Class CertificateBundle
java.lang.Object
org.springframework.vault.support.Certificate
org.springframework.vault.support.CertificateBundle
Value object representing a certificate bundle consisting of a private key, the
certificate and the issuer certificate. Certificate and keys can be either DER or PEM
encoded. RSA and Elliptic Curve keys and certificates can be converted to a
KeySpec respective X509Certificate object. Supports creation of
key stores that contain the key and the certificate
chain.- Author:
- Mark Paluch, Alex Bremora, Bogdan Cardos
- See Also:
-
Method Summary
Modifier and TypeMethodDescriptioncreateKeyStore(String keyAlias) Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.createKeyStore(String keyAlias, boolean includeCaChain) Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.createKeyStore(String keyAlias, boolean includeCaChain, char[] password) Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.createKeyStore(String keyAlias, boolean includeCaChain, CharSequence password) Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.createKeyStore(String keyAlias, char[] password) Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.createKeyStore(String keyAlias, CharSequence password) Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.Retrieve the private key asKeySpec.static CertificateBundleCreate aCertificateBundlegiven a private key with certificates and the serial number.static CertificateBundleof(String serialNumber, String certificate, String issuingCaCertificate, String privateKey, String privateKeyType) Create aCertificateBundlegiven a private key with certificates and the serial number.static CertificateBundleof(String serialNumber, String certificate, String issuingCaCertificate, String privateKey, String privateKeyType, Long revocationTime) Create aCertificateBundlegiven a private key with certificates and the serial number.Methods inherited from class org.springframework.vault.support.Certificate
createTrustStore, createTrustStore, getCertificate, getIssuingCaCertificate, getRevocationTime, getSerialNumber, getX509Certificate, getX509IssuerCertificate, getX509IssuerCertificates, isRevoked, of, of, of
-
Method Details
-
of
public static CertificateBundle of(String serialNumber, String certificate, String issuingCaCertificate, String privateKey) Create aCertificateBundlegiven a private key with certificates and the serial number.- Parameters:
serialNumber- must not be empty or null.certificate- must not be empty or null.issuingCaCertificate- must not be empty or null.privateKey- must not be empty or null.- Returns:
- the
CertificateBundleinstead.
-
of
public static CertificateBundle of(String serialNumber, String certificate, String issuingCaCertificate, String privateKey, @Nullable String privateKeyType) Create aCertificateBundlegiven a private key with certificates and the serial number.- Parameters:
serialNumber- must not be empty or null.certificate- must not be empty or null.issuingCaCertificate- must not be empty or null.privateKey- must not be empty or null.privateKeyType- must not be empty or null.- Returns:
- the
CertificateBundle - Since:
- 2.4
-
of
public static CertificateBundle of(String serialNumber, String certificate, String issuingCaCertificate, String privateKey, @Nullable String privateKeyType, Long revocationTime) Create aCertificateBundlegiven a private key with certificates and the serial number.- Parameters:
serialNumber- must not be empty or null.certificate- must not be empty or null.issuingCaCertificate- must not be empty or null.privateKey- must not be empty or null.privateKeyType- must not be empty or null.revocationTime- the revocation time.- Returns:
- the
CertificateBundle - Since:
- 2.4
-
getPrivateKey
- Returns:
- the private key (decrypted form, PEM or DER-encoded)
-
getPrivateKeyType
- Returns:
- the private key type, can be null.
- Since:
- 2.4
-
getRequiredPrivateKeyType
- Returns:
- the required private key type, can be null.
- Throws:
IllegalStateException- if the private key type is null- Since:
- 2.4
-
getPrivateKeySpec
Retrieve the private key asKeySpec.- Returns:
- the private
KeySpec.KeyFactorycan generate aPrivateKeyfrom thisKeySpec.
-
createKeyStore
Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.- Parameters:
keyAlias- the key alias to use.- Returns:
- the
KeyStorecontaining the private key and certificate chain.
-
createKeyStore
Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.- Parameters:
keyAlias- the key alias to use.password- the password to use.- Returns:
- the
KeyStorecontaining the private key and certificate chain. - Since:
- 2.4
-
createKeyStore
Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.- Parameters:
keyAlias- the key alias to use.password- the password to use.- Returns:
- the
KeyStorecontaining the private key and certificate chain. - Since:
- 2.4
-
createKeyStore
Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.- Parameters:
keyAlias- the key alias to use.includeCaChain- whether to include the certificate authority chain instead of just the issuer certificate.- Returns:
- the
KeyStorecontaining the private key and certificate chain. - Since:
- 2.3.3
-
createKeyStore
Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.- Parameters:
keyAlias- the key alias to use.includeCaChain- whether to include the certificate authority chain instead of just the issuer certificate.password- the password to use.- Returns:
- the
KeyStorecontaining the private key and certificate chain. - Since:
- 2.4
-
createKeyStore
Create aKeyStorefrom thisCertificateBundlecontaining the private key and certificate chain.- Parameters:
keyAlias- the key alias to use.includeCaChain- whether to include the certificate authority chain instead of just the issuer certificate.password- the password to use.- Returns:
- the
KeyStorecontaining the private key and certificate chain. - Since:
- 2.4
-