Class X509RSAKeyLengthValidator

java.lang.Object
net.shibboleth.shared.component.AbstractInitializableComponent
net.shibboleth.shared.component.AbstractIdentifiedInitializableComponent
net.shibboleth.shared.component.AbstractIdentifiableInitializableComponent
All Implemented Interfaces:
Validator<X509Certificate>, net.shibboleth.shared.component.Component, net.shibboleth.shared.component.DestructableComponent, net.shibboleth.shared.component.IdentifiableComponent, net.shibboleth.shared.component.IdentifiedComponent, net.shibboleth.shared.component.InitializableComponent

@ThreadSafe public class X509RSAKeyLengthValidator extends AbstractX509Validator
Validator class to check RSA key lengths in X.509 certificates. An instance of the class can be configured to have both a warning boundary and an error boundary. The default is to give an error for any key smaller than 2048 bits, with no provision for warnings. This seems the right long term default. During the transition to 2048-bit keys, it may be appropriate to set the warning boundary to 2048 bits and the error boundary to 1024 bits.
Since:
0.9.0
  • Nested Class Summary

    Nested classes/interfaces inherited from interface net.shibboleth.metadata.validate.Validator

    Validator.Action
  • Field Summary

    Fields
    Modifier and Type
    Field
    Description
    private int
    The RSA key length below which an error should result.
    private int
    The RSA key length below which a warning should result.
  • Constructor Summary

    Constructors
    Constructor
    Description
     
  • Method Summary

    Modifier and Type
    Method
    Description
    void
    doValidate(X509Certificate cert, Item<?> item, String callerId)
    Apply the validator to the object in the given Item context.
    final int
    Get the RSA key length below which an error will result.
    final int
    Get the RSA key length below which a warning will result.
    void
    setErrorBoundary(int length)
    Set the RSA key length below which an error should result.
    void
    setWarningBoundary(int length)
    Set the RSA key length below which a warning should result.

    Methods inherited from class net.shibboleth.metadata.validate.x509.AbstractX509Validator

    validate

    Methods inherited from class net.shibboleth.metadata.validate.BaseValidator

    addError, addErrorMessage, addErrorMessage, addErrorMessage, addStatus, addWarning, getMessage, makeComponentId, setMessage

    Methods inherited from class net.shibboleth.shared.component.AbstractIdentifiableInitializableComponent

    setId

    Methods inherited from class net.shibboleth.shared.component.AbstractIdentifiedInitializableComponent

    doInitialize, ensureId, getId, ifDestroyedThrowDestroyedComponentException, ifInitializedThrowUnmodifiabledComponentException, ifNotInitializedThrowUninitializedComponentException

    Methods inherited from class net.shibboleth.shared.component.AbstractInitializableComponent

    checkComponentActive, checkSetterPreconditions, destroy, doDestroy, initialize, isDestroyed, isInitialized

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait

    Methods inherited from interface net.shibboleth.shared.component.DestructableComponent

    destroy, isDestroyed

    Methods inherited from interface net.shibboleth.shared.component.IdentifiableComponent

    setId

    Methods inherited from interface net.shibboleth.shared.component.IdentifiedComponent

    getId

    Methods inherited from interface net.shibboleth.shared.component.InitializableComponent

    initialize, isInitialized

    Methods inherited from interface net.shibboleth.metadata.validate.Validator

    validate
  • Field Details

    • errorBoundary

      private int errorBoundary
      The RSA key length below which an error should result. Default: 2048.
    • warningBoundary

      private int warningBoundary
      The RSA key length below which a warning should result. Default: 0 (disabled).
  • Constructor Details

    • X509RSAKeyLengthValidator

      public X509RSAKeyLengthValidator()
  • Method Details

    • getErrorBoundary

      public final int getErrorBoundary()
      Get the RSA key length below which an error will result.
      Returns:
      the RSA key length below which an error will result.
    • setErrorBoundary

      public void setErrorBoundary(int length)
      Set the RSA key length below which an error should result.
      Parameters:
      length - the RSA key length below which an error should result
    • getWarningBoundary

      public final int getWarningBoundary()
      Get the RSA key length below which a warning will result.
      Returns:
      the RSA key length below which a warning will result.
    • setWarningBoundary

      public void setWarningBoundary(int length)
      Set the RSA key length below which a warning should result.
      Parameters:
      length - the RSA key length below which a warning should result
    • doValidate

      public void doValidate(@Nonnull X509Certificate cert, @Nonnull Item<?> item, @Nonnull String callerId)
      Description copied from class: AbstractX509Validator
      Apply the validator to the object in the given Item context. The validator influences future processing by adding item metadata to the Item.
      Specified by:
      doValidate in class AbstractX509Validator
      Parameters:
      cert - the certificate to be validated
      item - the Item context for the validation
      callerId - a String identifying the caller