Package io.netty.pkitesting
Class RevocationServer
- java.lang.Object
-
- io.netty.pkitesting.RevocationServer
-
public final class RevocationServer extends java.lang.ObjectA simple HTTP server that serves Certificate Revocation Lists.Issuer certificates can be registered with the server, and revocations of their certificates and be published and added to the revocation lists.
The server is only intended for testing usage, and runs entirely in a single thread.
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description private static classRevocationServer.CrlInfo
-
Field Summary
Fields Modifier and Type Field Description private java.lang.StringcrlBaseAddressprivate com.sun.net.httpserver.HttpServercrlServerprivate static RevocationServerinstanceprivate java.util.concurrent.atomic.AtomicIntegerissuerCounterprivate java.util.concurrent.ConcurrentMap<java.security.cert.X509Certificate,RevocationServer.CrlInfo>issuersprivate java.util.concurrent.ConcurrentMap<java.lang.String,RevocationServer.CrlInfo>paths
-
Constructor Summary
Constructors Modifier Constructor Description privateRevocationServer()
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description private static byte[]generateCrl(RevocationServer.CrlInfo info)java.net.URIgetCrlUri(X509Bundle issuer)Get the URI of the Certificate Revocation List for the given issuer.static RevocationServergetInstance()Get the shared revocation server instance.voidregister(X509Bundle issuer)Register an issuer with the revocation server.voidregister(X509Bundle issuer, java.security.Provider provider)Register an issuer with the revocation server.voidrevoke(X509Bundle cert, java.time.Instant time)Revoke the given certificate with the given revocation time.private voidstart()
-
-
-
Field Detail
-
instance
private static volatile RevocationServer instance
-
crlServer
private final com.sun.net.httpserver.HttpServer crlServer
-
crlBaseAddress
private final java.lang.String crlBaseAddress
-
issuerCounter
private final java.util.concurrent.atomic.AtomicInteger issuerCounter
-
issuers
private final java.util.concurrent.ConcurrentMap<java.security.cert.X509Certificate,RevocationServer.CrlInfo> issuers
-
paths
private final java.util.concurrent.ConcurrentMap<java.lang.String,RevocationServer.CrlInfo> paths
-
-
Method Detail
-
getInstance
public static RevocationServer getInstance() throws java.lang.Exception
Get the shared revocation server instance. This will start the server, if it isn't already running, and bind it to a random port on the loopback address.- Returns:
- The revocation server instance.
- Throws:
java.lang.Exception- If the server failed to start.
-
start
private void start()
-
register
public void register(X509Bundle issuer)
Register an issuer with the revocation server. This must be done before CRLs can be served for that issuer, and before any of its certificates can be revoked.- Parameters:
issuer- The issuer to register.
-
register
public void register(X509Bundle issuer, java.security.Provider provider)
Register an issuer with the revocation server. This must be done before CRLs can be served for that issuer, and before any of its certificates can be revoked.- Parameters:
issuer- The issuer to register.provider- TheProviderto use (ornullto fallback to default)
-
revoke
public void revoke(X509Bundle cert, java.time.Instant time)
Revoke the given certificate with the given revocation time.The issuer of the given certificate must be registered before its certifiactes can be revoked.
- Parameters:
cert- The certificate to revoke.time- The time of revocation.
-
getCrlUri
public java.net.URI getCrlUri(X509Bundle issuer)
Get the URI of the Certificate Revocation List for the given issuer.- Parameters:
issuer- The issuer to get the CRL for.- Returns:
- The URI to the CRL for the given issuer,
or
nullif the issuer is not registered.
-
generateCrl
private static byte[] generateCrl(RevocationServer.CrlInfo info)
-
-