public class DefaultKeyStore extends KeyStoreSpi
The content of this keystore can not be load from an inputstream when the method
engineLoad(InputStream, char[]) is called.
The methods engineSetCertificateEntry(String, Certificate) and engineDeleteEntry(String) are used
to add/remove certificates to/from this keystore. The method
engineSetKeyEntry(String, byte[], Certificate[]) is used to set a private key with it associated certificate
chain. the private key must be an encrypted DER (ASN1) private key in PKCS#8 format.
| Constructor and Description |
|---|
DefaultKeyStore() |
| Modifier and Type | Method and Description |
|---|---|
Enumeration<String> |
engineAliases()
Lists all the alias names of this keystore.
|
boolean |
engineContainsAlias(String alias)
Checks if the given alias exists in this keystore.
|
void |
engineDeleteEntry(String alias)
Deletes the entry identified by the given alias from this keystore.
|
Certificate |
engineGetCertificate(String alias)
Returns the certificate associated with the given alias.
|
Certificate[] |
engineGetCertificateChain(String alias)
Returns the certificate chain associated with the given alias.
|
Key |
engineGetKey(String alias,
char[] password)
Returns the key associated with the given alias, using the given password to recover it.
|
boolean |
engineIsCertificateEntry(String alias)
Returns true if the entry identified by the given alias was created by a call to
setCertificateEntry, or
created by a call to setEntry with a TrustedCertificateEntry. |
boolean |
engineIsKeyEntry(String alias)
Returns true if the entry identified by the given alias was created by a call to
setKeyEntry, or created
by a call to setEntry with a PrivateKeyEntry or a SecretKeyEntry. |
void |
engineLoad(InputStream stream,
char[] password)
Loads the keystore from the given input stream.
|
void |
engineSetCertificateEntry(String alias,
Certificate cert)
Assigns the given certificate to the given alias.
|
void |
engineSetKeyEntry(String alias,
byte[] key,
Certificate[] chain)
Assigns the given key (that has already been protected) to the given alias.
|
void |
engineSetKeyEntry(String alias,
Key key,
char[] password,
Certificate[] chain) |
int |
engineSize()
Retrieves the number of entries in this keystore.
|
public Enumeration<String> engineAliases()
KeyStoreSpiengineAliases in class KeyStoreSpipublic boolean engineContainsAlias(String alias)
KeyStoreSpiengineContainsAlias in class KeyStoreSpialias - the alias namepublic void engineDeleteEntry(String alias) throws KeyStoreException
KeyStoreSpiengineDeleteEntry in class KeyStoreSpialias - the alias nameKeyStoreException - if the entry cannot be removed.public Certificate engineGetCertificate(String alias)
KeyStoreSpi
If the given alias name identifies an entry created by a call to setCertificateEntry, or created by a
call to setEntry with a TrustedCertificateEntry, then the trusted certificate contained in that
entry is returned.
If the given alias name identifies an entry created by a call to setKeyEntry, or created by a call to
setEntry with a PrivateKeyEntry, then the first element of the certificate chain in that entry
(if a chain exists) is returned.
engineGetCertificate in class KeyStoreSpialias - the alias namepublic Certificate[] engineGetCertificateChain(String alias)
KeyStoreSpisetKeyEntry, or by a call to setEntry with a PrivateKeyEntry.engineGetCertificateChain in class KeyStoreSpialias - the alias namepublic Key engineGetKey(String alias, char[] password) throws NoSuchAlgorithmException, UnrecoverableKeyException
KeyStoreSpisetKeyEntry, or by a call to setEntry with a
PrivateKeyEntry or SecretKeyEntry.engineGetKey in class KeyStoreSpialias - the alias namepassword - the password for recovering the keyNoSuchAlgorithmException - if the algorithm for recovering the key cannot be foundUnrecoverableKeyException - if the key cannot be recovered (e.g., the given password is wrong).public boolean engineIsCertificateEntry(String alias)
KeyStoreSpisetCertificateEntry, or
created by a call to setEntry with a TrustedCertificateEntry.engineIsCertificateEntry in class KeyStoreSpialias - the alias for the keystore entry to be checkedpublic boolean engineIsKeyEntry(String alias)
KeyStoreSpisetKeyEntry, or created
by a call to setEntry with a PrivateKeyEntry or a SecretKeyEntry.engineIsKeyEntry in class KeyStoreSpialias - the alias for the keystore entry to be checkedpublic void engineLoad(InputStream stream, char[] password) throws IOException, NoSuchAlgorithmException, CertificateException
KeyStoreSpiA password may be given to unlock the keystore (e.g. the keystore resides on a hardware token device), or to check the integrity of the keystore data. If a password is not given for integrity checking, then integrity checking is not performed.
engineLoad in class KeyStoreSpistream - the input stream from which the keystore is loaded, or nullpassword - the password used to check the integrity of the keystore, the password used to unlock the keystore, or
nullIOException - if there is an I/O or format problem with the keystore data, if a password is required but not
given, or if the given password was incorrect. If the error is due to a wrong password, the
cause of the IOException should be an
UnrecoverableKeyExceptionNoSuchAlgorithmException - if the algorithm used to check the integrity of the keystore cannot be foundCertificateException - if any of the certificates in the keystore could not be loadedpublic void engineSetCertificateEntry(String alias, Certificate cert) throws KeyStoreException
KeyStoreSpi
If the given alias identifies an existing entry created by a call to setCertificateEntry, or created by a
call to setEntry with a TrustedCertificateEntry, the trusted certificate in the existing entry is
overridden by the given certificate.
engineSetCertificateEntry in class KeyStoreSpialias - the alias namecert - the certificateKeyStoreException - if the given alias already exists and does not identify an entry containing a trusted certificate,
or this operation fails for some other reason.public void engineSetKeyEntry(String alias, byte[] key, Certificate[] chain) throws KeyStoreException
KeyStoreSpi
If the protected key is of type java.security.PrivateKey, it must be accompanied by a certificate chain
certifying the corresponding public key.
If the given alias already exists, the keystore information associated with it is overridden by the given key (and possibly certificate chain).
engineSetKeyEntry in class KeyStoreSpialias - the alias namekey - the key (in protected format) to be associated with the aliaschain - the certificate chain for the corresponding public key (only useful if the protected key is of type
java.security.PrivateKey).KeyStoreException - if this operation fails.public void engineSetKeyEntry(String alias, Key key, char[] password, Certificate[] chain) throws KeyStoreException
KeyStoreExceptionpublic int engineSize()
KeyStoreSpiengineSize in class KeyStoreSpi