|
JavaTM 2 Platform Standard Ed. 5.0 |
|||||||||
ÀÌÀü Ŭ·¡½º ´ÙÀ½ Ŭ·¡½º | ÇÁ·¹ÀÓÀ¸·Î ÇÁ·¹ÀÓ ¾øÀÌ | |||||||||
°³¿ä: »óÀÚ | Çʵå | constructor | ¸Þ¼µå | »ó¼¼: Çʵå | »ý¼ºÀÚ | ¸Þ¼µå |
java.lang.Objectjava.security.cert.Certificate
java.security.cert.X509Certificate
public abstract class X509Certificate
X. 509 ÀÎÁõ¼ ÀÇ Ãß»ó Ŭ·¡½ºÀÔ´Ï´Ù. ÀÌ Å¬·¡½º´Â X. 509 ÀÎÁõ¼ ÀÇ ¸ðµç ¼Ó¼º¿¡ ¾×¼¼½ºÇϱâ À§ÇÑ Ç¥ÁØÀûÀÎ ¹æ¹ýÀ» Á¦°øÇÕ´Ï´Ù.
±âº»ÀûÀÎ X. 509 v3 Çü½ÄÀº 1996 ³â 6 ¿ù¿¡ ISO/IEC ¹× ANSI X9¿¡ ÀÇÇØ Ã¥Á¤µÇ¾î ¾Æ·¡¿Í °°ÀÌ ASN. 1 À¸·Î ±â¼úµË´Ï´Ù.
Certificate ::= SEQUENCE { tbsCertificate TBSCertificate, signatureAlgorithm AlgorithmIdentifier, signature BIT STRING }
ÀÌ·¯ÇÑ ÀÎÁõ¼´Â ÀÎÅͳÝÀÇ ½ÃÅ¥·¯Æ¼ ½Ã½ºÅÛÀ¸·Î ÀÎÁõµîÀÇ ±â´ÉÀ» Áö¿ø Çϱâ À§Çؼ ³Ð°Ô »ç¿ëµÇ°í ÀÖ½À´Ï´Ù. ´ëÇ¥ÀûÀÎ ¾îÇø®ÄÉÀ̼ǿ¡´Â Privacy Enhanced Mail (PEM), Transport Layer Security (SSL), ½Å·ÚÇÒ ¼ö ÀÖ´Â ¼ÒÇÁÆ®¿þ¾î ¹èÆ÷¸¦ À§ÇÑ ÄÚµå ¼¸í ¹× Secure Electronic Transactions (SET)µîÀÌ ÀÖ½À´Ï´Ù.
ÀÌ·¯ÇÑ ÀÎÁõ¼´Â ¡¸ÀÎÁõ¼ ¹ßÇà±¹ (CA)¡¹¿¡ ÀÇÇØ °ü¸® ¹× º¸ÁõµÇ°í ÀÖ½À´Ï´Ù. CA´Â µ¥ÀÌÅ͸¦ X. 509 Ç¥ÁØ Çü½ÄÀ¸·Î ÇÏ°í ³ª¼, ±× µ¥ÀÌÅÍ¿¡ µðÁöÅÐ ¼¸í ÇÏ´Â °ÍÀ¸·Î½á ÀÎÁõ¼¸¦ ÀÛ¼ºÇÏ´Â ¼ºñ½ºÀÔ´Ï´Ù. CA´Â ½Å·ÚÇÒ ¼ö ÀÖ´Â Á¦»ïÀڷμ ±â´ÉÇØ, Á÷Á¢Àº ¾È¸éÀÌ ¾ø´Â ÁÖü³¢¸®¸¦ ¼Ò°³ÇÕ´Ï´Ù. CA ÀÎÁõ¼´Â ±× CA ÀÚ½ÅÀ¸·Î ¶Ç´Â ¡¸·çÆ®¡¹CA µîÀÇ ´Ù¸¥ CA¿¡ ÀÇÇØ ¼¸íµÇ°í ÀÖ½À´Ï´Ù.
ÀÚ¼¼ÇÑ °ÍÀº, http://www.ietf.org/rfc/rfc2459.txt¿¡ ÀÖ´Â RFC 2459 ¡¸Internet X. 509 Public Key Infrastructure Certificate and CRL Profile¡¹¸¦ ÂüÁ¶ÇϽʽÿÀ.
tbsCertificate
ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
TBSCertificate ::= SEQUENCE { version [0] EXPLICIT Version DEFAULT v1, serialNumber CertificateSerialNumber, signature AlgorithmIdentifier, issuer Name, validity Validity, subject Name, subjectPublicKeyInfo SubjectPublicKeyInfo, issuerUniqueID [1] IMPLICIT UniqueIdentifier OPTIONAL, -- If present, version must be v2 or v3 subjectUniqueID [2] IMPLICIT UniqueIdentifier OPTIONAL, -- If present, version must be v2 or v3 extensions [3] EXPLICIT Extensions OPTIONAL -- If present, version must be v3 }
ÀÎÁõ¼ ÀÇ ÀνºÅϽº´Â ÀÎÁõ¼ ÆÑÅ丮¸¦ »ç¿ëÇØ »ý¼ºµË´Ï´Ù. ¾Æ·¡ÀÇ ¿¹´Â X. 509 ÀÎÁõ¼ ÀÇ ÀνºÅϽº¸¦ »ý¼ºÇÏ´Â ¹æ¹ýÀ» ³ªÅ¸³»°í ÀÖ½À´Ï´Ù.
InputStream inStream = new FileInputStream("fileName-of-cert"); CertificateFactory cf = CertificateFactory.getInstance("X. 509"); X509Certificate cert = (X509Certificate) cf.generateCertificate(inStream); inStream.close();
Certificate
,
CertificateFactory
,
X509Extension
,
Á÷·ÄÈ µÈ Çü½Ä Áßø(Nested) Ŭ·¡½º °³¿ä |
---|
Ŭ·¡½º java.security.cert. Certificate ·ÎºÎÅÍ »ó¼ÓµÈ Áßø(Nested) Ŭ·¡½º/ÀÎÅÍÆäÀ̽º |
---|
Certificate.CertificateRep |
»ý¼ºÀÚ °³¿ä | |
---|---|
protected |
X509Certificate ()
X. 509 ÀÎÁõ¼ ÀÇ »ý¼ºÀÚ ÀÔ´Ï´Ù. |
¸Þ¼µå °³¿ä | |
---|---|
abstract void |
checkValidity ()
ÀÎÁõ¼°¡ ÇöÀç À¯È¿ÇÑÁö ¾î¶²Áö¸¦ ÆÇÁ¤ÇÕ´Ï´Ù. |
abstract void |
checkValidity (Date date)
ÁöÁ¤µÈ ³¯Â¥¿Í ½Ã°£°¡ ÀÎÁõ¼ ÀÇ À¯È¿±â°£³»ÀÏÁö ¾î¶³Áö¸¦ ÆÇÁ¤ÇÕ´Ï´Ù. |
abstract int |
getBasicConstraints ()
À§±âÀÎ BasicConstraints È®Àå ±â´É (OID = 2.5. 29.19)·ÎºÎÅÍ ÀÎÁõ¼
ÀÇ Á¦¾àÀÇ ÆÐ½ºÀÇ ±æÀ̸¦ ÃëµæÇÕ´Ï´Ù. |
List <String > |
getExtendedKeyUsage ()
È®ÀåŰ »ç¿ë¹ýÀÇ È®Àå ±â´É (OID = 2.5. 29.37)¿¡ ÀÖ´Â ExtKeyUsageSyntax ÇʵåÀÇ °´Ã¼ ½Äº°ÀÚ¸¦ ³ªÅ¸³»´Â º¯°æ ºÒ°¡´ÉÇÑ String
¸®½ºÆ®¸¦ ÃëµæÇÕ´Ï´Ù. |
Collection <List <? >> |
getIssuerAlternativeNames ()
IssuerAltName È®Àå ±â´É (OID = 2.5. 29.18)À¸·ÎºÎÅÍ, ¹ßÇàÀÚÀÇ ´ëü¸íÀÇ ºÒº¯ÀÎ Ä÷º¼ÇÀ» ÃëµæÇÕ´Ï´Ù. |
abstract Principal |
getIssuerDN ()
ºñÃßõ getIssuerX500Principal() ·Î ¿Å°Ü³õÀ» ¼ö ÀÖ¾ú½À´Ï´Ù. |
abstract boolean[] |
getIssuerUniqueID ()
ÀÎÁõ¼ ·ÎºÎÅÍ issuerUniqueID °ªÀ» ÃëµæÇÕ´Ï´Ù. |
X500Principal |
getIssuerX500Principal ()
ÀÎÁõ¼ ·ÎºÎÅÍ ¹ßÇàÀÚ (¹ßÇàÀÚÀÇ ½Äº°¸í)ÀÇ °ªÀ» X500Principal ·Î
¼ ¸®ÅÏÇÕ´Ï´Ù. |
abstract boolean[] |
getKeyUsage ()
KeyUsage È®Àå ±â´É (OID = 2.5. 29.15)ÀÇ ºñÆ®¸¦ ³ªÅ¸³»´Â boolean ¹è¿À» ÃëµæÇÕ´Ï´Ù. |
abstract Date |
getNotAfter ()
ÀÎÁõ¼ ÀÇ À¯È¿±â°£À¸·ÎºÎÅÍ notAfter
³¯Â¥¿Í ½Ã°£¸¦ ÃëµæÇÕ´Ï´Ù. |
abstract Date |
getNotBefore ()
ÀÎÁõ¼ ÀÇ À¯È¿±â°£À¸·ÎºÎÅÍ notBefore
³¯Â¥¿Í ½Ã°£¸¦ ÃëµæÇÕ´Ï´Ù. |
abstract BigInteger |
getSerialNumber ()
ÀÎÁõ¼ ·ÎºÎÅÍ serialNumber °ªÀ» ÃëµæÇÕ´Ï´Ù. |
abstract String |
getSigAlgName ()
ÀÎÁõ¼ ÀÇ ¼¸í ¾Ë°í¸®Áò¸íÀ» ÃëµæÇÕ´Ï´Ù. |
abstract String |
getSigAlgOID ()
ÀÎÁõ¼ ·ÎºÎÅÍ ¼¸í ¾Ë°í¸®ÁòÀÇ OID ij¸¯ÅÍ ¶óÀÎÀ» ÃëµæÇÕ´Ï´Ù. |
abstract byte[] |
getSigAlgParams ()
ÀÌ ÀÎÁõ¼ ÀÇ ¼¸í ¾Ë°í¸®ÁòÀ¸·ÎºÎÅÍ, DER ·Î encode µÈ ¼¸í ¾Ë°í¸®Áò ÆÄ¶ó¹ÌÅ͸¦ ÃëµæÇÕ´Ï´Ù. |
abstract byte[] |
getSignature ()
ÀÎÁõ¼ ·ÎºÎÅÍ signature Ä¡ (¿ø½Ã½Ã±×´ÏÃĺøÆ®)¸¦ ÃëµæÇÕ´Ï´Ù. |
Collection <List <? >> |
getSubjectAlternativeNames ()
SubjectAltName È®Àå ±â´É (OID = 2.5. 29.17)À¸·ÎºÎÅÍ, ÇÇÀÎÁõÀÚÀÇ ´ëü¸íÀÇ ºÒº¯ÀÎ Ä÷º¼ÇÀ» ÃëµæÇÕ´Ï´Ù. |
abstract Principal |
getSubjectDN ()
ºñÃßõ getSubjectX500Principal() ·Î ¿Å°Ü³õÀ» ¼ö ÀÖ¾ú½À´Ï´Ù. |
abstract boolean[] |
getSubjectUniqueID ()
ÀÎÁõ¼ ·ÎºÎÅÍ subjectUniqueID °ªÀ» ÃëµæÇÕ´Ï´Ù. |
X500Principal |
getSubjectX500Principal ()
ÀÎÁõ¼ ·ÎºÎÅÍ ÇÇÀÎÁõÀÚ (ÇÇÀÎÁõÀÚÀÇ ½Äº°¸í)ÀÇ °ªÀ» X500Principal ·Î
¼ ¸®ÅÏÇÕ´Ï´Ù. |
abstract byte[] |
getTBSCertificate ()
ÀÌ ÀÎÁõ¼ ·ÎºÎÅÍ DER ·Î encode µÈ ÀÎÁõ Á¤º¸ tbsCertificate ¸¦ ÃëµæÇÕ´Ï´Ù. |
abstract int |
getVersion ()
ÀÎÁõ¼ ·ÎºÎÅÍ version (¹öÀü
¹øÈ£) Ä¡¸¦ ÃëµæÇÕ´Ï´Ù. |
Ŭ·¡½º java.security.cert. Certificate ·ÎºÎÅÍ »ó¼ÓµÈ ¸Þ¼µå |
---|
equals,
getEncoded,
getPublicKey,
getType,
hashCode,
toString,
verify,
verify,
writeReplace |
Ŭ·¡½º java.lang. Object ·ÎºÎÅÍ »ó¼ÓµÈ ¸Þ¼µå |
---|
clone,
finalize,
getClass,
notify,
notifyAll,
wait,
wait,
wait |
ÀÎÅÍÆäÀ̽º java.security.cert. X509Extension ·ÎºÎÅÍ »ó¼ÓµÈ ¸Þ¼µå |
---|
getCriticalExtensionOIDs,
getExtensionValue,
getNonCriticalExtensionOIDs,
hasUnsupportedCriticalExtension |
»ý¼ºÀÚ »ó¼¼ |
---|
protected X509Certificate()
¸Þ¼µåÀÇ »ó¼¼ |
---|
public abstract void checkValidity() throws CertificateExpiredException, CertificateNotYetValidException
À¯È¿±â°£Àº ÀÎÁõ¼°¡ À¯È¿ÇÑ ÃÖÃÊÀÇ ÀÏ½Ã¿Í ¸¶Áö¸· ÀϽÃÀÇ 2°³ÀÇ ÀϽÃÄ¡·ÎºÎÅÍ µË´Ï´Ù. À̰ÍÀº ASN. 1 À¸·Î ´ÙÀ½°ú °°ÀÌ Á¤Àǵ˴ϴÙ.
validity ValidityValidity ::= SEQUENCE { notBefore CertificateValidityDate, notAfter CertificateValidityDate }
CertificateValidityDate ::= CHOICE { utcTime UTCTime, generalTime GeneralizedTime }
CertificateExpiredException
- ÀÎÁõ¼
ÀÇ À¯È¿±â°£ÀÌ ²÷¾îÁ® ÀÖ´Â °æ¿ì
CertificateNotYetValidException
- ÀÎÁõ¼°¡ ¾ÆÁ÷ À¯È¿ÇÏ°Ô µÇÁö ¾ÊÀº °æ¿ìpublic abstract void checkValidity(Date date) throws CertificateExpiredException, CertificateNotYetValidException
date
- ÁöÁ¤µÈ ÀϽÿ¡ ÀÌ ÀÎÁõ¼°¡ À¯È¿ÇÑÁö ¾î¶²Áö¸¦ Á¶»çÇÏ´Â Date
CertificateExpiredException
- ÁöÁ¤µÈ date
¿¡ ÀÎÁõ¼°¡ ±âÇÑ ¸¶°¨ÀÌ µÇ¾î ÀÖ´Â °æ¿ì
CertificateNotYetValidException
- ÁöÁ¤µÈ date
¿¡ ÀÎÁõ¼°¡ ¾ÆÁ÷ À¯È¿ÇÏ°Ô µÇÁö ¾ÊÀº °æ¿ìcheckValidity()
public abstract int getVersion()
version
(¹öÀü
¹øÈ£) Ä¡¸¦ ÃëµæÇÕ´Ï´Ù. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
version [0] EXPLICIT Version DEFAULT v1Version ::= INTEGER { v1(0), v2(1), v3(2) }
public abstract BigInteger getSerialNumber()
serialNumber
°ªÀ» ÃëµæÇÕ´Ï´Ù. ½Ã¸®¾ó ¹øÈ£´Â ÀÎÁõ¼
¹ßÇà±¹¿¡ ÀÇÇØ °¢ ÀÎÁõ¼¿¡ ÇÒ´çÇÒ ¼ö ÀÖ´Â Á¤¼ö°ª
ÀÔ´Ï´Ù. ½Ã¸®¾ó ¹øÈ£´Â ÁöÁ¤µÈ CA¿¡ ÀÇÇØ ¹ßÇàµÈ °¢ ÀÎÁõ¼¿¡ ´ëÇØ¼ ÀÏÀǰ¡ ¾Æ´Ï¸é ¾ÈµË´Ï´Ù. Áï, ¹ßÇàÀÚ¸í°ú ½Ã¸®¾ó ¹øÈ£¿¡ ÀÇÇØ ÀÏÀÇÀÇ ÀÎÁõ¼°¡ ½Äº°µË´Ï´Ù. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
serialNumber CertificateSerialNumberCertificateSerialNumber ::= INTEGER
public abstract Principal getIssuerDN()
issuer
¸¦ ±¸Çö °íÀ¯ÀÇ Principal °´Ã¼·Î¼ ¸®ÅÏÇÕ´Ï´Ù. À̽ļºÀÌ ÀÖ´Â Äڵ尡 ÀÌ·¯ÇÑ °´Ã¼¿¡
Á¸ÇØ¾ß ÇÏÁö´Â ¾Ê½À´Ï´Ù.
ÀÎÁõ¼
·ÎºÎÅÍ issuer
(¹ßÇàÀÚ ½Äº°¸í) Ä¡¸¦ ÃëµæÇÕ´Ï´Ù. ¹ßÇàÀÚ¸íÀº ÀÎÁõ¼
ÀÇ ¼¸í°ú ¹ßÇàÀ» ÇàÇÑ ¿£Æ¼Æ¼¸¦ ½Äº°ÇÕ´Ï´Ù.
¹ßÇàÀÚ¸í Çʵ忡´Â X. 500 ½Äº°¸í (DN)ÀÌ Æ÷ÇԵ˴ϴÙ. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
issuer NameName ::= CHOICE { RDNSequence } RDNSequence ::= SEQUENCE OF RelativeDistinguishedName RelativeDistinguishedName ::= SET OF AttributeValueAssertion AttributeValueAssertion ::= SEQUENCE { AttributeType, AttributeValue } AttributeType ::= OBJECT IDENTIFIER AttributeValue ::= ANY
Name
¿¡´Â ±¹¸íµîÀÇ ¼Ó¼º°ú °Å±â¿¡ ´ëÀÀÇÏ´Â US µîÀÇ °ªÀ¸·ÎºÎÅÍ µÇ´Â °èÃþÀûÀÎ À̸§À» ±â¼úÇÕ´Ï´Ù. AttributeValue
ÄÄÆÛ³ÍÆ®ÀÇ ÇüÅ´ AttributeType
¿¡ ÀÇÇØ Á¤ÇØÁý´Ï´Ù. ÀϹÝÀûÀ¸·Î´Â directoryString
ÀÔ´Ï´Ù. directoryString
Àº º¸Åë
PrintableString
, TeletexString
, UniversalString
¾î¶² °ÍÀΰ¡ÀÔ´Ï´Ù.
public X500Principal getIssuerX500Principal()
X500Principal
·Î
¼ ¸®ÅÏÇÕ´Ï´Ù.
¼ºê Ŭ·¡½º¿¡¼ ÀÌ ¸Þ¼µå¸¦ ¿À¹ö¶óÀ̵å(override) ÇÏ´Â °ÍÀ» ÃßõÇÕ´Ï´Ù.
X500Principal
public abstract Principal getSubjectDN()
subject
¸¦ ±¸Çö °íÀ¯ÀÇ Principal °´Ã¼·Î¼ ¸®ÅÏÇÕ´Ï´Ù. À̽ļºÀÌ ÀÖ´Â Äڵ尡 ÀÌ·¯ÇÑ °´Ã¼¿¡
Á¸ÇØ¾ß ÇÏÁö´Â ¾Ê½À´Ï´Ù.
subject
(ÇÇÀÎÁõÀÚÀÇ ½Äº°¸í)ÀÇ °ªÀ» ÀÎÁõ¼
·ÎºÎÅÍ ÃëµæÇÕ´Ï´Ù. subject
°ªÀÌ ºñ¾îÀÖ´Â °æ¿ì, ¸®ÅϵÈ
Principal
°´Ã¼ÀÇ getName()
¸Þ¼µå´Â ºñ¾îÀִ ij¸¯ÅÍ ¶óÀÎ ("")À» ¸®ÅÏÇÕ´Ï´Ù.
ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
subject Name
Name
¹× ±× ¿ÜÀÇ °ü·ÃµÈ Á¤ÀÇ¿¡ ´ëÇØ¼´Â getIssuerDN
¸¦
ÂüÁ¶ÇϽʽÿÀ.
public X500Principal getSubjectX500Principal()
X500Principal
·Î
¼ ¸®ÅÏÇÕ´Ï´Ù. ÇÇÀÎÁõÀÚÀÇ °ªÀÌ ºñ¾îÀÖ´Â °æ¿ì, ¸®ÅϵÈ
X500Principal
°´Ã¼ÀÇ getName()
¸Þ¼µå´Â ºñ¾îÀִ ij¸¯ÅÍ ¶óÀÎ ("")À» ¸®ÅÏÇÕ´Ï´Ù.
¼ºê Ŭ·¡½º¿¡¼ ÀÌ ¸Þ¼µå¸¦ ¿À¹ö¶óÀ̵å(override) ÇÏ´Â °ÍÀ» ÃßõÇÕ´Ï´Ù.
X500Principal
public abstract Date getNotBefore()
notBefore
³¯Â¥¿Í ½Ã°£¸¦ ÃëµæÇÕ´Ï´Ù. ÇØ´çÇÏ´Â ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
validity ValidityValidity ::= SEQUENCE { notBefore CertificateValidityDate, notAfter CertificateValidityDate }
CertificateValidityDate ::= CHOICE { utcTime UTCTime, generalTime GeneralizedTime }
checkValidity()
public abstract Date getNotAfter()
notAfter
³¯Â¥¿Í ½Ã°£¸¦ ÃëµæÇÕ´Ï´Ù. ÇØ´çÇÏ´Â ASN. 1 Á¤ÀÇ¿¡ ´ëÇØ¼´Â getNotBefore
¸¦
ÂüÁ¶ÇϽʽÿÀ.
checkValidity()
public abstract byte[] getTBSCertificate() throws CertificateEncodingException
tbsCertificate
¸¦ ÃëµæÇÕ´Ï´Ù. À̰ÍÀº ¼¸íÀ» °³º°ÀûÀ¸·Î °ËÁõÇϱâ À§Çؼ »ç¿ëµË´Ï´Ù.
CertificateEncodingException
- encode ¿¡·¯°¡ ¹ß»ýÇßÀ» °æ¿ìpublic abstract byte[] getSignature()
signature
Ä¡ (¿ø½Ã½Ã±×´ÏÃĺøÆ®)¸¦ ÃëµæÇÕ´Ï´Ù. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
signature BIT STRING
public abstract String getSigAlgName()
signatureAlgorithm AlgorithmIdentifierAlgorithmIdentifier ::= SEQUENCE { algorithm OBJECT IDENTIFIER, parameters ANY DEFINED BY algorithm OPTIONAL } -- contains a value of the type -- registered for use with the -- algorithm object identifier value
¾Ë°í¸®Áò¸íÀº algorithm
OID ij¸¯ÅÍ ¶óÀÎÀ¸·ÎºÎÅÍ ÆÇÁ¤µË´Ï´Ù.
public abstract String getSigAlgOID()
°ü·ÃµÈ ASN. 1 Á¤ÀÇ¿¡ ´ëÇØ¼´Â getSigAlgName
¸¦
ÂüÁ¶ÇϽʽÿÀ.
public abstract byte[] getSigAlgParams()
AlgorithmParameters
¸¦
»ç¿ëÇØ, getSigAlgName
¿¡ ÀÇÇØ ¸®ÅϵÈ
À̸§À» »ç¿ëÇØ ÀνºÅϽº¸¦ »ý¼ºÇÕ´Ï´Ù.
°ü·ÃµÈ ASN. 1 Á¤ÀÇ¿¡ ´ëÇØ¼´Â getSigAlgName
¸¦
ÂüÁ¶ÇϽʽÿÀ.
public abstract boolean[] getIssuerUniqueID()
issuerUniqueID
°ªÀ» ÃëµæÇÕ´Ï´Ù. ¹ßÇàÀÚ °íÀ¯ÀÇ ½Äº°ÀÚ´Â ¹ßÇàÀÚ¸íÀÌ ¹Ýº¹ÇØ Àç»ç¿ëµÉ °¡´É¼º¿¡ ´ëóÇϱâ À§Çؼ
ÀÎÁõ¼¿¡ Á¤Àǵǰí ÀÖ½À´Ï´Ù. RFC 2459 ¿¡¼´Â À̸§À» Àç»ç¿ëÇÏÁö ¾Ê´Â °Í ¹× ÁذÅÇÏ´Â ÀÎÁõ¼°¡ ÀÏÀÇÀÇ ½Äº°ÀÚ¸¦ »ç¿ëÇÏÁö ¾Ê´Â °ÍÀ» Ãßõ Çϰí ÀÖ½À´Ï´Ù. ±× ÇÁ·ÎÆÄÀÏ¿¡ ÁذÅÇÏ´Â ¾îÇø®ÄÉÀ̼ÇÀº ÀÏÀÇÀÇ ½Äº°ÀÚ¸¦ ÇØ¼® ¹× ºñ±³ÇÒ ¼ö ÀÖ´Â °ÍÀÌ ÇÊ¿äÇÕ´Ï´Ù.
ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
issuerUniqueID [1] IMPLICIT UniqueIdentifier OPTIONALUniqueIdentifier ::= BIT STRING
public abstract boolean[] getSubjectUniqueID()
subjectUniqueID
°ªÀ» ÃëµæÇÕ´Ï´Ù.
ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
subjectUniqueID [2] IMPLICIT UniqueIdentifier OPTIONALUniqueIdentifier ::= BIT STRING
public abstract boolean[] getKeyUsage()
KeyUsage
È®Àå ±â´É (OID = 2.5. 29.15)ÀÇ ºñÆ®¸¦ ³ªÅ¸³»´Â boolean ¹è¿À» ÃëµæÇÕ´Ï´Ù. Ű »ç¿ë ¸ñÀûÀÇ È®Àå ±â´ÉÀº ÀÎÁõ¼
·Î ¼³Á¤µÇ¾î Àִ ŰÀÇ »ç¿ë ¸ñÀû (¿¹¸¦ µé¾î
¾ÏÈ£¿ë, ¼¸í¿ë, ÀÎÁõ¼
¼¸í¿ë)À» Á¤ÀÇÇÕ´Ï´Ù. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
KeyUsage ::= BIT STRING { digitalSignature (0), nonRepudiation (1), keyEncipherment (2), dataEncipherment (3), keyAgreement (4), keyCertSign (5), cRLSign (6), encipherOnly (7), decipherOnly (8) }RFC 2459 ¿¡¼´Â À̰ÍÀ» »ç¿ëÇÏ´Â °æ¿ì´Â À§±âÀÎ È®ÀåÀ¸·Î¼ ¸¶Å· ÇÏ´Â °ÍÀ» Ãßõ Çϰí ÀÖ½À´Ï´Ù.
public List <String > getExtendedKeyUsage() throws CertificateParsingException
ExtKeyUsageSyntax
ÇʵåÀÇ °´Ã¼ ½Äº°ÀÚ¸¦ ³ªÅ¸³»´Â º¯°æ ºÒ°¡´ÉÇÑ String
¸®½ºÆ®¸¦ ÃëµæÇÕ´Ï´Ù. À̰ÍÀº Ű »ç¿ë¹ýÀÇ È®Àå ±â´É Çʵ忡 ³ªÅ¸³ª°í ÀÖ´Â ±âº»ÀûÀÎ ¸ñÀû¿¡ °¡¼¼ÇØ, ȤÀº ±× ±âº»ÀûÀÎ ¸ñÀû ´ë½Å¿¡
°ø°³Å°°¡ »ç¿ëµÇ´Â ¸ñÀû (º¹¼ö°¡´É)À» ³ªÅ¸³À´Ï´Ù.
ExtKeyUsageSyntax ::= SEQUENCE SIZE (1..MAX) OF KeyPurposeIdŰÀÇ ¸ñÀûÀº ¿ä±¸¿¡ ¸ÂÃß¾î Á¶Á÷À¸·Î Á¤ÀÇÇÕ´Ï´Ù. ŰÀÇ ¸ñÀûÀ» ƯÁ¤ÇÏ´Â °´Ã¼ ½Äº°ÀÚ´Â IANA ¶Ç´Â ITU-T Rec. X. 660, ȤÀº ISO/IEC/ITU 9834-1¿¡ µû¶ó ÇÒ´çÇÒ ¼ö ¾øÀ¸¸é ¾ÈµË´Ï´Ù.KeyPurposeId ::= OBJECT IDENTIFIER
ÀÌ ¸Þ¼µå´Â Java 2 Platform Standard Edition
¹öÀü
1.4 ·Î Ãß°¡µÇ¾ú½À´Ï´Ù. ±âÁ¸ÀÇ ¼ºñ½º ÇÁ·Î¹ÙÀÌ´õ¿ÍÀÇ ÇÏÀ§ ȣȯ¼ºÀ» À¯ÁöÇϱâ À§Çؼ
abstract
¿¡´Â ÇÏÁö ¸øÇϰí, µðÆúÆ®ÀÇ ±¸ÇöÀ» Á¦°øÇÕ´Ï´Ù. ¼ºê Ŭ·¡½º´Â ¿Ã¹Ù¸¥ ±¸ÇöÀ¸·Î ÀÌ ¸Þ¼µå¸¦ ¿À¹ö¶óÀ̵å(override) ÇÏÁö ¾ÊÀ¸¸é ¾ÈµË´Ï´Ù.
CertificateParsingException
- È®Àå ±â´ÉÀÌ º¹È£È ÇÒ ¼ö ¾ø¾ú´ø °æ¿ìpublic abstract int getBasicConstraints()
BasicConstraints
È®Àå ±â´É (OID = 2.5. 29.19)·ÎºÎÅÍ ÀÎÁõ¼
ÀÇ Á¦¾àÀÇ ÆÐ½ºÀÇ ±æÀ̸¦ ÃëµæÇÕ´Ï´Ù.
±âº» Á¦¾à È®Àå ±â´ÉÀº ÀÎÁõ¼
ÀÇ ÇÇÀÎÁõÀÚ°¡ ÀÎÁõ¼
¹ßÇà±¹ (CA)ÀÏÁö ¾î¶³Áö ¹× ±× CA
ÀÎÁõ¼
ÆÐ½ºÀÇ ±íÀ̸¦ ½Äº°ÇÕ´Ï´Ù. pathLenConstraint
Çʵå (¾Æ·¡¿Í °°À̸¦ ÂüÁ¶)´Â cA
°¡ TRUE ·Î ¼³Á¤µÇ¾î ÀÖ´Â °æ¿ì¿¡¸¸ À¯È¿ÇÕ´Ï´Ù. ÀÌ °æ¿ì
ÀÎÁõ¼
ÆÐ½º·Î ÀÌ ÀÎÁõ¼
ÀÇ ÈÄ¿¡ °è¼ÓµÇ´Â CA ÀÎÁõ¼
ÀÇ ÃÖ´ë¼ö¸¦ ³ªÅ¸³À´Ï´Ù. °ª 0 Àº ¿£µå¿£Æ¼Æ¼ÀÇ ÀÎÁõ¼
»ÓÀÎ °ÍÀ» ³ªÅ¸³À´Ï´Ù.
RFC 2459 ¿¡¼´Â cA
°¡ TRUE (ÀÌ ÀÎÁõ¼´Â ÀÎÁõ¼
¹ßÇà±¹ÀÇ °ÍÀÌ´Ù)ÀÇ °æ¿ì´Â ÀÌ È®Àå ±â´ÉÀº Ç×»ó À§±â·Î¼ ¸¶Å· µË´Ï´Ù.
ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
BasicConstraints ::= SEQUENCE { cA BOOLEAN DEFAULT FALSE, pathLenConstraint INTEGER (0..MAX) OPTIONAL }
pathLenConstraint
°ª, ÇÇÀÎÁõÀÚ°¡ CA ·Î pathLenConstraint
ÀÌ Ç¥½ÃµÇÁö ¾Ê´Â °æ¿ì´Â ÀÎÁõ ÆÐ½ºÀÇ ±æÀÌ¿¡ Á¦ÇÑÀÌ ¾ø´Â °ÍÀÌ °¡¸®Å°±â ¶§¹®¿¡ Integer.MAX_VALUE
°¡ ¸®ÅϵȴÙpublic Collection <List <? >> getSubjectAlternativeNames() throws CertificateParsingException
SubjectAltName
È®Àå ±â´É (OID = 2.5. 29.17)À¸·ÎºÎÅÍ, ÇÇÀÎÁõÀÚÀÇ ´ëü¸íÀÇ ºÒº¯ÀÎ Ä÷º¼ÇÀ» ÃëµæÇÕ´Ï´Ù.
SubjectAltName
È®Àå ±â´ÉÀÇ ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
SubjectAltName ::= GeneralNames GeneralNames :: = SEQUENCE SIZE (1..MAX) OF GeneralName GeneralName ::= CHOICE { otherName [0] OtherName, rfc822Name [1] IA5String, dNSName [2] IA5String, x400Address [3] ORAddress, directoryName [4] Name, ediPartyName [5] EDIPartyName, uniformResourceIdentifier [6] IA5String, iPAddress [7] OCTET STRING, registeredID [8] OBJECT IDENTIFIER}
ÀÌ ÀÎÁõ¼¿¡ SubjectAltName
È®Àå ±â´ÉÀÌ Æ÷ÇÔµÇÁö ¾Ê´Â °æ¿ì´Â null
ÀÌ ¸®Åϵ˴ϴÙ
. ±×·¸Áö ¾ÊÀº °æ¿ì´Â È®Àå ±â´É¿¡ Æ÷ÇԵǴ °¢ GeneralName
¸¦ ³ªÅ¸³»´Â ¿£Æ®¸®¸¦ Æ÷ÇÔÇÑ Collection
°¡ ¸®Åϵ˴ϴÙ
. °¢ ¿£Æ®¸®´Â List
·Î
ÀÌ List
ÃÖÃÊÀÇ ¿£Æ®¸®´Â Integer
(À̸§ ŸÀÔ, 0 ~ 8), 2¹øÂ°ÀÇ ¿£Æ®¸®´Â String
³ª ¹ÙÀÌÆ® ¹è¿ (°¢°¢ÀÌ Ä³¸¯ÅÍ ¶óÀÎ Çü½Ä ¶Ç´Â ASN. 1 DER encode Çü½ÄÀÇ À̸§)ÀÌ µË´Ï´Ù.
RFC 822, DNS, URI
°¢ À̸§Àº String
·Î
¼ ¸®Åϵ˴ϴÙ
. ÀÌ ¶§, RFC 2459¿¡ Æ÷ÇԵǴ Á¦ÇÑ¿¡ µû¶ó, °¢°¢ÀÇ Å¸ÀÔÀ¸·Î ¸íÈ®ÇÏ°Ô Á¤ÀÇµÈ Ä³¸¯ÅÍ ¶óÀÎ Çü½ÄÀÌ ÀÌ¿ëµË´Ï´Ù. IPv4 ÁÖ¼Ò¸íÀº ´åÀ¸·Î 4 °³¿¡ ´Ü¶ôÁö¾îÁø Ç¥±â¹ýÀ¸·Î ¸®Åϵ˴ϴÙ
. IPv6 ÁÖ¼Ò¸íÀº ¡¸a1:a2:...:a8¡¹¶ó°í ÇÏ´Â Çü½Ä¿¡¼ ¸®Åϵ˴ϴÙ
. a1 ~ a8´Â
16 Áø¼ö Ç¥±â·Î ÁÖ¼Ò¸¦ 16 ºñÆ®¾¿À¸·Î 8 °³·Î ºÐÇÒÇϰí ÀÖ½À´Ï´Ù. OID¸íÀº ÇǸ®¾îµå·Î ´Ü¶ôÁö¾îÁø ºÎ°¡ µÇÁö ¾Ê´Â ÀÏ·ÃÀÇ Á¤¼ö·Î ³ªÅ¸³»Áö´Â String
·Î
¼ ¸®Åϵ˴ϴÙ
. µð·ºÅ丮¸í (½Äº°¸í)Àº RFC 2253 ij¸¯ÅÍ ¶óÀÎ Çü½ÄÀ¸·Î¼ ¸®Åϵ˴ϴÙ
. otherName, X. 400 ¸í, EDI »ó´ë¸í, ±× ´Ù¸¥ ŸÀÔÀÇ À̸§¿¡´Â Ç¥ÁØÀÇ Ä³¸¯ÅÍ ¶óÀÎ Çü½ÄÀº ¾ø½À´Ï´Ù. À̸§ÀÇ ASN. 1 DER encode Çü½ÄÀ» Æ÷ÇÔÇÑ ¹ÙÀÌÆ® ¹è¿·Î¼ ¸®Åϵ˴ϴÙ
.
¸®ÅϵÈ
Collection
¿¡´Â °°Àº ŸÀÔÀ¸·Î 1°³
ÀÌ»óÀÇ À̸§ÀÌ Æ÷ÇԵǾî ÀÖ´Â ÀÏÀÌ ÀÖ½À´Ï´Ù. ¶Ç, ¸®ÅϵÈ
Collection
´Â ºÒº¯À̸ç, ¹ÙÀÌÆ® ¹è¿À» Æ÷ÇÔÇÑ ¿£Æ®¸®´Â ¸ðµÎ ÀÌÈÄÀÇ º¯°æÀ¸·ÎºÎÅÍ º¸È£Çϱâ À§Çؼ º¹Á¦µÇ°í ÀÖ½À´Ï´Ù.
ÀÌ ¸Þ¼µå´Â Java 2 Platform Standard Edition
¹öÀü
1.4 ·Î Ãß°¡µÇ¾ú½À´Ï´Ù. ±âÁ¸ÀÇ ¼ºñ½º ÇÁ·Î¹ÙÀÌ´õ¿ÍÀÇ ÇÏÀ§ ȣȯ¼ºÀ» À¯ÁöÇϱâ À§Çؼ
abstract
¿¡´Â ÇÏÁö ¸øÇϰí, µðÆúÆ®ÀÇ ±¸ÇöÀ» Á¦°øÇÕ´Ï´Ù. ¼ºê Ŭ·¡½º´Â ¿Ã¹Ù¸¥ ±¸ÇöÀ¸·Î ÀÌ ¸Þ¼µå¸¦ ¿À¹ö¶óÀ̵å(override) ÇÏÁö ¾ÊÀ¸¸é ¾ÈµË´Ï´Ù.
Collection
. ¶Ç´Â null
CertificateParsingException
- È®Àå ±â´ÉÀÌ º¹È£È ÇÒ ¼ö ¾ø¾ú´ø °æ¿ìpublic Collection <List <? >> getIssuerAlternativeNames() throws CertificateParsingException
IssuerAltName
È®Àå ±â´É (OID = 2.5. 29.18)À¸·ÎºÎÅÍ, ¹ßÇàÀÚÀÇ ´ëü¸íÀÇ ºÒº¯ÀÎ Ä÷º¼ÇÀ» ÃëµæÇÕ´Ï´Ù.
IssuerAltName
È®Àå ±â´ÉÀÇ ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
IssuerAltName ::= GeneralNames
GeneralNames
ASN. 1 Á¤ÀÇ´Â getSubjectAlternativeNames
¿¡ ÀÖ½À´Ï´Ù.
ÀÌ ÀÎÁõ¼¿¡ IssuerAltName
È®Àå ±â´ÉÀÌ Æ÷ÇÔµÇÁö ¾Ê´Â °æ¿ì´Â null
ÀÌ ¸®Åϵ˴ϴÙ
. ±×·¸Áö ¾ÊÀº °æ¿ì´Â È®Àå ±â´É¿¡ Æ÷ÇԵǴ °¢ GeneralName
¸¦ ³ªÅ¸³»´Â ¿£Æ®¸®¸¦ Æ÷ÇÔÇÑ Collection
°¡ ¸®Åϵ˴ϴÙ
. °¢ ¿£Æ®¸®´Â List
·Î
ÀÌ List
ÃÖÃÊÀÇ ¿£Æ®¸®´Â Integer
(À̸§ ŸÀÔ, 0 ~ 8), 2¹øÂ°ÀÇ ¿£Æ®¸®´Â String
³ª ¹ÙÀÌÆ® ¹è¿ (°¢°¢ÀÌ Ä³¸¯ÅÍ ¶óÀÎ Çü½Ä ¶Ç´Â ASN. 1 DER encode Çü½ÄÀÇ À̸§)ÀÌ µË´Ï´Ù. °¢°¢ÀÇ À̸§ÇüÀ¸·Î »ç¿ëµÇ´Â Çü½ÄÀÇ »ó¼¼ÇÑ °Í¿¡ ´ëÇÏ¿©´Â getSubjectAlternativeNames
¸Þ¼µå¸¦ ÂüÁ¶ÇϽʽÿÀ.
¸®ÅϵÈ
Collection
¿¡´Â °°Àº ŸÀÔÀ¸·Î 1°³
ÀÌ»óÀÇ À̸§ÀÌ Æ÷ÇԵǾî ÀÖ´Â ÀÏÀÌ ÀÖ½À´Ï´Ù. ¶Ç, ¸®ÅϵÈ
Collection
´Â ºÒº¯À̸ç, ¹ÙÀÌÆ® ¹è¿À» Æ÷ÇÔÇÑ ¿£Æ®¸®´Â ¸ðµÎ ÀÌÈÄÀÇ º¯°æÀ¸·ÎºÎÅÍ º¸È£Çϱâ À§Çؼ º¹Á¦µÇ°í ÀÖ½À´Ï´Ù.
ÀÌ ¸Þ¼µå´Â Java 2 Platform Standard Edition
¹öÀü
1.4 ·Î Ãß°¡µÇ¾ú½À´Ï´Ù. ±âÁ¸ÀÇ ¼ºñ½º ÇÁ·Î¹ÙÀÌ´õ¿ÍÀÇ ÇÏÀ§ ȣȯ¼ºÀ» À¯ÁöÇϱâ À§Çؼ
abstract
¿¡´Â ÇÏÁö ¸øÇϰí, µðÆúÆ®ÀÇ ±¸ÇöÀ» Á¦°øÇÕ´Ï´Ù. ¼ºê Ŭ·¡½º´Â ¿Ã¹Ù¸¥ ±¸ÇöÀ¸·Î ÀÌ ¸Þ¼µå¸¦ ¿À¹ö¶óÀ̵å(override) ÇÏÁö ¾ÊÀ¸¸é ¾ÈµË´Ï´Ù.
Collection
. ¶Ç´Â null
CertificateParsingException
- È®Àå ±â´ÉÀÌ º¹È£È ÇÒ ¼ö ¾ø¾ú´ø °æ¿ì
|
JavaTM 2 Platform Standard Ed. 5.0 |
|||||||||
ÀÌÀü Ŭ·¡½º ´ÙÀ½ Ŭ·¡½º | ÇÁ·¹ÀÓÀ¸·Î ÇÁ·¹ÀÓ ¾øÀÌ | |||||||||
°³¿ä: »óÀÚ | Çʵå | constructor | ¸Þ¼µå | »ó¼¼: Çʵå | »ý¼ºÀÚ | ¸Þ¼µå |
Copyright 2004 Sun Microsystems, Inc. All rights reserved. Use is subject to license terms . Documentation Redistribution Policy µµ ÂüÁ¶ÇϽʽÿÀ.