Class CertificateManager

java.lang.Object
craterdog.security.CertificateManager

public abstract class CertificateManager extends Object
This class provides methods that hide the complexities of the Java security API in dealing with certificate management.
Author:
Derk Norton
  • Constructor Details

    • CertificateManager

      public CertificateManager()
  • Method Details

    • saveKeyStore

      public final void saveKeyStore​(OutputStream output, KeyStore keyStore, char[] password) throws IOException
      This method saves a PKCS12 format key store out to an output stream.
      Parameters:
      output - The output stream to be written to.
      keyStore - The PKCS12 format key store.
      password - The password that should be used to encrypt the file.
      Throws:
      IOException - Unable to save the key store to the specified output stream.
    • retrieveKeyStore

      public final KeyStore retrieveKeyStore​(InputStream input, char[] password) throws IOException
      This method retrieves a PKCS12 format key store from an input stream.
      Parameters:
      input - The input stream from which to read the key store.
      password - The password that was used to encrypt the file.
      Returns:
      The PKCS12 format key store.
      Throws:
      IOException - Unable to retrieve the key store from the specified input stream.
    • retrieveCertificate

      public final X509Certificate retrieveCertificate​(KeyStore keyStore, String certificateName)
      This method retrieves a public certificate from a key store.
      Parameters:
      keyStore - The key store containing the certificate.
      certificateName - The name (alias) of the certificate.
      Returns:
      The X509 format public certificate.
    • retrievePrivateKey

      public final PrivateKey retrievePrivateKey​(KeyStore keyStore, String keyName, char[] password)
      This method retrieves a private key from a key store.
      Parameters:
      keyStore - The key store containing the private key.
      keyName - The name (alias) of the private key.
      password - The password used to encrypt the private key.
      Returns:
      The decrypted private key.
    • createCertificateAuthority

      public abstract X509Certificate createCertificateAuthority​(PrivateKey privateKey, PublicKey publicKey, String subject, BigInteger serialNumber, long lifetime)
      This method creates a new self-signed X509 certificate for a new certificate authority (CA).
      Parameters:
      privateKey - The private key for the new certificate.
      publicKey - The public key that the new certificate is encoding.
      subject - The distinguished name for the certificate (e.g. CN=Derk Norton, O=Crater Dog Technologies).
      serialNumber - The unique serial number for the new certificate.
      lifetime - The number of milliseconds before the certificate should expire.
      Returns:
      The new signed certificate.
    • createCertificate

      public abstract X509Certificate createCertificate​(PrivateKey caPrivateKey, X509Certificate caCertificate, PublicKey publicKey, String subject, BigInteger serialNumber, long lifetime)
      This method creates a new X509 certificate that is signed by a certificate authority (CA).
      Parameters:
      caPrivateKey - The private key for the certificate authority.
      caCertificate - The public certificate for the certificate authority.
      publicKey - The public key that the new certificate is encoding.
      subject - The distinguished name for the certificate (e.g. CN=Derk Norton, O=Crater Dog Technologies).
      serialNumber - The unique serial number for the new certificate.
      lifetime - The number of milliseconds before the certificate should expire.
      Returns:
      The new signed certificate.
    • createPkcs12KeyStore

      public final KeyStore createPkcs12KeyStore​(String keyName, char[] password, PrivateKey privateKey, X509Certificate certificate)
      This method creates a new PKCS12 format key store containing a named private key and public certificate.
      Parameters:
      keyName - The name of the private key and public certificate.
      password - The password used to encrypt the private key.
      privateKey - The private key.
      certificate - The X509 format public certificate.
      Returns:
      The new PKCS12 format key store.
    • createPkcs12KeyStore

      public final KeyStore createPkcs12KeyStore​(String keyName, char[] password, PrivateKey privateKey, List<X509Certificate> certificates)
      This method creates a new PKCS12 format key store containing a named private key and public certificate chain.
      Parameters:
      keyName - The name of the private key and public certificate.
      password - The password used to encrypt the private key.
      privateKey - The private key.
      certificates - The chain of X509 format public certificates.
      Returns:
      The new PKCS12 format key store.
    • encodeCertificate

      public abstract String encodeCertificate​(X509Certificate certificate)
      This method encodes an X509 format certificate into a PEM string.
      Parameters:
      certificate - The X509 format certificate.
      Returns:
      The corresponding PEM string.
    • decodeCertificate

      public abstract X509Certificate decodeCertificate​(String pem)
      This method decodes an X509 format certificate from a PEM string.
      Parameters:
      pem - The PEM string for the certificate.
      Returns:
      The corresponding X509 format certificate.
    • encodeKeyStore

      public final String encodeKeyStore​(KeyStore keyStore, char[] password)
      This method encodes a PKCS12 format key store into a base 64 string format.
      Parameters:
      keyStore - The PKCS12 format key store to be encoded.
      password - The password to be used to encrypt the byte stream.
      Returns:
      The base 64 encoded string.
    • decodeKeyStore

      public final KeyStore decodeKeyStore​(String base64String, char[] password)
      This method decodes a PKCS12 format key store from its encrypted byte stream.
      Parameters:
      base64String - The base 64 encoded, password encrypted PKCS12 byte stream.
      password - The password that was used to encrypt the byte stream.
      Returns:
      The PKCS12 format key store.