public final class JdkSslServerContext extends JdkSslContext
SslContext which uses JDK's SSL/TLS implementation.| Modifier and Type | Field and Description |
|---|---|
private javax.net.ssl.SSLContext |
ctx |
private java.util.List<java.lang.String> |
nextProtocols |
DEFAULT_CIPHERS, PROTOCOL, PROTOCOLS| Constructor and Description |
|---|
JdkSslServerContext(java.io.File certChainFile,
java.io.File keyFile)
Creates a new instance.
|
JdkSslServerContext(java.io.File certChainFile,
java.io.File keyFile,
java.lang.String keyPassword)
Creates a new instance.
|
JdkSslServerContext(SslBufferPool bufPool,
java.io.File certChainFile,
java.io.File keyFile,
java.lang.String keyPassword,
java.lang.Iterable<java.lang.String> ciphers,
java.lang.Iterable<java.lang.String> nextProtocols,
long sessionCacheSize,
long sessionTimeout)
Creates a new instance.
|
| Modifier and Type | Method and Description |
|---|---|
javax.net.ssl.SSLContext |
context()
Returns the JDK
SSLContext object held by this context. |
private static java.security.spec.PKCS8EncodedKeySpec |
generateKeySpec(char[] password,
byte[] key)
Generates a key specification for an (encrypted) private key.
|
boolean |
isClient()
Returns the
true if and only if this context is for client-side. |
java.util.List<java.lang.String> |
nextProtocols()
Returns the list of application layer protocols for the TLS NPN/ALPN extension, in the order of preference.
|
cipherSuites, newEngine, newEngine, sessionCacheSize, sessionContext, sessionTimeoutbufferPool, defaultClientProvider, defaultServerProvider, isServer, newBufferPool, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newHandler, newHandler, newServerContext, newServerContext, newServerContext, newServerContext, newServerContext, newServerContextprivate final javax.net.ssl.SSLContext ctx
private final java.util.List<java.lang.String> nextProtocols
public JdkSslServerContext(java.io.File certChainFile,
java.io.File keyFile)
throws javax.net.ssl.SSLException
certChainFile - an X.509 certificate chain file in PEM formatkeyFile - a PKCS#8 private key file in PEM formatjavax.net.ssl.SSLExceptionpublic JdkSslServerContext(java.io.File certChainFile,
java.io.File keyFile,
java.lang.String keyPassword)
throws javax.net.ssl.SSLException
certChainFile - an X.509 certificate chain file in PEM formatkeyFile - a PKCS#8 private key file in PEM formatkeyPassword - the password of the keyFile.
null if it's not password-protected.javax.net.ssl.SSLExceptionpublic JdkSslServerContext(SslBufferPool bufPool, java.io.File certChainFile, java.io.File keyFile, java.lang.String keyPassword, java.lang.Iterable<java.lang.String> ciphers, java.lang.Iterable<java.lang.String> nextProtocols, long sessionCacheSize, long sessionTimeout) throws javax.net.ssl.SSLException
bufPool - the buffer pool which will be used by this context.
null to use the default buffer pool.certChainFile - an X.509 certificate chain file in PEM formatkeyFile - a PKCS#8 private key file in PEM formatkeyPassword - the password of the keyFile.
null if it's not password-protected.ciphers - the cipher suites to enable, in the order of preference.
null to use the default cipher suites.nextProtocols - the application layer protocols to accept, in the order of preference.
null to disable TLS NPN/ALPN extension.sessionCacheSize - the size of the cache used for storing SSL session objects.
0 to use the default value.sessionTimeout - the timeout for the cached SSL session objects, in seconds.
0 to use the default value.javax.net.ssl.SSLExceptionpublic boolean isClient()
SslContexttrue if and only if this context is for client-side.isClient in class SslContextpublic java.util.List<java.lang.String> nextProtocols()
SslContextnextProtocols in class SslContextnull if NPN/ALPN extension has been disabled.public javax.net.ssl.SSLContext context()
JdkSslContextSSLContext object held by this context.context in class JdkSslContextprivate static java.security.spec.PKCS8EncodedKeySpec generateKeySpec(char[] password,
byte[] key)
throws java.io.IOException,
java.security.NoSuchAlgorithmException,
javax.crypto.NoSuchPaddingException,
java.security.spec.InvalidKeySpecException,
java.security.InvalidKeyException,
java.security.InvalidAlgorithmParameterException
password - characters, if null or empty an unencrypted key is assumedkey - bytes of the DER encoded private keyjava.io.IOException - if parsing key failsjava.security.NoSuchAlgorithmException - if the algorithm used to encrypt key is unkownjavax.crypto.NoSuchPaddingException - if the padding scheme specified in the decryption algorithm is unkownjava.security.spec.InvalidKeySpecException - if the decryption key based on password cannot be generatedjava.security.InvalidKeyException - if the decryption key based on password cannot be used to decrypt keyjava.security.InvalidAlgorithmParameterException - if decryption algorithm parameters are somehow faulty