Class BasicSignatureSigningParametersResolver

java.lang.Object
org.opensaml.xmlsec.impl.AbstractSecurityParametersResolver<SignatureSigningParameters>
net.shibboleth.oidc.security.jose.impl.BasicSignatureSigningParametersResolver
All Implemented Interfaces:
SignatureSigningParametersResolver, Resolver<SignatureSigningParameters,CriteriaSet>
Direct Known Subclasses:
ClientInformationSignatureSigningParametersResolver, RelyingPartySigningParametersResolver

public class BasicSignatureSigningParametersResolver extends AbstractSecurityParametersResolver<SignatureSigningParameters> implements SignatureSigningParametersResolver
Basic implementation of an SignatureSigningParametersResolver.

The following Criterion inputs are supported:

The set of effective signature algorithms is filtered against those supported by the runtime and those configured by include/exclude policy.

Since:
2.2.0
  • Field Details

    • log

      @Nonnull private final org.slf4j.Logger log
      Class logger.
    • algorithmRegistry

      @Nullable private AlgorithmRegistry algorithmRegistry
      The AlgorithmRegistry used when processing algorithm URIs.
  • Constructor Details

    • BasicSignatureSigningParametersResolver

      public BasicSignatureSigningParametersResolver()
      Constructor.
  • Method Details

    • getAlgorithmRegistry

      @Nonnull public AlgorithmRegistry getAlgorithmRegistry()
      Get the AlgorithmRegistry instance used when resolving algorithm URIs. Defaults to the registry obtained via AlgorithmSupport.getGlobalAlgorithmRegistry().
      Returns:
      the algorithm registry instance
    • setAlgorithmRegistry

      public void setAlgorithmRegistry(@Nonnull AlgorithmRegistry registry)
      Set the AlgorithmRegistry instance used when resolving algorithm URIs. Defaults to the registry obtained via AlgorithmSupport.getGlobalAlgorithmRegistry().
      Parameters:
      registry - the new algorithm registry instance
    • resolve

      @Nonnull public Iterable<SignatureSigningParameters> resolve(@Nullable CriteriaSet criteria) throws ResolverException
      Specified by:
      resolve in interface Resolver<SignatureSigningParameters,CriteriaSet>
      Throws:
      ResolverException
    • resolveSingle

      @Nullable public SignatureSigningParameters resolveSingle(@Nullable CriteriaSet criteria) throws ResolverException
      Specified by:
      resolveSingle in interface Resolver<SignatureSigningParameters,CriteriaSet>
      Throws:
      ResolverException
    • logResult

      protected void logResult(@Nonnull SignatureSigningParameters params)
      Log the resolved parameters.
      Parameters:
      params - the resolved param
    • validate

      protected boolean validate(@Nonnull SignatureSigningParameters params)
      Validate that the SignatureSigningParameters instance has all the required properties populated.
      Parameters:
      params - the parameters instance to evaluate
      Returns:
      true if parameters instance passes validation, false otherwise
    • getIncludeExcludePredicate

      @Nonnull protected Predicate<String> getIncludeExcludePredicate(@Nonnull CriteriaSet criteria)
      Get a predicate which implements the effective configured include/exclude policy.
      Parameters:
      criteria - the input criteria being evaluated
      Returns:
      include/exclude predicate instance
    • resolveAndPopulateCredentialAndSignatureAlgorithm

      protected void resolveAndPopulateCredentialAndSignatureAlgorithm(@Nonnull SignatureSigningParameters params, @Nonnull CriteriaSet criteria, @Nonnull Predicate<String> includeExcludePredicate)
      Resolve and populate the signing credential and signature method algorithm URI on the supplied parameters instance.
      Parameters:
      params - the parameters instance being populated
      criteria - the input criteria being evaluated
      includeExcludePredicate - the include/exclude predicate with which to evaluate the candidate signing method algorithm URIs
    • findCompatibleAlgorithmAndCredential

      protected void findCompatibleAlgorithmAndCredential(@Nonnull List<String> algorithms, @Nonnull List<Credential> credentials, @Nonnull SignatureSigningParameters params)
      Loop through the algorithms and find the first compatible credential. Add the compatible algorithm and credential to the signing parameters.
      Parameters:
      algorithms - the algorithms to find compatible from
      credentials - the credentials to find compatibility with
      params - the parameters to add a compatible algorithm and credential too.
    • getAlgorithmRuntimeSupportedPredicate

      @Nonnull protected Predicate<String> getAlgorithmRuntimeSupportedPredicate()
      Get a predicate which evaluates whether a cryptographic algorithm is supported by the runtime environment.
      Returns:
      the predicate
    • credentialSupportsSigningAlgorithm

      protected boolean credentialSupportsSigningAlgorithm(@Nonnull Credential credential, @Nonnull @NotEmpty String algorithm)
      Evaluate whether the specified credential is supported for use with the specified signing algorithm.

      First, the key type is checked against the algorithm family, then the algorithm and key length are checked. If the key is an EC type, the curve is also checked against the algorithm. If the key is a MAC type, check the key length matches the MAC signing algorithm used.

      Parameters:
      credential - the credential to evaluate
      algorithm - the algorithm URI to evaluate
      Returns:
      true if credential may be used with the supplied algorithm URI, false otherwise
    • getEffectiveSigningCredentials

      @Nonnull protected List<Credential> getEffectiveSigningCredentials(@Nonnull CriteriaSet criteria)
      Get the effective list of signing credentials to consider.
      Parameters:
      criteria - the input criteria being evaluated
      Returns:
      the list of credentials
    • getEffectiveSignatureAlgorithms

      @Nonnull protected List<String> getEffectiveSignatureAlgorithms(@Nonnull CriteriaSet criteria, @Nonnull Predicate<String> includeExcludePredicate)
      Get the effective list of signature algorithm URIs to consider, including application of include/exclude policy.
      Parameters:
      criteria - the input criteria being evaluated
      includeExcludePredicate - the include/exclude predicate to use
      Returns:
      the list of effective algorithm URIs