Spring Security Framework

org.springframework.security.providers.x509
Class X509AuthenticationProvider

java.lang.Object
  extended by org.springframework.security.providers.x509.X509AuthenticationProvider
All Implemented Interfaces:
InitializingBean, MessageSourceAware, AuthenticationProvider

Deprecated. superceded by the preauth provider. Use the X.509 authentication support in org.springframework.security.ui.preauth.x509 instead or namespace support via the <x509 /> element.

public class X509AuthenticationProvider
extends Object
implements AuthenticationProvider, InitializingBean, MessageSourceAware

Processes an X.509 authentication request.

The request will typically originate from X509ProcessingFilter).

Version:
$Id$
Author:
Luke Taylor

Field Summary
protected  MessageSourceAccessor messages
          Deprecated.  
 
Constructor Summary
X509AuthenticationProvider()
          Deprecated.  
 
Method Summary
 void afterPropertiesSet()
          Deprecated.  
 Authentication authenticate(Authentication authentication)
          Deprecated. If the supplied authentication token contains a certificate then this will be passed to the configured X509AuthoritiesPopulator to obtain the user details and authorities for the user identified by the certificate.
 void setMessageSource(MessageSource messageSource)
          Deprecated.  
 void setX509AuthoritiesPopulator(X509AuthoritiesPopulator x509AuthoritiesPopulator)
          Deprecated.  
 void setX509UserCache(X509UserCache cache)
          Deprecated.  
 boolean supports(Class authentication)
          Deprecated. Returns true if this AuthenticationProvider supports the indicated Authentication object.
 
Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
 

Field Detail

messages

protected MessageSourceAccessor messages
Deprecated. 
Constructor Detail

X509AuthenticationProvider

public X509AuthenticationProvider()
Deprecated. 
Method Detail

afterPropertiesSet

public void afterPropertiesSet()
                        throws Exception
Deprecated. 
Specified by:
afterPropertiesSet in interface InitializingBean
Throws:
Exception

authenticate

public Authentication authenticate(Authentication authentication)
                            throws AuthenticationException
Deprecated. 
If the supplied authentication token contains a certificate then this will be passed to the configured X509AuthoritiesPopulator to obtain the user details and authorities for the user identified by the certificate.

If no certificate is present (for example, if the filter is applied to an HttpRequest for which client authentication hasn't been configured in the container) then a BadCredentialsException will be raised.

Specified by:
authenticate in interface AuthenticationProvider
Parameters:
authentication - the authentication request.
Returns:
an X509AuthenticationToken containing the authorities of the principal represented by the certificate.
Throws:
AuthenticationException - if the X509AuthoritiesPopulator rejects the certficate.
BadCredentialsException - if no certificate was presented in the authentication request.

setMessageSource

public void setMessageSource(MessageSource messageSource)
Deprecated. 
Specified by:
setMessageSource in interface MessageSourceAware

setX509AuthoritiesPopulator

public void setX509AuthoritiesPopulator(X509AuthoritiesPopulator x509AuthoritiesPopulator)
Deprecated. 

setX509UserCache

public void setX509UserCache(X509UserCache cache)
Deprecated. 

supports

public boolean supports(Class authentication)
Deprecated. 
Description copied from interface: AuthenticationProvider
Returns true if this AuthenticationProvider supports the indicated Authentication object.

Returning true does not guarantee an AuthenticationProvider will be able to authenticate the presented instance of the Authentication class. It simply indicates it can support closer evaluation of it. An AuthenticationProvider can still return null from the AuthenticationProvider.authenticate(Authentication) method to indicate another AuthenticationProvider should be tried.

Selection of an AuthenticationProvider capable of performing authentication is conducted at runtime the ProviderManager.

Specified by:
supports in interface AuthenticationProvider
Parameters:
authentication - DOCUMENT ME!
Returns:
true if the implementation can more closely evaluate the Authentication class presented

Spring Security Framework

Copyright © 2004-2010 SpringSource, Inc. All Rights Reserved.