Package craterdog.security
Class CertificateManager
java.lang.Object
craterdog.security.CertificateManager
This class provides methods that hide the complexities of the Java security API in dealing
with certificate management.
- Author:
- Derk Norton
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionabstract X509CertificatecreateCertificate(PrivateKey caPrivateKey, X509Certificate caCertificate, PublicKey publicKey, String subject, BigInteger serialNumber, long lifetime)This method creates a new X509 certificate that is signed by a certificate authority (CA).abstract X509CertificatecreateCertificateAuthority(PrivateKey privateKey, PublicKey publicKey, String subject, BigInteger serialNumber, long lifetime)This method creates a new self-signed X509 certificate for a new certificate authority (CA).createPkcs12KeyStore(String keyName, char[] password, PrivateKey privateKey, X509Certificate certificate)This method creates a new PKCS12 format key store containing a named private key and public certificate.createPkcs12KeyStore(String keyName, char[] password, PrivateKey privateKey, List<X509Certificate> certificates)This method creates a new PKCS12 format key store containing a named private key and public certificate chain.abstract X509CertificatedecodeCertificate(String pem)This method decodes an X509 format certificate from a PEM string.decodeKeyStore(String base64String, char[] password)This method decodes a PKCS12 format key store from its encrypted byte stream.abstract StringencodeCertificate(X509Certificate certificate)This method encodes an X509 format certificate into a PEM string.encodeKeyStore(KeyStore keyStore, char[] password)This method encodes a PKCS12 format key store into a base 64 string format.retrieveCertificate(KeyStore keyStore, String certificateName)This method retrieves a public certificate from a key store.retrieveKeyStore(InputStream input, char[] password)This method retrieves a PKCS12 format key store from an input stream.retrievePrivateKey(KeyStore keyStore, String keyName, char[] password)This method retrieves a private key from a key store.voidsaveKeyStore(OutputStream output, KeyStore keyStore, char[] password)This method saves a PKCS12 format key store out to an output stream.
-
Constructor Details
-
CertificateManager
public CertificateManager()
-
-
Method Details
-
saveKeyStore
public final void saveKeyStore(OutputStream output, KeyStore keyStore, char[] password) throws IOExceptionThis method saves a PKCS12 format key store out to an output stream.- Parameters:
output- The output stream to be written to.keyStore- The PKCS12 format key store.password- The password that should be used to encrypt the file.- Throws:
IOException- Unable to save the key store to the specified output stream.
-
retrieveKeyStore
This method retrieves a PKCS12 format key store from an input stream.- Parameters:
input- The input stream from which to read the key store.password- The password that was used to encrypt the file.- Returns:
- The PKCS12 format key store.
- Throws:
IOException- Unable to retrieve the key store from the specified input stream.
-
retrieveCertificate
This method retrieves a public certificate from a key store.- Parameters:
keyStore- The key store containing the certificate.certificateName- The name (alias) of the certificate.- Returns:
- The X509 format public certificate.
-
retrievePrivateKey
This method retrieves a private key from a key store.- Parameters:
keyStore- The key store containing the private key.keyName- The name (alias) of the private key.password- The password used to encrypt the private key.- Returns:
- The decrypted private key.
-
createCertificateAuthority
public abstract X509Certificate createCertificateAuthority(PrivateKey privateKey, PublicKey publicKey, String subject, BigInteger serialNumber, long lifetime)This method creates a new self-signed X509 certificate for a new certificate authority (CA).- Parameters:
privateKey- The private key for the new certificate.publicKey- The public key that the new certificate is encoding.subject- The distinguished name for the certificate (e.g. CN=Derk Norton, O=Crater Dog Technologies).serialNumber- The unique serial number for the new certificate.lifetime- The number of milliseconds before the certificate should expire.- Returns:
- The new signed certificate.
-
createCertificate
public abstract X509Certificate createCertificate(PrivateKey caPrivateKey, X509Certificate caCertificate, PublicKey publicKey, String subject, BigInteger serialNumber, long lifetime)This method creates a new X509 certificate that is signed by a certificate authority (CA).- Parameters:
caPrivateKey- The private key for the certificate authority.caCertificate- The public certificate for the certificate authority.publicKey- The public key that the new certificate is encoding.subject- The distinguished name for the certificate (e.g. CN=Derk Norton, O=Crater Dog Technologies).serialNumber- The unique serial number for the new certificate.lifetime- The number of milliseconds before the certificate should expire.- Returns:
- The new signed certificate.
-
createPkcs12KeyStore
public final KeyStore createPkcs12KeyStore(String keyName, char[] password, PrivateKey privateKey, X509Certificate certificate)This method creates a new PKCS12 format key store containing a named private key and public certificate.- Parameters:
keyName- The name of the private key and public certificate.password- The password used to encrypt the private key.privateKey- The private key.certificate- The X509 format public certificate.- Returns:
- The new PKCS12 format key store.
-
createPkcs12KeyStore
public final KeyStore createPkcs12KeyStore(String keyName, char[] password, PrivateKey privateKey, List<X509Certificate> certificates)This method creates a new PKCS12 format key store containing a named private key and public certificate chain.- Parameters:
keyName- The name of the private key and public certificate.password- The password used to encrypt the private key.privateKey- The private key.certificates- The chain of X509 format public certificates.- Returns:
- The new PKCS12 format key store.
-
encodeCertificate
This method encodes an X509 format certificate into a PEM string.- Parameters:
certificate- The X509 format certificate.- Returns:
- The corresponding PEM string.
-
decodeCertificate
This method decodes an X509 format certificate from a PEM string.- Parameters:
pem- The PEM string for the certificate.- Returns:
- The corresponding X509 format certificate.
-
encodeKeyStore
This method encodes a PKCS12 format key store into a base 64 string format.- Parameters:
keyStore- The PKCS12 format key store to be encoded.password- The password to be used to encrypt the byte stream.- Returns:
- The base 64 encoded string.
-
decodeKeyStore
This method decodes a PKCS12 format key store from its encrypted byte stream.- Parameters:
base64String- The base 64 encoded, password encrypted PKCS12 byte stream.password- The password that was used to encrypt the byte stream.- Returns:
- The PKCS12 format key store.
-