|
JavaTM 2 Platform Standard Ed. 5.0 |
|||||||||
ÀÌÀü Ŭ·¡½º ´ÙÀ½ Ŭ·¡½º | ÇÁ·¹ÀÓÀ¸·Î ÇÁ·¹ÀÓ ¾øÀÌ | |||||||||
°³¿ä: NESTED | Çʵå | constructor | ¸Þ¼µå | »ó¼¼: Çʵå | »ý¼ºÀÚ | ¸Þ¼µå |
java.lang.Objectjava.security.cert.TrustAnchor
public class TrustAnchor
Æ®·¯½ºÆ® ¿¨Ä¿, ¶Ç´Â °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â ÀÎÁõ¼ ¹ßÇà±¹ (CA)ÀÔ´Ï´Ù.
ÀÌ Å¬·¡½º´Â ¡¸°¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA¡¹¸¦ ³ªÅ¸³», X. 509 ÀÎÁõ¼
ÆÐ½ºÀÇ Å¸´ç¼ºÀ» °Ë»çÇÏ´Â Æ®·¯½ºÆ® ¿¨Ä¿·Î¼ »ç¿ëÇÕ´Ï´Ù. ¹«¾ùº¸´Ù ½Å·ÚÇÒ ¼ö ÀÖ´Â CA¿¡´Â CA
°ø°³Å°, CA
À̸§, ±×¸®°í ±× ۸¦ »ç¿ëÇØ °Ë»çµÈ ÆÐ½º¼¼Æ®¿¡ ´ëÇÑ Á¦¾àÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. ÀÌ·¯ÇÑ ÆÄ¶ó¹ÌÅÍ´Â ½Å·ÚµÈ X509Certificate
Çü½ÄÀΰ¡ °³º°ÀÇ ÆÄ¶ó¹ÌÅͷμ ÁöÁ¤µË´Ï´Ù.
º´Çà ¾×¼¼½º
¸ðµç TrustAnchor
°´Ã¼´Â
ºÒº¯À¸·Î thread¿¡ ´ëÇØ¼ ¾ÈÀüÇÏÁö ¾ÊÀ¸¸é ¾ÈµË´Ï´Ù. Áï, ÀÌ Å¬·¡½º¿¡¼ Á¤ÀÇµÈ ¸Þ¼µå´Â ¾Ç¿µÇâÀ» ÁÖ´Â ÀÏ ¾øÀÌ, º¹¼ö thread°¡ º´ÇàÇØ ´ÜÀÏ TrustAnchor
°´Ã¼ (¶Ç´Â 1°³
ÀÌ»ó)·Î È£ÃâÇÒ ¼ö ÀÖ½À´Ï´Ù
. TrustAnchor
°´Ã¼´Â ºÒº¯À¸·Î ÇÑÆí thread¿¡ ´ëÇØ¼ ¾ÈÀüÇÏÁö ¾ÊÀ¸¸é ¾È µÇ±â ¶§¹®¿¡
¾×¼¼½ºÀÇ µ¿±âÀÇ °ÆÁ¤À» ÇÏ´Â ÀÏ ¾øÀÌ, ´Ù¾çÇÑ Äڵ忡 ÀÌ °´Ã¼¸¦ °Ç³×ÁÙ ¼ö°¡ ÀÖ½À´Ï´Ù. À̰ÍÀº ÀÌ Å¬·¡½ºÀÇ ¸ðµç public Çʵå¿Í ¸Þ¼µå, ±×¸®°í ¼ºê Ŭ·¡½º¿¡¼ Ãß°¡ ¶Ç´Â ¿À¹ö¶óÀ̵å(override) µÈ public Çʵå¿Í ¸Þ¼µå¿¡ µé¾î¸ÂÀ¾´Ï´Ù.
PKIXParameters.PKIXParameters(Set)
,
PKIXBuilderParameters.PKIXBuilderParameters(Set, CertSelector)
»ý¼ºÀÚ °³¿ä | |
---|---|
TrustAnchor (String caName,
PublicKey pubKey,
byte[] nameConstraints)
½Äº°¸í°ú °ø°³Å°¶ó°íµµ¿Í µµ ½Å·ÚÇÒ ¼ö ÀÖ´Â CA°¡ °¡¸®Å°´Â TrustAnchor
ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù. |
|
TrustAnchor (X500Principal caPrincipal,
PublicKey pubKey,
byte[] nameConstraints)
X500Principal¿Í °ø°³Å°¶ó°íµµ¿Í µµ ½Å·ÚÇÒ ¼ö ÀÖ´Â CA°¡ °¡¸®Å°´Â TrustAnchor
ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù. |
|
TrustAnchor (X509Certificate trustedCert,
byte[] nameConstraints)
ÁöÁ¤ÇÑ X509Certificate ¿Í
À̸§ Á¦¾à (»ý·« °¡´É)À¸·Î TrustAnchor
ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù. |
¸Þ¼µå °³¿ä | |
---|---|
X500Principal |
getCA ()
°¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA X500Principal·Î¼ÀÇ À̸§À» ¸®ÅÏÇÕ´Ï´Ù. |
String |
getCAName ()
RFC 2253 String Çü½Ä¿¡
ÇÑ, °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA
À̸§À» ¸®ÅÏÇÕ´Ï´Ù. |
PublicKey |
getCAPublicKey ()
°¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA °ø°³Å°¸¦ ¸®ÅÏÇÕ´Ï´Ù. |
byte[] |
getNameConstraints ()
À̸§ Á¦¾àÀÇ ÆÄ¶ó¹ÌÅ͸¦ ¸®ÅÏÇÕ´Ï´Ù. |
X509Certificate |
getTrustedCert ()
°¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA ÀÎÁõ¼¸¦ ¸®ÅÏÇÕ´Ï´Ù. |
String |
toString ()
TrustAnchor ¸¦ ¼³¸íÇÏ´Â ¼½Ä ÷ºÎ ij¸¯ÅÍ ¶óÀÎÀ» ¸®ÅÏÇÕ´Ï´Ù. |
Ŭ·¡½º java.lang. Object ·ÎºÎÅÍ »ó¼ÓµÈ ¸Þ¼µå |
---|
clone,
equals,
finalize,
getClass,
hashCode,
notify,
notifyAll,
wait,
wait,
wait |
»ý¼ºÀÚ »ó¼¼ |
---|
public TrustAnchor(X509Certificate trustedCert, byte[] nameConstraints)
X509Certificate
¿Í
À̸§ Á¦¾à (»ý·« °¡´É)À¸·Î TrustAnchor
ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù. À̸§ Á¦¾àÀº X. 509 ÀÎÁõ¼
ÆÐ½ºÀÇ Å¸´ç¼ºÀ» °Ë»çÇÒ ¶§ÀÇ Á¦¾àÀ» Ãß°¡Çϱâ À§Çؼ »ç¿ëµË´Ï´Ù.
À̸§ Á¦¾àÀº ¹ÙÀÌÆ® ¹è¿·Î ÁöÁ¤µË´Ï´Ù. ÀÌ ¹ÙÀÌÆ® ¹è¿¿¡´Â RFC 2459 ·Î X. 509 ·Î Á¤Àǵǰí ÀÖ´Â NameConstraints ±¸Á¶Ã¼¿¡ ÀÖ´Â °Í °°Àº À̸§ Á¦¾àÀÇ DER encode Çü½ÄÀÌ Æ÷ÇÔµÇÁö ¾ÊÀ¸¸é ¾ÈµË´Ï´Ù. NameConstraints ±¸Á¶Ã¼ÀÇ ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
NameConstraints ::= SEQUENCE {
permittedSubtrees [0] GeneralSubtrees OPTIONAL,
excludedSubtrees [1] GeneralSubtrees OPTIONAL }
GeneralSubtrees ::= SEQUENCE SIZE (1..MAX) OF GeneralSubtree
GeneralSubtree ::= SEQUENCE {
base GeneralName,
minimum [0] BaseDistance DEFAULT 0,
maximum [1] BaseDistance OPTIONAL }
BaseDistance ::= INTEGER (0..MAX)
GeneralName ::= CHOICE {
otherName [0] OtherName,
rfc822Name [1] IA5String,
dNSName [2] IA5String,
x400Address [3] ORAddress,
directoryName [4] Name,
ediPartyName [5] EDIPartyName,
uniformResourceIdentifier [6] IA5String,
iPAddress [7] OCTET STRING,
registeredID [8] OBJECT IDENTIFIER}
ÀÌÈÄÀÇ º¯°æÀ¸·ÎºÎÅÍ º¸È£Çϱâ À§Çؼ Á¦°øµÇ´Â À̸§ Á¦¾àÀÇ ¹ÙÀÌÆ® ¹è¿Àº º¹Á¦µÇ°í ÀÖ½À´Ï´Ù.
trustedCert
- ½Å·ÚµÈ X509Certificate
nameConstraints
- À̸§ Á¦¾àÀ» üũÇϱâ À§Çؼ »ç¿ëµÇ´Â NameConstraints È®Àå Á¤º¸¸¦ ASN. 1 DER ·Î encode ÇÑ °ªÀ» Æ÷ÇÔÇÑ ¹ÙÀÌÆ® ¹è¿. È®Àå Á¤º¸ÀÇ °ª¸¸ÀÌ Æ÷ÇԵǾî OID ³ª À§±âÀÇ Á¤µµ¸¦ ³ªÅ¸³»´Â Ç÷¡±×´Â Æ÷ÇÔµÇÁö ¾Ê´Â´Ù. ÀÌ ÆÄ¶ó¹ÌÅ͸¦ ¹«½ÃÇÏ·Á¸é null
À»
ÁöÁ¤ÇÑ´Ù
IllegalArgumentException
- À̸§ Á¦¾àÀÌ º¹È£È ÇÒ ¼ö ¾ø´Â °æ¿ì
NullPointerException
- ÁöÁ¤ÇÑ X509Certificate
°¡ null
ÀÎ °æ¿ìpublic TrustAnchor(X500Principal caPrincipal, PublicKey pubKey, byte[] nameConstraints)
TrustAnchor
ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù. À̸§ Á¦¾àÀº »ý·« °¡´ÉÇÑ ÆÄ¶ó¹ÌÅÍ·Î X. 509 ÀÎÁõ¼
ÆÐ½ºÀÇ Å¸´ç¼ºÀ» °Ë»çÇÒ ¶§ÀÇ Á¦¾àÀ» Ãß°¡Çϱâ À§Çؼ »ç¿ëµË´Ï´Ù.
À̸§ Á¦¾àÀº ¹ÙÀÌÆ® ¹è¿·Î ÁöÁ¤µË´Ï´Ù. ÀÌ ¹ÙÀÌÆ® ¹è¿¿¡´Â RFC 2459 ·Î X. 509 ·Î Á¤Àǵǰí ÀÖ´Â NameConstraints ±¸Á¶Ã¼¿¡ ÀÖ´Â °Í °°Àº À̸§ Á¦¾àÀÇ DER encode Çü½ÄÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. NameConstraints ±¸Á¶Ã¼ÀÇ ASN. 1 ÁöÁ¤Àº, TrustAnchor(X509Certificate trustedCert, byte[] nameConstraints)
·Î ¼³¸íÇϰí ÀÖ½À´Ï´Ù.
ÀÌÈÄÀÇ º¯°æÀ¸·ÎºÎÅÍ º¸È£Çϱâ À§Çؼ ¿©±â¼ Á¦°øµÇ°í ÀÖ´Â À̸§ Á¦¾àÀÇ ¹ÙÀÌÆ® ¹è¿Àº º¹Á¦µÇ°í ÀÖ½À´Ï´Ù.
caPrincipal
- °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA
X500Principal·Î¼ÀÇ
À̸§pubKey
- °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA
°ø°³Å°nameConstraints
- À̸§ Á¦¾àÀ» üũÇϱâ À§Çؼ »ç¿ëµÇ´Â NameConstraints È®Àå Á¤º¸¸¦ ASN. 1 DER ·Î encode ÇÑ °ªÀ» Æ÷ÇÔÇÑ ¹ÙÀÌÆ® ¹è¿. È®Àå Á¤º¸ÀÇ °ª¸¸ÀÌ Æ÷ÇԵǾî OID ³ª À§±âÀÇ Á¤µµ¸¦ ³ªÅ¸³»´Â Ç÷¡±×´Â Æ÷ÇÔµÇÁö ¾Ê´Â´Ù. ÀÌ ÆÄ¶ó¹ÌÅ͸¦ ¹«½ÃÇÏ·Á¸é null
À»
ÁöÁ¤ÇÑ´Ù
NullPointerException
- ÁöÁ¤µÈ caPrincipal
ÆÄ¶ó¹ÌÅͳª pubKey
ÆÄ¶ó¹ÌÅͰ¡ null
ÀÎ °æ¿ìpublic TrustAnchor(String caName, PublicKey pubKey, byte[] nameConstraints)
TrustAnchor
ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù. À̸§ Á¦¾àÀº »ý·« °¡´ÉÇÑ ÆÄ¶ó¹ÌÅÍ·Î X. 509 ÀÎÁõ¼
ÆÐ½ºÀÇ Å¸´ç¼ºÀ» °Ë»çÇÒ ¶§ÀÇ Á¦¾àÀ» Ãß°¡Çϱâ À§Çؼ »ç¿ëµË´Ï´Ù.
À̸§ Á¦¾àÀº ¹ÙÀÌÆ® ¹è¿·Î ÁöÁ¤µË´Ï´Ù. ÀÌ ¹ÙÀÌÆ® ¹è¿¿¡´Â RFC 2459 ·Î X. 509 ·Î Á¤Àǵǰí ÀÖ´Â NameConstraints ±¸Á¶Ã¼¿¡ ÀÖ´Â °Í °°Àº À̸§ Á¦¾àÀÇ DER encode Çü½ÄÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. NameConstraints ±¸Á¶Ã¼ÀÇ ASN. 1 ÁöÁ¤Àº, TrustAnchor(X509Certificate trustedCert, byte[] nameConstraints)
·Î ¼³¸íÇϰí ÀÖ½À´Ï´Ù.
ÀÌÈÄÀÇ º¯°æÀ¸·ÎºÎÅÍ º¸È£Çϱâ À§Çؼ ¿©±â¼ Á¦°øµÇ°í ÀÖ´Â À̸§ Á¦¾àÀÇ ¹ÙÀÌÆ® ¹è¿Àº º¹Á¦µÇ°í ÀÖ½À´Ï´Ù.
caName
- RFC 2253 String
Çü½Ä¿¡
ÇÑ, °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA
X. 500 ½Äº°¸ípubKey
- °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA
°ø°³Å°nameConstraints
- À̸§ Á¦¾àÀ» üũÇϱâ À§Çؼ »ç¿ëµÇ´Â NameConstraints È®Àå Á¤º¸¸¦ ASN. 1 DER ·Î encode ÇÑ °ªÀ» Æ÷ÇÔÇÑ ¹ÙÀÌÆ® ¹è¿. È®Àå Á¤º¸ÀÇ °ª¸¸ÀÌ Æ÷ÇԵǾî OID ³ª À§±âÀÇ Á¤µµ¸¦ ³ªÅ¸³»´Â Ç÷¡±×´Â Æ÷ÇÔµÇÁö ¾Ê´Â´Ù. ÀÌ ÆÄ¶ó¹ÌÅ͸¦ ¹«½ÃÇÏ·Á¸é null
À»
ÁöÁ¤ÇÑ´Ù
IllegalArgumentException
- ÁöÁ¤ÇÑ caName
ÆÄ¶ó¹ÌÅͰ¡ °ø¹é (caName.length() == 0)
ÀÎÁö, ±× Çü½ÄÀÌ ¿Ã¹Ù¸£Áö ¾ÊÀº °æ¿ì. ȤÀº À̸§ Á¦¾àÀÌ º¹È£È ÇÒ ¼ö ¾ø´Â °æ¿ì
NullPointerException
- ÁöÁ¤µÈ caName
ÆÄ¶ó¹ÌÅͳª pubKey
ÆÄ¶ó¹ÌÅͰ¡ null
ÀÎ °æ¿ì¸Þ¼µåÀÇ »ó¼¼ |
---|
public final X509Certificate getTrustedCert()
X509Certificate
. Æ®·¯½ºÆ® ¿¨Ä¿¸¦ ½Å·ÚÇÒ ¼ö ÀÖ´Â ÀÎÁõ¼
·Î¼ ÁöÁ¤µÇ¾î ÀÖÁö ¾ÊÀº °æ¿ì´Â null
public final X500Principal getCA()
null
public final String getCAName()
String
Çü½Ä¿¡
ÇÑ, °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA
À̸§À» ¸®ÅÏÇÕ´Ï´Ù.
null
public final PublicKey getCAPublicKey()
null
public final byte[] getNameConstraints()
À̸§ Á¦¾àÀº ¹ÙÀÌÆ® ¹è¿·Î¼ ¸®Åϵ˴ϴÙ
. ÀÌ ¹ÙÀÌÆ® ¹è¿¿¡´Â RFC 2459 ·Î X. 509 ·Î Á¤Àǵǰí ÀÖ´Â NameConstraints ±¸Á¶Ã¼¿¡ ÀÖ´Â °Í °°Àº À̸§ Á¦¾àÀÇ DER encode Çü½ÄÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. NameConstraints ±¸Á¶Ã¼ÀÇ ASN. 1 ÁöÁ¤Àº, TrustAnchor(X509Certificate trustedCert, byte[] nameConstraints)
·Î ¼³¸íÇϰí ÀÖ½À´Ï´Ù.
ÀÌÈÄÀÇ º¯°æÀ¸·ÎºÎÅÍ º¸È£Çϱâ À§Çؼ ¸®ÅÏµÈ ¹ÙÀÌÆ® ¹è¿ÀÇ º¹Á¦°¡ ÀÛ¼ºµË´Ï´Ù.
null
public String toString()
TrustAnchor
¸¦ ¼³¸íÇÏ´Â ¼½Ä ÷ºÎ ij¸¯ÅÍ ¶óÀÎÀ» ¸®ÅÏÇÕ´Ï´Ù.
Object
³»ÀÇ toString
TrustAnchor
¸¦ ¼³¸íÇÏ´Â ¼½Ä ÷ºÎ ij¸¯ÅÍ ¶óÀÎ
|
JavaTM 2 Platform Standard Ed. 5.0 |
|||||||||
ÀÌÀü Ŭ·¡½º ´ÙÀ½ Ŭ·¡½º | ÇÁ·¹ÀÓÀ¸·Î ÇÁ·¹ÀÓ ¾øÀÌ | |||||||||
°³¿ä: NESTED | Çʵå | constructor | ¸Þ¼µå | »ó¼¼: Çʵå | »ý¼ºÀÚ | ¸Þ¼µå |
Copyright 2004 Sun Microsystems, Inc. All rights reserved. Use is subject to license terms . Documentation Redistribution Policy µµ ÂüÁ¶ÇϽʽÿÀ.