Package org.keycloak.crypto
Class X509CertificateChainValidator
java.lang.Object
org.keycloak.crypto.X509CertificateChainValidator
Validates x5c certificate chains of end entity signing certificates against a set of trust
anchors and an optional extended key usage requirement.
-
Method Summary
Modifier and TypeMethodDescriptionstatic List<X509Certificate>decodeCertificateChain(List<String> x5c) static JWKtoJwk(X509Certificate leaf, String algorithm, List<X509Certificate> certificateChain) static JWKvalidate(List<String> x5c, String algorithm, Collection<X509Certificate> trustAnchors, List<String> requiredExtendedKeyUsages) Validates the x5c certificate chain against the given trust anchors and returns the leaf key as JWK.
-
Method Details
-
validate
public static JWK validate(List<String> x5c, String algorithm, Collection<X509Certificate> trustAnchors, List<String> requiredExtendedKeyUsages) throws VerificationException Validates the x5c certificate chain against the given trust anchors and returns the leaf key as JWK. The leaf must be a currently valid end entity certificate usable for digital signatures. WhenrequiredExtendedKeyUsagesis not empty, the leaf must additionally contain at least one of the given extended key usage OIDs.- Throws:
VerificationException
-
decodeCertificateChain
public static List<X509Certificate> decodeCertificateChain(List<String> x5c) throws VerificationException - Throws:
VerificationException
-
toJwk
public static JWK toJwk(X509Certificate leaf, String algorithm, List<X509Certificate> certificateChain) throws VerificationException - Throws:
VerificationException
-