Class X509ROCAValidator
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
net.shibboleth.shared.component.AbstractIdentifiedInitializableComponent
net.shibboleth.shared.component.AbstractIdentifiableInitializableComponent
net.shibboleth.metadata.validate.BaseValidator
net.shibboleth.metadata.validate.x509.AbstractX509Validator
net.shibboleth.metadata.validate.x509.X509ROCAValidator
- All Implemented Interfaces:
Validator<X509Certificate>,net.shibboleth.shared.component.Component,net.shibboleth.shared.component.DestructableComponent,net.shibboleth.shared.component.IdentifiableComponent,net.shibboleth.shared.component.IdentifiedComponent,net.shibboleth.shared.component.InitializableComponent
Validator class to check that X.509 certificate public keys are not
affected by the Return of Coppersmith Attack (ROCA, CVE-2017-15361).
- Since:
- 0.10.0
- See Also:
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionprivate static classChecks to see whether a given modulus represents a key affected by the attack.Nested classes/interfaces inherited from interface net.shibboleth.metadata.validate.Validator
Validator.Action -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionvoiddoValidate(X509Certificate cert, Item<?> item, String callerId) Apply the validator to the object in the givenItemcontext.Methods inherited from class net.shibboleth.metadata.validate.x509.AbstractX509Validator
validateMethods inherited from class net.shibboleth.metadata.validate.BaseValidator
addError, addErrorMessage, addErrorMessage, addErrorMessage, addStatus, addWarning, getMessage, makeComponentId, setMessageMethods inherited from class net.shibboleth.shared.component.AbstractIdentifiableInitializableComponent
setIdMethods inherited from class net.shibboleth.shared.component.AbstractIdentifiedInitializableComponent
doInitialize, ensureId, getId, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentExceptionMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.DestructableComponent
destroy, isDestroyedMethods inherited from interface net.shibboleth.shared.component.IdentifiableComponent
setIdMethods inherited from interface net.shibboleth.shared.component.IdentifiedComponent
getIdMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Constructor Details
-
X509ROCAValidator
public X509ROCAValidator()
-
-
Method Details
-
doValidate
public void doValidate(@Nonnull X509Certificate cert, @Nonnull Item<?> item, @Nonnull String callerId) Description copied from class:AbstractX509ValidatorApply the validator to the object in the givenItemcontext. The validator influences future processing by adding item metadata to theItem.- Specified by:
doValidatein classAbstractX509Validator- Parameters:
cert- the certificate to be validateditem- theItemcontext for the validationcallerId- aStringidentifying the caller
-