Class X509RSAExponentValidator
java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
net.shibboleth.shared.component.AbstractIdentifiedInitializableComponent
net.shibboleth.shared.component.AbstractIdentifiableInitializableComponent
net.shibboleth.metadata.validate.BaseValidator
net.shibboleth.metadata.validate.x509.AbstractX509Validator
net.shibboleth.metadata.validate.x509.X509RSAExponentValidator
- All Implemented Interfaces:
Validator<X509Certificate>,net.shibboleth.shared.component.Component,net.shibboleth.shared.component.DestructableComponent,net.shibboleth.shared.component.IdentifiableComponent,net.shibboleth.shared.component.IdentifiedComponent,net.shibboleth.shared.component.InitializableComponent
Validator class to check RSA public exponent values in X.509 certificates.
An instance of the class can be configured to have both a warning boundary and an
error boundary. The default is to give an error for any exponent less than or equal to
three, with no provision for warnings.
This NIST recommendation is for at least 65537 (2**16+1) but it's not obvious where
this came from so doesn't seem worth insisting on by default.
- Since:
- 0.9.0
-
Nested Class Summary
Nested classes/interfaces inherited from interface net.shibboleth.metadata.validate.Validator
Validator.Action -
Field Summary
FieldsModifier and TypeFieldDescriptionprivate BigIntegerThe RSA public exponent value below which an error should result.private BigIntegerThe RSA public exponent value below which a warning should result. -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprivate static final BigIntegerbigInteger(long value) Private method to wrap construction ofBigIntegerliterals.voiddoValidate(X509Certificate cert, Item<?> item, String callerId) Apply the validator to the object in the givenItemcontext.final BigIntegerGet the RSA public exponent below which an error will result.final BigIntegerGet the RSA public exponent below which a warning will result.voidsetErrorBoundary(long length) Set the RSA public exponent below which an error should result.voidsetErrorBoundary(BigInteger length) Set the RSA public exponent below which an error should result.voidsetWarningBoundary(long length) Set the RSA public exponent below which a warning should result.voidsetWarningBoundary(BigInteger length) Set the RSA public exponent below which a warning should result.Methods inherited from class net.shibboleth.metadata.validate.x509.AbstractX509Validator
validateMethods inherited from class net.shibboleth.metadata.validate.BaseValidator
addError, addErrorMessage, addErrorMessage, addErrorMessage, addStatus, addWarning, getMessage, makeComponentId, setMessageMethods inherited from class net.shibboleth.shared.component.AbstractIdentifiableInitializableComponent
setIdMethods inherited from class net.shibboleth.shared.component.AbstractIdentifiedInitializableComponent
doInitialize, ensureId, getId, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentExceptionMethods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent
checkComponentActive, checkSetterPreconditions, destroy, doDestroy, initialize, isDestroyed, isInitializedMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface net.shibboleth.shared.component.DestructableComponent
destroy, isDestroyedMethods inherited from interface net.shibboleth.shared.component.IdentifiableComponent
setIdMethods inherited from interface net.shibboleth.shared.component.IdentifiedComponent
getIdMethods inherited from interface net.shibboleth.shared.component.InitializableComponent
initialize, isInitialized
-
Field Details
-
errorBoundary
The RSA public exponent value below which an error should result. Default: 5. -
warningBoundary
The RSA public exponent value below which a warning should result. Default: 0 (disabled).
-
-
Constructor Details
-
X509RSAExponentValidator
public X509RSAExponentValidator()
-
-
Method Details
-
bigInteger
Private method to wrap construction ofBigIntegerliterals.- Parameters:
value- value to be converted toBigInteger- Returns:
- the converted
BigInteger
-
getErrorBoundary
Get the RSA public exponent below which an error will result.- Returns:
- the RSA public exponent below which an error will result.
-
setErrorBoundary
Set the RSA public exponent below which an error should result.- Parameters:
length- the RSA public exponent below which an error should result
-
setErrorBoundary
public void setErrorBoundary(long length) Set the RSA public exponent below which an error should result.- Parameters:
length- the RSA public exponent below which an error should result
-
getWarningBoundary
Get the RSA public exponent below which a warning will result.- Returns:
- the RSA public exponent below which a warning will result.
-
setWarningBoundary
Set the RSA public exponent below which a warning should result.- Parameters:
length- the RSA public exponent below which a warning should result
-
setWarningBoundary
public void setWarningBoundary(long length) Set the RSA public exponent below which a warning should result.- Parameters:
length- the RSA public exponent below which a warning should result
-
doValidate
public void doValidate(@Nonnull X509Certificate cert, @Nonnull Item<?> item, @Nonnull String callerId) Description copied from class:AbstractX509ValidatorApply the validator to the object in the givenItemcontext. The validator influences future processing by adding item metadata to theItem.- Specified by:
doValidatein classAbstractX509Validator- Parameters:
cert- the certificate to be validateditem- theItemcontext for the validationcallerId- aStringidentifying the caller
-