Class ExplicitKeySignedJWTTrustEngine
java.lang.Object
net.shibboleth.oidc.security.impl.BaseSignedJWTTrustEngine<Iterable<Credential>>
net.shibboleth.oidc.security.impl.ExplicitKeySignedJWTTrustEngine
- All Implemented Interfaces:
TrustedCredentialTrustEngine<SignedJWT>,TrustEngine<SignedJWT>
- Direct Known Subclasses:
ClientInformationJWTTrustEngine
public class ExplicitKeySignedJWTTrustEngine
extends BaseSignedJWTTrustEngine<Iterable<Credential>>
implements TrustedCredentialTrustEngine<SignedJWT>
An implementation of
SignatureTrustEngine which evaluates the validity
and trustworthiness of JWT signatures.
Processing is first performed as described in BaseSignedJWTTrustEngine. If based on this processing, it is
determined that the token does not present or does not contain a resolveable valid (and trusted) signing
key, then all trusted credentials obtained by the trusted credential resolver will be used to attempt to validate the
signature.
- Since:
- 2.2.0
-
Field Summary
FieldsModifier and TypeFieldDescriptionprivate final CredentialResolverResolver used for resolving trusted credentials.private final ExplicitKeyTrustEvaluatorThe external explicit key trust engine to use as a basis for trust in this implementation.private final org.slf4j.LoggerClass logger. -
Constructor Summary
ConstructorsConstructorDescriptionExplicitKeySignedJWTTrustEngine(CredentialResolver resolver, JOSEObjectCredentialResolver joseObjectResolver) Constructor. -
Method Summary
Modifier and TypeMethodDescriptionprotected booleandoValidate(SignedJWT signedJWT, CriteriaSet trustBasisCriteria) Validate the signed JWT using the supplied trust criteria.protected booleanevaluateTrust(Credential untrustedCredential, Iterable<Credential> trustedCredentials) Evaluate the untrusted KeyInfo-derived credential with respect to the specified trusted information.Methods inherited from class net.shibboleth.oidc.security.impl.BaseSignedJWTTrustEngine
checkParams, resolveTokenCredentials, validate, validate, verifySignatureMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface org.opensaml.security.trust.TrustEngine
validate
-
Field Details
-
log
@Nonnull private final org.slf4j.Logger logClass logger. -
credentialResolver
Resolver used for resolving trusted credentials. -
keyTrust
The external explicit key trust engine to use as a basis for trust in this implementation.
-
-
Constructor Details
-
ExplicitKeySignedJWTTrustEngine
public ExplicitKeySignedJWTTrustEngine(@Nonnull @ParameterName(name="resolver") CredentialResolver resolver, @Nonnull @ParameterName(name="JOSEObjectResolver") JOSEObjectCredentialResolver joseObjectResolver) Constructor.- Parameters:
resolver- credential resolver used to resolve trusted credentials.joseObjectResolver- resolver which resolve credentials from the headers of aJOSEObjectinstance.
-
-
Method Details
-
getCredentialResolver
- Specified by:
getCredentialResolverin interfaceTrustedCredentialTrustEngine<SignedJWT>
-
evaluateTrust
protected boolean evaluateTrust(@Nonnull Credential untrustedCredential, @Nullable Iterable<Credential> trustedCredentials) throws SecurityException Evaluate the untrusted KeyInfo-derived credential with respect to the specified trusted information.- Specified by:
evaluateTrustin classBaseSignedJWTTrustEngine<Iterable<Credential>>- Parameters:
untrustedCredential- the untrusted credential being evaluatedtrustedCredentials- the information which serves as the basis for trust evaluation- Returns:
- true if the trust can be established for the untrusted credential, otherwise false
- Throws:
SecurityException- if an error occurs during trust processing
-