Package org.keycloak.common.util
Class CertificateUtils
java.lang.Object
org.keycloak.common.util.CertificateUtils
The Class CertificateUtils provides utility functions for generation of V1 and V3
X509Certificate-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionstatic X509CertificategenerateV1SelfSignedCertificate(KeyPair caKeyPair, String subject) Generate version 1 self signedX509Certificate.static X509CertificategenerateV1SelfSignedCertificate(KeyPair caKeyPair, String subject, BigInteger serialNumber) static X509CertificategenerateV1SelfSignedCertificate(KeyPair caKeyPair, String subject, BigInteger serialNumber, Date validityEndDate) static X509CertificategenerateV3Certificate(KeyPair keyPair, PrivateKey caPrivateKey, X509Certificate caCert, String subject) Generates version 3X509Certificate.static booleanisSelfSigned(X509Certificate certificate) Checks whether the certificate is self signed, meaning it is self issued with matching subject and issuer names and its signature verifies with its own public key.
-
Constructor Details
-
CertificateUtils
public CertificateUtils()
-
-
Method Details
-
generateV3Certificate
public static X509Certificate generateV3Certificate(KeyPair keyPair, PrivateKey caPrivateKey, X509Certificate caCert, String subject) throws Exception Generates version 3X509Certificate.- Parameters:
keyPair- the key paircaPrivateKey- the CA private keycaCert- the CA certificatesubject- the subject name- Returns:
- the x509 certificate
- Throws:
Exception- the exception
-
generateV1SelfSignedCertificate
Generate version 1 self signedX509Certificate.- Parameters:
caKeyPair- the CA key pairsubject- the subject name- Returns:
- the x509 certificate
- Throws:
Exception- the exception
-
generateV1SelfSignedCertificate
public static X509Certificate generateV1SelfSignedCertificate(KeyPair caKeyPair, String subject, BigInteger serialNumber) -
generateV1SelfSignedCertificate
public static X509Certificate generateV1SelfSignedCertificate(KeyPair caKeyPair, String subject, BigInteger serialNumber, Date validityEndDate) -
isSelfSigned
Checks whether the certificate is self signed, meaning it is self issued with matching subject and issuer names and its signature verifies with its own public key.- Parameters:
certificate- the certificate to check- Returns:
- true if the certificate is self issued and signed by its own key
- Throws:
GeneralSecurityException- if the signature cannot be verified at all
-