Package org.keycloak.broker.provider
Interface TrustMaterialIdentityProvider<C extends IdentityProviderModel>
- All Superinterfaces:
IdentityProvider<C>,Provider
- All Known Implementing Classes:
DefaultTrustIdentityProvider,GitLabIdentityProvider,GoogleIdentityProvider,KeycloakOIDCIdentityProvider,LinkedInOIDCIdentityProvider,OID4VPIdentityProvider,OIDCIdentityProvider
public interface TrustMaterialIdentityProvider<C extends IdentityProviderModel>
extends IdentityProvider<C>
Identity providers that expose reusable trust material for flows such as
client attestation or OID4VCI key attestation.
-
Method Summary
Modifier and TypeMethodDescriptionresolveKeys(TrustMaterialRequest request) default Stream<X509TrustMaterial>resolveX509Trust(TrustMaterialRequest request) Resolves X.509 trust anchors and policy.static JWKvalidateX509Chain(List<X509TrustMaterial> trustMaterials, List<String> x5c, String algorithm) Validates the x5c certificate chain against the given trust materials and returns the chain leaf key.default JWKvalidateX509Chain(TrustMaterialRequest request, List<String> x5c, String algorithm) Validates the x5c certificate chain of a presented artifact against this provider's X.509 trust material and returns the chain leaf key.Methods inherited from interface org.keycloak.broker.provider.IdentityProvider
export, getConfig, isMapperSupported, isType, reloadKeys
-
Method Details
-
resolveKeys
-
resolveX509Trust
Resolves X.509 trust anchors and policy. Providers that only expose JWKs do not need to implement this method. -
validateX509Chain
default JWK validateX509Chain(TrustMaterialRequest request, List<String> x5c, String algorithm) throws VerificationException Validates the x5c certificate chain of a presented artifact against this provider's X.509 trust material and returns the chain leaf key. Exposing X.509 trust anchors mandates chain validation: a missing or unverifiable chain fails.- Returns:
- the leaf key of the validated chain, or null when this provider exposes no X.509 trust material
- Throws:
VerificationException
-
validateX509Chain
static JWK validateX509Chain(List<X509TrustMaterial> trustMaterials, List<String> x5c, String algorithm) throws VerificationException Validates the x5c certificate chain against the given trust materials and returns the chain leaf key. The materials are tried in order and the first successful validation wins.- Returns:
- the leaf key of the validated chain, or null if no trust material was given
- Throws:
VerificationException
-