/* * Copyright (c) 2018, 2022, Oracle and/or its affiliates. All rights reserved. * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. * * This code is free software; you can redistribute it and/or modify it * under the terms of the GNU General Public License version 2 only, as * published by the Free Software Foundation. * * This code is distributed in the hope that it will be useful, but WITHOUT * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License * version 2 for more details (a copy is included in the LICENSE file that * accompanied this code). * * You should have received a copy of the GNU General Public License version * 2 along with this work; if not, write to the Free Software Foundation, * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. * * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA * or visit www.oracle.com if you need additional information or have any * questions.
*/
public String serialNumber; public String algorithm; public String subject; public String issuer; public String keyType; publiclong certId; publicint keyLength; public String encoded;
public X509Certificate certificate() throws CertificateException {
ByteArrayInputStream is = new ByteArrayInputStream(encoded.getBytes()); return (X509Certificate) CERTIFICATE_FACTORY.generateCertificate(is);
}
// Get the encoded form of the CertPath we made byte[] encoded = cp.getEncoded("PKCS7");
CERTIFICATE_FACTORY.generateCertPath(new ByteArrayInputStream(encoded), "PKCS7");
}
SecurityTools.keytool("-J-XX:StartFlightRecording=filename=keytool.jfr,settings=config.jfc", "-genkeypair", "-alias", "testkey", "-keyalg", "RSA", "-keysize", "2048", "-dname", "CN=8292033.oracle.com,OU=JPG,C=US", "-keypass", "changeit", "-validity", "365", "-keystore", "keystore.pkcs12", "-storepass", "changeit")
.shouldHaveExitValue(0); // The keytool command will load the keystore and call CertificateFactory.generateCertificate
jfrTool("keytool.jfr")
.shouldContain("8292033.oracle.com") // should record our new cert
.shouldNotContain("algorithm = N/A") // shouldn't record cert under construction
.shouldHaveExitValue(0);
}
publicstaticvoid generateChain(boolean selfSignedTest, boolean trustAnchorCert) throws Exception { // Do path validation as if it is always Tue, 06 Sep 2016 22:12:21 GMT // This value is within the lifetimes of all certificates.
Date testDate = new Date(1473199941000L);
TrustAnchor ta; if (trustAnchorCert) {
ta = new TrustAnchor(ca, null);
} else {
ta = new TrustAnchor(ca.getIssuerX500Principal(), ca.getPublicKey(), null);
}
CertPathValidator validator = CertPathValidator.getInstance("PKIX");
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.