public class DaneVerifier
extends java.lang.Object
| Constructor and Description |
|---|
DaneVerifier() |
DaneVerifier(org.minidns.AbstractDnsClient client) |
| Modifier and Type | Method and Description |
|---|---|
javax.net.ssl.HttpsURLConnection |
verifiedConnect(javax.net.ssl.HttpsURLConnection conn)
Invokes
URLConnection.connect() in a DANE verified fashion. |
javax.net.ssl.HttpsURLConnection |
verifiedConnect(javax.net.ssl.HttpsURLConnection conn,
javax.net.ssl.X509TrustManager trustManager)
Invokes
URLConnection.connect() in a DANE verified fashion. |
boolean |
verify(javax.net.ssl.SSLSession session)
Verifies the certificate chain in an active
SSLSession. |
boolean |
verify(javax.net.ssl.SSLSocket socket)
Verifies the certificate chain in an active
SSLSocket. |
boolean |
verifyCertificateChain(java.security.cert.X509Certificate[] chain,
java.lang.String hostName,
int port)
Verifies a certificate chain to be valid when used with the given connection details using DANE.
|
public DaneVerifier()
public DaneVerifier(org.minidns.AbstractDnsClient client)
public boolean verify(javax.net.ssl.SSLSocket socket)
throws java.security.cert.CertificateException
SSLSocket. The socket must be connected.socket - A connected SSLSocket whose certificate chain shall be verified using DANE.false, additional PKIX validation is required.java.security.cert.CertificateException - if the certificate chain provided differs from the one enforced using DANE.public boolean verify(javax.net.ssl.SSLSession session)
throws java.security.cert.CertificateException
SSLSession.session - An active SSLSession whose certificate chain shall be verified using DANE.false, additional PKIX validation is required.java.security.cert.CertificateException - if the certificate chain provided differs from the one enforced using DANE.public boolean verifyCertificateChain(java.security.cert.X509Certificate[] chain,
java.lang.String hostName,
int port)
throws java.security.cert.CertificateException
chain - A certificate chain that should be verified using DANE.hostName - The DNS name of the host this certificate chain belongs to.port - The port number that was used to reach the server providing the certificate chain in question.false, additional PKIX validation is required.java.security.cert.CertificateException - if the certificate chain provided differs from the one enforced using DANE.public javax.net.ssl.HttpsURLConnection verifiedConnect(javax.net.ssl.HttpsURLConnection conn)
throws java.io.IOException,
java.security.cert.CertificateException
URLConnection.connect() in a DANE verified fashion.
This method must be called before URLConnection.connect() is invoked.
If a SSLSocketFactory was set on this HttpsURLConnection, it will be ignored. You can use
verifiedConnect(HttpsURLConnection, X509TrustManager) to inject a custom TrustManager.conn - connection to be connected.HttpsURLConnection after being connected.java.io.IOException - when the connection could not be established.java.security.cert.CertificateException - if there was an exception while verifying the certificate.public javax.net.ssl.HttpsURLConnection verifiedConnect(javax.net.ssl.HttpsURLConnection conn,
javax.net.ssl.X509TrustManager trustManager)
throws java.io.IOException,
java.security.cert.CertificateException
URLConnection.connect() in a DANE verified fashion.
This method must be called before URLConnection.connect() is invoked.
If a SSLSocketFactory was set on this HttpsURLConnection, it will be ignored.conn - connection to be connected.trustManager - A non-default TrustManager to be used.HttpsURLConnection after being connected.java.io.IOException - when the connection could not be established.java.security.cert.CertificateException - if there was an exception while verifying the certificate.