_KEYConstantDEFAULT_DOMAIN_CERT_KEYis a key pointing to the domain with default certificate.static StringDEFAULT_DOMAIN_CERT_VALConstantDEFAULT_DOMAIN_CERT_VALkeeps default value for a domain with default certificate.static StringJKS_KEYSTORE_FILE_KEYConstantJKS_KEYSTORE_FILE_KEYis a key pointing to a JKS keystore file.static StringJKS_KEYSTORE_FILE_VALConstantJKS_KEYSTORE_FILE_VALkeeps default value for a JKS keystore file.static StringJKS_KEYSTORE_PWD_KEYConstantJKS_KEYSTORE_PWD_KEYis a key pointing to a private key password,static StringJKS_KEYSTORE_PWD_VALConstantJKS_KEYSTORE_PWD_VALis a default private key password.static StringPEM_CERTIFICATE_KEYstatic StringSERVER_CERTS_LOCATION_KEYConstantSERVER_CERTS_DIR_KEYis a key pointing to a configuration parameter with directory names where all server certificates are stored.static StringSERVER_CERTS_LOCATION_VALConstantSERVER_CERTS_DIR_VALis a default directory name where all certificate files are stored.static StringSSL_CONTAINER_CLASS_KEYConstantSSL_CONTAINER_CLASS_KEYis a key pointing to a container implementation class.static StringSSL_CONTAINER_CLASS_VALConstantSSL_CONTAINER_CLASS_VALkeeps default container implementation class loaded if none is specified in configuration file.static StringTRUSTED_CERTS_DIR_KEYConstantTRUSTED_CERTS_DIR_KEYis a key pointing to a configuration parameter where all trusted certificates are stored.static StringTRUSTED_CERTS_DIR_VALConstantTRUSTED_CERTS_DIR_VALis a default directory name where all trusted certificates are stored.static StringTRUSTSTORE_FILE_KEYConstantTRUSTSTORE_FILE_KEYis a key pointing to a trust store file.static StringTRUSTSTORE_FILE_VALConstantTRUSTSTORE_FILE_VALis a default truststore file.static StringTRUSTSTORE_PWD_KEYConstantTRUSTSTORE_PWD_KEYis a key pointing to a trustore file password.static StringTRUSTSTORE_PWD_VALConstantTRUSTSTORE_PWD_VALis a default password for truststore file.
-
Method Summary
All Methods Instance Methods Abstract Methods Modifier and Type Method Description voidaddCertificates(Map<String,String> params)MethodaddCertificatesallows to add more certificates at run time after the container has bee already initialized.IOInterfacecreateIoInterface(String protocol, String tls_hostname, int port, boolean clientMode, boolean wantClientAuth, boolean needClientAuth, ByteOrder byteOrder, TrustManager[] x509TrustManagers, TLSEventHandler eventHandler, IOInterface ioi, CertificateContainerIfc certificateContainer)String[]getEnabledCiphers()String[]getEnabledProtocols()SSLContextgetSSLContext(String protocol, String hostname, boolean clientMode)MethodgetSSLContextcreates and returns new SSLContext for a given domain (hostname).SSLContextgetSSLContext(String protocol, String hostname, boolean clientMode, TrustManager[] tms)MethodgetSSLContextcreates and returns new SSLContext for a given domain (hostname).KeyStoregetTrustStore()Returns a trust store with all trusted certificates.
-
-
-
Field Detail
-
ALLOW_INVALID_CERTS_KEY
static final String ALLOW_INVALID_CERTS_KEY
ConstantALLOW_INVALID_CERTS_KEYis a key pointing to a configuration parameters specyfying if invalid certificates are acceptable by the server. Invalid certificates are expired ones or certificates issued for a different domain. This should be really set tofalsein any real deployment and can be set ottruein development invironment.- See Also:
- Constant Field Values
-
ALLOW_INVALID_CERTS_VAL
static final String ALLOW_INVALID_CERTS_VAL
ConstantALLOW_INVALID_CERTS_VALis a default configuration parameter specifying if invalid certificates are acceptable by the server.- See Also:
- Constant Field Values
-
ALLOW_SELF_SIGNED_CERTS_KEY
static final String ALLOW_SELF_SIGNED_CERTS_KEY
ConstantALLOW_SELF_SIGNED_CERTS_KEYis a key pointing to a configuration parameter specifying if self-signed certificates are acceptable for the server.- See Also:
- Constant Field Values
-
ALLOW_SELF_SIGNED_CERTS_VAL
static final String ALLOW_SELF_SIGNED_CERTS_VAL
ConstantALLOW_SELF_SIGNED_CERTS_VALis a default configuration value specifying if self-signed certificates are allowed by the server.- See Also:
- Constant Field Values
-
CERT_ALIAS_KEY
static final String CERT_ALIAS_KEY
- See Also:
- Constant Field Values
-
CERT_SAVE_TO_DISK_KEY
static final String CERT_SAVE_TO_DISK_KEY
- See Also:
- Constant Field Values
-
DEFAULT_DOMAIN_CERT_KEY
static final String DEFAULT_DOMAIN_CERT_KEY
ConstantDEFAULT_DOMAIN_CERT_KEYis a key pointing to the domain with default certificate.- See Also:
- Constant Field Values
-
DEFAULT_DOMAIN_CERT_VAL
static final String DEFAULT_DOMAIN_CERT_VAL
ConstantDEFAULT_DOMAIN_CERT_VALkeeps default value for a domain with default certificate.- See Also:
- Constant Field Values
-
JKS_KEYSTORE_FILE_KEY
static final String JKS_KEYSTORE_FILE_KEY
ConstantJKS_KEYSTORE_FILE_KEYis a key pointing to a JKS keystore file.- See Also:
- Constant Field Values
-
JKS_KEYSTORE_FILE_VAL
static final String JKS_KEYSTORE_FILE_VAL
ConstantJKS_KEYSTORE_FILE_VALkeeps default value for a JKS keystore file.
-
JKS_KEYSTORE_PWD_KEY
static final String JKS_KEYSTORE_PWD_KEY
ConstantJKS_KEYSTORE_PWD_KEYis a key pointing to a private key password,- See Also:
- Constant Field Values
-
JKS_KEYSTORE_PWD_VAL
static final String JKS_KEYSTORE_PWD_VAL
ConstantJKS_KEYSTORE_PWD_VALis a default private key password.- See Also:
- Constant Field Values
-
PEM_CERTIFICATE_KEY
static final String PEM_CERTIFICATE_KEY
- See Also:
- Constant Field Values
-
SERVER_CERTS_LOCATION_KEY
static final String SERVER_CERTS_LOCATION_KEY
ConstantSERVER_CERTS_DIR_KEYis a key pointing to a configuration parameter with directory names where all server certificates are stored. This can be a comma separated list of directories, instead of a single directory name. Certificates are stored in*.pemfiles where the first part of the file name is a domain name i.e.:yourdomain.com.pem. There is one exception though. The file nameddefault.pemstores a certificate which is a default certificate for the server if certificate for specific domain is missing.- See Also:
- Constant Field Values
-
SERVER_CERTS_LOCATION_VAL
static final String SERVER_CERTS_LOCATION_VAL
ConstantSERVER_CERTS_DIR_VALis a default directory name where all certificate files are stored.- See Also:
- Constant Field Values
-
SSL_CONTAINER_CLASS_KEY
static final String SSL_CONTAINER_CLASS_KEY
ConstantSSL_CONTAINER_CLASS_KEYis a key pointing to a container implementation class. The class is loaded at startup time and initialized using configuration parameters. Some container implementations may accept different parameters set. Please refer to the implementation for more details.- See Also:
- Constant Field Values
-
SSL_CONTAINER_CLASS_VAL
static final String SSL_CONTAINER_CLASS_VAL
ConstantSSL_CONTAINER_CLASS_VALkeeps default container implementation class loaded if none is specified in configuration file.
-
TRUSTED_CERTS_DIR_KEY
static final String TRUSTED_CERTS_DIR_KEY
ConstantTRUSTED_CERTS_DIR_KEYis a key pointing to a configuration parameter where all trusted certificates are stored. This can be a comma separated list of directories.- See Also:
- Constant Field Values
-
TRUSTED_CERTS_DIR_VAL
static final String TRUSTED_CERTS_DIR_VAL
ConstantTRUSTED_CERTS_DIR_VALis a default directory name where all trusted certificates are stored.- See Also:
- Constant Field Values
-
TRUSTSTORE_FILE_KEY
static final String TRUSTSTORE_FILE_KEY
ConstantTRUSTSTORE_FILE_KEYis a key pointing to a trust store file.- See Also:
- Constant Field Values
-
TRUSTSTORE_FILE_VAL
static final String TRUSTSTORE_FILE_VAL
ConstantTRUSTSTORE_FILE_VALis a default truststore file.
-
TRUSTSTORE_PWD_KEY
static final String TRUSTSTORE_PWD_KEY
ConstantTRUSTSTORE_PWD_KEYis a key pointing to a trustore file password.- See Also:
- Constant Field Values
-
TRUSTSTORE_PWD_VAL
static final String TRUSTSTORE_PWD_VAL
ConstantTRUSTSTORE_PWD_VALis a default password for truststore file.- See Also:
- Constant Field Values
-
-
Method Detail
-
addCertificates
void addCertificates(Map<String,String> params) throws CertificateParsingException
MethodaddCertificatesallows to add more certificates at run time after the container has bee already initialized. This is to avoid server restart if there are certificates updates or new certificates for new virtual domain. The method should add new certificates or replace existing one if there is already a certificate for a domain.- Parameters:
params- aMapvalue with configuration parameters.- Throws:
CertificateParsingException
-
createIoInterface
IOInterface createIoInterface(String protocol, String tls_hostname, int port, boolean clientMode, boolean wantClientAuth, boolean needClientAuth, ByteOrder byteOrder, TrustManager[] x509TrustManagers, TLSEventHandler eventHandler, IOInterface ioi, CertificateContainerIfc certificateContainer) throws IOException
- Throws:
IOException
-
getSSLContext
SSLContext getSSLContext(String protocol, String hostname, boolean clientMode)
MethodgetSSLContextcreates and returns new SSLContext for a given domain (hostname). For creation of the SSLContext a certificate associated with this domain (hostname) should be used. If there is no specific certificate for a given domain then default certificate should be used.- Parameters:
protocol- aStringis either 'SSL' or 'TLS' value.hostname- aStringvalue keeps a hostname or domain for SSLContext.clientMode- if set SSLContext will be created for client mode (ie. creation of server certificate will be skipped if there is no certificate)- Returns:
- a
SSLContextvalue
-
getSSLContext
SSLContext getSSLContext(String protocol, String hostname, boolean clientMode, TrustManager[] tms)
MethodgetSSLContextcreates and returns new SSLContext for a given domain (hostname). For creation of the SSLContext a certificate associated with this domain (hostname) should be used. If there is no specific certificate for a given domain then default certificate should be used.- Parameters:
protocol- aStringis either 'SSL' or 'TLS' value.hostname- aStringvalue keeps a hostname or domain for SSLContext.clientMode- if set SSLContext will be created for client mode (ie. creation of server certificate will be skipped if there is no certificate)tms- array of TrustManagers which should be used to validate remote certificate- Returns:
- a
SSLContextvalue
-
getTrustStore
KeyStore getTrustStore()
Returns a trust store with all trusted certificates.- Returns:
- a KeyStore with all trusted certificates, the KeyStore can be empty but cannot be null.
-
getEnabledCiphers
String[] getEnabledCiphers()
-
getEnabledProtocols
String[] getEnabledProtocols()
-
-