|
JavaTM 2 Platform Standard Ed. 5.0 |
|||||||||
ÀÌÀü Ŭ·¡½º ´ÙÀ½ Ŭ·¡½º | ÇÁ·¹ÀÓÀ¸·Î ÇÁ·¹ÀÓ ¾øÀÌ | |||||||||
°³¿ä: NESTED | Çʵå | constructor | ¸Þ¼µå | »ó¼¼: Çʵå | »ý¼ºÀÚ | ¸Þ¼µå |
java.lang.Objectjava.security.cert.CRL
java.security.cert.X509CRL
public abstract class X509CRL
X. 509 ÀÎÁõ¼ ÀÇ Ãë¼Ò ¸®½ºÆ® (CRL)ÀÇ Ãß»ó Ŭ·¡½ºÀÔ´Ï´Ù. CRL´Â »èÁ¦µÈ ÀÎÁõ¼¸¦ ½Äº°Çϴ ŸÀÓ ½ºÅÆÇÁ ÷ºÎÀÇ ¸®½ºÆ®ÀÔ´Ï´Ù. CRL´Â ÀÎÁõ¼ ¹ßÇà±¹ (CA)¿¡ ÀÇÇØ ¼¸íµÇ¾î °ø¿ë ¸®Æ÷ÁöÅ͸®(repository)·Î ÀÚÀ¯·Ó°Ô ÀÌ¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
»èÁ¦µÈ °¢ ÀÎÁõ¼´Â CRL ¿¡¼´Â ÀÎÁõ¼ ÀÇ ½Ã¸®¾ó ¹øÈ£¿¡ ÀÇÇØ ½Äº°µË´Ï´Ù. ÀÎÁõ¼ »ç¿ë ½Ã½ºÅÛÀÌ ÀÎÁõ¼¸¦ »ç¿ëÇÒ ¶§ (¿¹¸¦ µé¾î ¸®¸ðÆ® »ç¿ëÀÚ ÀÇ µðÁöÅÐ ¼¸íÀÇ °ËÁõÀ» À§ÇØ), ½Ã½ºÅÛÀº ÀÎÁõ¼ ÀÇ ¼¸í°ú À¯È¿±â°£À» È®ÀÎÇÒ »Ó¸¸ ¾Æ´Ï¶ó, »õ·Î¿î CRL¸¦ ÃëµæÇØ, ÀÎÁõ¼ ÀÇ ½Ã¸®¾ó ¹øÈ£°¡ ±× CRL¿¡ ¾ø´Â °Íµµ È®ÀÎÇÕ´Ï´Ù. ¡¸»õ·Ó´Ù¡¹ÀÇ ¹Ì´Â ·ÎÄà Á¤Ã¥¿¡ µû¶ó¼ ´Ù¸¨´Ï´Ù¸¸, ÀϹÝÀûÀ¸·Î °¡Àå »õ·Ó°Ô ¹ßÇàµÈ CRL¸¦ ÀǹÌÇÕ´Ï´Ù. CA´Â »õ·Î¿î CRL¸¦ Á¤±âÀû (¿¹¸¦ µé¾î ¸Å½Ã, ¸ÅÀÏ, ¸ÅÁÖ)À¸·Î ¹ßÇàÇÕ´Ï´Ù. Ãë¼Ò°¡ ÀÖÀ» ¶§¸¶´Ù ¿£Æ®¸®°¡ CRL¿¡ Ãß°¡µÇ¾î ÀÎÁõ¼ ÀÇ À¯È¿±â°£ÀÌ ²÷¾îÁö¸é ¿£Æ®¸®°¡ »èÁ¦µË´Ï´Ù.
X. 509 v2 CRL Çü½ÄÀº ASN. 1 À¸·Î ´ÙÀ½°ú °°ÀÌ ±â¼úµË´Ï´Ù.
CertificateList ::= SEQUENCE { tbsCertList TBSCertList, signatureAlgorithm AlgorithmIdentifier, signature BIT STRING }
ÀÚ¼¼ÇÑ °ÍÀº, http://www.ietf.org/rfc/rfc2459.txt¿¡ ÀÖ´Â RFC 2459 ¡¸Internet X. 509 Public Key Infrastructure Certificate and CRL Profile¡¹¸¦ ÂüÁ¶ÇϽʽÿÀ.
tbsCertList
ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
TBSCertList ::= SEQUENCE { version Version OPTIONAL, -- if present, must be v2 signature AlgorithmIdentifier, issuer Name, thisUpdate ChoiceOfTime, nextUpdate ChoiceOfTime OPTIONAL, revokedCertificates SEQUENCE OF SEQUENCE { userCertificate CertificateSerialNumber, revocationDate ChoiceOfTime, crlEntryExtensions Extensions OPTIONAL -- if present, must be v2 } OPTIONAL, crlExtensions [0] EXPLICIT Extensions OPTIONAL -- if present, must be v2 }
CRL ÀνºÅϽº´Â ÀÎÁõ¼ ÆÑÅ丮¸¦ »ç¿ëÇØ »ý¼ºµË´Ï´Ù. ¾Æ·¡ÀÇ ¿¹´Â X. 509 CRL ÀνºÅϽº¸¦ »ý¼ºÇÏ´Â ¹æ¹ýÀ» ³ªÅ¸³»°í ÀÖ½À´Ï´Ù.
InputStream inStream = new FileInputStream("fileName-of-crl");
CertificateFactory cf = CertificateFactory.getInstance("X. 509");
X509CRL crl = (X509CRL) cf.generateCRL(inStream);
inStream.close();
CRL
,
CertificateFactory
,
X509Extension
»ý¼ºÀÚ °³¿ä | |
---|---|
protected |
X509CRL ()
X. 509 CRL »ý¼ºÀÚ ÀÔ´Ï´Ù. |
¸Þ¼µå °³¿ä | |
---|---|
boolean |
equals (Object other)
ÁöÁ¤µÈ °´Ã¼¿Í ÀÌ CRL°¡ µ¿ÀÏÇÑÁö ¾î¶²Áö¸¦ ÆÇÁ¤ÇÕ´Ï´Ù. |
abstract byte[] |
getEncoded ()
ÀÌ CRL ASN. 1 DER ·Î encode µÈ Çü½ÄÀ» ¸®ÅÏÇÕ´Ï´Ù. |
abstract Principal |
getIssuerDN ()
ºñÃßõ getIssuerX500Principal() ·Î ¿Å°Ü³õÀ» ¼ö ÀÖ¾ú½À´Ï´Ù. |
X500Principal |
getIssuerX500Principal ()
CRL ·ÎºÎÅÍ ¹ßÇàÀÚ (¹ßÇàÀÚÀÇ ½Äº°¸í)ÀÇ °ªÀ» X500Principal ·Î
¼ ¸®ÅÏÇÕ´Ï´Ù. |
abstract Date |
getNextUpdate ()
CRL ·ÎºÎÅÍ nextUpdate
³¯Â¥¿Í ½Ã°£¸¦ ÃëµæÇÕ´Ï´Ù. |
abstract X509CRLEntry |
getRevokedCertificate (BigInteger serialNumber)
ÁöÁ¤µÈ ÀÎÁõ¼ ÀÇ serialNumber¸¦ °¡Áö´Â CRL ¿£Æ®¸®¸¦ ÃëµæÇÕ´Ï´Ù (Á¸ÀçÇÏ´Â °æ¿ì). |
X509CRLEntry |
getRevokedCertificate (X509Certificate certificate)
ÁöÁ¤µÈ ÀÎÁõ¼¿¡ ´ëÇÑ CRL ¿£Æ®¸®¸¦ ÃëµæÇÕ´Ï´Ù (Á¸ÀçÇÏ´Â °æ¿ì). |
abstract Set <? extends X509CRLEntry > |
getRevokedCertificates ()
¸ðµç ¿£Æ®¸®¸¦ ÃëµæÇÕ´Ï´Ù. |
abstract String |
getSigAlgName ()
¼¸í ¾Ë°í¸®Áò¸íÀ» ÃëµæÇÕ´Ï´Ù. |
abstract String |
getSigAlgOID ()
CRL ·ÎºÎÅÍ ¼¸í ¾Ë°í¸®ÁòÀÇ OID ij¸¯ÅÍ ¶óÀÎÀ» ÃëµæÇÕ´Ï´Ù. |
abstract byte[] |
getSigAlgParams ()
ÀÌ CRL ¼¸í ¾Ë°í¸®ÁòÀ¸·ÎºÎÅÍ, DER ·Î encode µÈ ¼¸í ¾Ë°í¸®Áò ÆÄ¶ó¹ÌÅ͸¦ ÃëµæÇÕ´Ï´Ù. |
abstract byte[] |
getSignature ()
signature Ä¡ (¿ø½Ã½Ã±×´ÏÃĺøÆ®)¸¦ ÃëµæÇÕ´Ï´Ù. |
abstract byte[] |
getTBSCertList ()
DER ·Î encode µÈ CRL Á¤º¸ tbsCertList ¸¦ CRL ·ÎºÎÅÍ ÃëµæÇÕ´Ï´Ù. |
abstract Date |
getThisUpdate ()
CRL ·ÎºÎÅÍ thisUpdate
³¯Â¥¿Í ½Ã°£¸¦ ÃëµæÇÕ´Ï´Ù. |
abstract int |
getVersion ()
CRL ·ÎºÎÅÍ version (¹öÀü
¹øÈ£) Ä¡¸¦ ÃëµæÇÕ´Ï´Ù. |
int |
hashCode ()
encode µÈ Çü½ÄÀ¸·ÎºÎÅÍ ÀÌ CRL ÇØ½Ã Äڵ尪À» ¸®ÅÏÇÕ´Ï´Ù. |
abstract void |
verify (PublicKey key)
ÁöÁ¤µÈ °ø°³Å°¿¡ ´ëÀÀÇÏ´Â ºñ°ø°³Å°¸¦ »ç¿ëÇØ, ÀÌ CRL°¡ ¼¸íµÈ °ÍÀ» °ËÁõÇÕ´Ï´Ù. |
abstract void |
verify (PublicKey key,
String sigProvider)
ÀÌ CRL °¡ ÁöÁ¤µÈ °ø°³Å°¿¡ ´ëÀÀÇÏ´Â ºñ°ø°³Å°¸¦ »ç¿ëÇØ ¼¸íµÈ °ÍÀ» °ËÁõÇÕ´Ï´Ù. |
Ŭ·¡½º java.security.cert. CRL ·ÎºÎÅÍ »ó¼ÓµÈ ¸Þ¼µå |
---|
getType,
isRevoked,
toString |
Ŭ·¡½º java.lang. Object ·ÎºÎÅÍ »ó¼ÓµÈ ¸Þ¼µå |
---|
clone,
finalize,
getClass,
notify,
notifyAll,
wait,
wait,
wait |
ÀÎÅÍÆäÀ̽º java.security.cert. X509Extension ·ÎºÎÅÍ »ó¼ÓµÈ ¸Þ¼µå |
---|
getCriticalExtensionOIDs,
getExtensionValue,
getNonCriticalExtensionOIDs,
hasUnsupportedCriticalExtension |
»ý¼ºÀÚ »ó¼¼ |
---|
protected X509CRL()
¸Þ¼µåÀÇ »ó¼¼ |
---|
public boolean equals(Object other)
other
°´Ã¼°¡ X509CRL
ÀνºÅϽºÀÇ °æ¿ì´Â encode µÈ Çü½ÄÀÌ ²¨³»Á® ÀÌ CRL
encode µÈ Çü½ÄÀ̶ó°í ºñ±³µË´Ï´Ù.
Object
³»ÀÇ equals
other
- ÀÌ CRL¿Í
µ¿ÀÏÇÑÁö ¾î¶²Áö°¡ ÆÇÁ¤µÇ´Â °´Ã¼
Object.hashCode()
,
Hashtable
public int hashCode()
Object
³»ÀÇ hashCode
Object.equals(java.lang.Object)
,
Hashtable
public abstract byte[] getEncoded() throws CRLException
CRLException
- encode ¿¡·¯°¡ ¹ß»ýÇßÀ» °æ¿ìpublic abstract void verify(PublicKey key) throws CRLException, NoSuchAlgorithmException, InvalidKeyException, NoSuchProviderException, SignatureException
key
- °ËÁõ¿¡ »ç¿ëÇÏ´Â PublicKey
NoSuchAlgorithmException
- Áö¿ø
µÇ¾î ÀÖÁö ¾ÊÀº ¼¸í ¾Ë°í¸®ÁòÀÇ °æ¿ì
InvalidKeyException
- ¹«È¿ÀΠŰÀÇ °æ¿ì
NoSuchProviderException
- µðÆúÆ®ÀÇ ÇÁ·Î¹ÙÀÌ´õ°¡ ¾ø´Â °æ¿ì
SignatureException
- ¼¸í ¿¡·¯ÀÇ °æ¿ì
CRLException
- encode ¿¡·¯ÀÇ °æ¿ìpublic abstract void verify(PublicKey key, String sigProvider) throws CRLException, NoSuchAlgorithmException, InvalidKeyException, NoSuchProviderException, SignatureException
key
- °ËÁõ¿¡ »ç¿ëÇÏ´Â PublicKeysigProvider
- ¼¸í ÇÁ·Î¹ÙÀÌ´õÀÇ À̸§
NoSuchAlgorithmException
- Áö¿ø
µÇ¾î ÀÖÁö ¾ÊÀº ¼¸í ¾Ë°í¸®ÁòÀÇ °æ¿ì
InvalidKeyException
- ¹«È¿ÀΠŰÀÇ °æ¿ì
NoSuchProviderException
- ¹«È¿ÀÎ ÇÁ·Î¹ÙÀÌ´õÀÇ °æ¿ì
SignatureException
- ¼¸í ¿¡·¯ÀÇ °æ¿ì
CRLException
- encode ¿¡·¯ÀÇ °æ¿ìpublic abstract int getVersion()
version
(¹öÀü
¹øÈ£) Ä¡¸¦ ÃëµæÇÕ´Ï´Ù. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
version Version OPTIONAL, -- if present, must be v2Version ::= INTEGER { v1(0), v2(1), v3(2) } -- v3 does not apply to CRLs but appears for consistency -- with definition of Version for certs
public abstract Principal getIssuerDN()
issuer
¸¦ ±¸Çö °íÀ¯ÀÇ Principal °´Ã¼·Î¼ ¸®ÅÏÇÕ´Ï´Ù. À̽ļºÀÌ ÀÖ´Â Äڵ尡 ÀÌ·¯ÇÑ °´Ã¼¿¡
Á¸ÇØ¾ß ÇÏÁö´Â ¾Ê½À´Ï´Ù.
CRL ·ÎºÎÅÍ issuer
(¹ßÇàÀÚ ½Äº°¸í) Ä¡¸¦ ÃëµæÇÕ´Ï´Ù. ¹ßÇàÀÚ¸íÀº CRL
¼¸í°ú ¹ßÇàÀ» ÇàÇÑ ¿£Æ¼Æ¼¸¦ ½Äº°ÇÕ´Ï´Ù.
¹ßÇàÀÚ¸í Çʵ忡´Â X. 500 ½Äº°¸í (DN)ÀÌ Æ÷ÇԵ˴ϴÙ. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
issuer Name Name ::= CHOICE { RDNSequence } RDNSequence ::= SEQUENCE OF RelativeDistinguishedName RelativeDistinguishedName ::= SET OF AttributeValueAssertion AttributeValueAssertion ::= SEQUENCE { AttributeType, AttributeValue } AttributeType ::= OBJECT IDENTIFIER AttributeValue ::= ANY
Name
¿¡´Â ±¹¸íµîÀÇ ¼Ó¼º°ú °Å±â¿¡ ´ëÀÀÇÏ´Â US µîÀÇ °ªÀ¸·ÎºÎÅÍ µÇ´Â °èÃþÀûÀÎ À̸§À» ±â¼úÇÕ´Ï´Ù. AttributeValue
ÄÄÆÛ³ÍÆ®ÀÇ ÇüÅ´ AttributeType
¿¡ ÀÇÇØ Á¤ÇØÁý´Ï´Ù. ÀϹÝÀûÀ¸·Î´Â directoryString
ÀÔ´Ï´Ù. directoryString
Àº º¸Åë
PrintableString
, TeletexString
, UniversalString
¾î¶² °ÍÀΰ¡ÀÔ´Ï´Ù.
public X500Principal getIssuerX500Principal()
X500Principal
·Î
¼ ¸®ÅÏÇÕ´Ï´Ù.
¼ºê Ŭ·¡½º¿¡¼ ÀÌ ¸Þ¼µå¸¦ ¿À¹ö¶óÀ̵å(override) ÇÏ´Â °ÍÀ» ÃßõÇÕ´Ï´Ù.
X500Principal
public abstract Date getThisUpdate()
thisUpdate
³¯Â¥¿Í ½Ã°£¸¦ ÃëµæÇÕ´Ï´Ù. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
thisUpdate ChoiceOfTime ChoiceOfTime ::= CHOICE { utcTime UTCTime, generalTime GeneralizedTime }
thisUpdate
³¯Â¥¿Í ½Ã°£public abstract Date getNextUpdate()
nextUpdate
³¯Â¥¿Í ½Ã°£¸¦ ÃëµæÇÕ´Ï´Ù.
nextUpdate
³¯Â¥¿Í ½Ã°£. ³¯Â¥¿Í ½Ã°£°¡ ¾ø´Â °æ¿ì´Â nullpublic abstract X509CRLEntry getRevokedCertificate(BigInteger serialNumber)
serialNumber
- CRL ÀÔ·ÂÀÌ ÂüÁ¶µÇ´Â ÀÎÁõ¼
ÀÇ ½Ã¸®¾ó ¹øÈ£
X509CRLEntry
public X509CRLEntry getRevokedCertificate(X509Certificate certificate)
ÀÌ ¸Þ¼µå¸¦ »ç¿ëÇϸé, °£Á¢ CRL (CRL ¹ßÇàÀÚ ÀÌ¿ÜÀÇ ¹ßÇàÀÚ¿¡ ÀÇÇØ ¹ßÇàµÈ ¿£Æ®¸®¸¦ Æ÷ÇÔÇÑ CRL) ³»ÀÇ CRL ¿£Æ®¸®¸¦ °Ë»öÇÒ ¼ö ÀÖ½À´Ï´Ù. µðÆúÆ® ±¸ÇöÀº CRL ¹ßÇàÀÚ¿¡ ÀÇÇØ ¹ßÇàµÈ ÀÎÁõ¼ ¿£Æ®¸®¸¸À» ¸®ÅÏÇÕ´Ï´Ù. °£Á¢ CRL Áö¿ø°¡ ÇÊ¿äÇÑ ¼ºê Ŭ·¡½º´Â ÀÌ ¸Þ¼µå¸¦ ¿À¹ö¶óÀ̵å(override) ÇÒ Çʿ䰡 ÀÖ½À´Ï´Ù.
certificate
- CRL ¿£Æ®¸®ÀÇ °Ë»ö ´ë»óÀÌ µÇ´Â ÀÎÁõ¼
NullPointerException
- ÀÎÁõ¼°¡ nullÀÎ °æ¿ìpublic abstract Set <? extends X509CRLEntry > getRevokedCertificates()
X509CRLEntry
public abstract byte[] getTBSCertList() throws CRLException
tbsCertList
¸¦ CRL ·ÎºÎÅÍ ÃëµæÇÕ´Ï´Ù. ÀÌ Á¤º¸´Â ¼¸íÀ» °³º°ÀûÀ¸·Î °ËÁõÇϱâ À§Çؼ »ç¿ëµË´Ï´Ù.
CRLException
- encode ¿¡·¯°¡ ¹ß»ýÇßÀ» °æ¿ìpublic abstract byte[] getSignature()
signature
Ä¡ (¿ø½Ã½Ã±×´ÏÃĺøÆ®)¸¦ ÃëµæÇÕ´Ï´Ù. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
signature BIT STRING
public abstract String getSigAlgName()
signatureAlgorithm AlgorithmIdentifierAlgorithmIdentifier ::= SEQUENCE { algorithm OBJECT IDENTIFIER, parameters ANY DEFINED BY algorithm OPTIONAL } -- contains a value of the type -- registered for use with the -- algorithm object identifier value
¾Ë°í¸®Áò¸íÀº algorithm
OID ij¸¯ÅÍ ¶óÀÎÀ¸·ÎºÎÅÍ ÆÇÁ¤µË´Ï´Ù.
public abstract String getSigAlgOID()
°ü·ÃµÈ ASN. 1 Á¤ÀÇ¿¡ ´ëÇØ¼´Â getSigAlgName
¸¦
ÂüÁ¶ÇϽʽÿÀ.
public abstract byte[] getSigAlgParams()
AlgorithmParameters
¸¦
»ç¿ëÇØ, getSigAlgName
¿¡ ÀÇÇØ ¸®ÅϵÈ
À̸§À» »ç¿ëÇØ ÀνºÅϽº¸¦ »ý¼ºÇÕ´Ï´Ù.
°ü·ÃµÈ ASN. 1 Á¤ÀÇ¿¡ ´ëÇØ¼´Â getSigAlgName
¸¦
ÂüÁ¶ÇϽʽÿÀ.
|
JavaTM 2 Platform Standard Ed. 5.0 |
|||||||||
ÀÌÀü Ŭ·¡½º ´ÙÀ½ Ŭ·¡½º | ÇÁ·¹ÀÓÀ¸·Î ÇÁ·¹ÀÓ ¾øÀÌ | |||||||||
°³¿ä: NESTED | Çʵå | constructor | ¸Þ¼µå | »ó¼¼: Çʵå | »ý¼ºÀÚ | ¸Þ¼µå |
Copyright 2004 Sun Microsystems, Inc. All rights reserved. Use is subject to license terms . Documentation Redistribution Policy µµ ÂüÁ¶ÇϽʽÿÀ.