Class CertificateUtils

java.lang.Object
org.keycloak.common.util.CertificateUtils

public class CertificateUtils extends Object
The Class CertificateUtils provides utility functions for generation of V1 and V3 X509Certificate
  • Constructor Details

    • CertificateUtils

      public CertificateUtils()
  • Method Details

    • generateV3Certificate

      public static X509Certificate generateV3Certificate(KeyPair keyPair, PrivateKey caPrivateKey, X509Certificate caCert, String subject) throws Exception
      Generates version 3 X509Certificate.
      Parameters:
      keyPair - the key pair
      caPrivateKey - the CA private key
      caCert - the CA certificate
      subject - the subject name
      Returns:
      the x509 certificate
      Throws:
      Exception - the exception
    • generateV1SelfSignedCertificate

      public static X509Certificate generateV1SelfSignedCertificate(KeyPair caKeyPair, String subject)
      Generate version 1 self signed X509Certificate.
      Parameters:
      caKeyPair - the CA key pair
      subject - the subject name
      Returns:
      the x509 certificate
      Throws:
      Exception - the exception
    • generateV1SelfSignedCertificate

      public static X509Certificate generateV1SelfSignedCertificate(KeyPair caKeyPair, String subject, BigInteger serialNumber)
    • generateV1SelfSignedCertificate

      public static X509Certificate generateV1SelfSignedCertificate(KeyPair caKeyPair, String subject, BigInteger serialNumber, Date validityEndDate)
    • isSelfSigned

      public static boolean isSelfSigned(X509Certificate certificate) throws GeneralSecurityException
      Checks whether the certificate is self signed, meaning it is self issued with matching subject and issuer names and its signature verifies with its own public key.
      Parameters:
      certificate - the certificate to check
      Returns:
      true if the certificate is self issued and signed by its own key
      Throws:
      GeneralSecurityException - if the signature cannot be verified at all