Class DomainLoadStoreParameter
- All Implemented Interfaces:
KeyStore.LoadStoreParameter
KeyStore
load and
store operations.
The following syntax is supported for configuration data:
domain <domainName> [<property> ...] {
keystore <keystoreName> [<property> ...] ;
...
};
...
where domainName and keystoreName are identifiers
and property is a key/value pairing. The key and value are
separated by an 'equals' symbol and the value is enclosed in double
quotes. A property value may be either a printable string or a binary
string of colon-separated pairs of hexadecimal digits. Multivalued
properties are represented as a comma-separated list of values,
enclosed in square brackets.
See Arrays.toString(java.lang.Object[]).
To ensure that keystore entries are uniquely identified, each
entry's alias is prefixed by its keystoreName followed
by the entry name separator and each keystoreName must be
unique within its domain. Entry name prefixes are omitted when
storing a keystore.
Properties are context-sensitive: properties that apply to all the keystores in a domain are located in the domain clause, and properties that apply only to a specific keystore are located in that keystore's clause. Unless otherwise specified, a property in a keystore clause overrides a property of the same name in the domain clause. All property names are case-insensitive. The following properties are supported:
-
keystoreType="<type>" - The keystore type.
-
keystoreURI="<url>" - The keystore location.
-
keystoreProviderName="<name>" - The name of the keystore's JCE provider.
-
keystorePasswordEnv="<environment-variable>" - The environment variable that stores a keystore password.
Alternatively, passwords may be supplied to the constructor
method in a
Map<String, ProtectionParameter>. -
entryNameSeparator="<separator>" - The separator between a keystore name prefix and an entry name. When specified, it applies to all the entries in a domain. Its default value is a space.
For example, configuration data for a simple keystore domain comprising three keystores is shown below:
domain app1 {
keystore app1-truststore
keystoreURI="file:///app1/etc/truststore.jks";
keystore system-truststore
keystoreURI="${java.home}/lib/security/cacerts";
keystore app1-keystore
keystoreType="PKCS12"
keystoreURI="file:///app1/etc/keystore.p12";
};
- Since:
- 1.8
-
Constructor Summary
ConstructorsConstructorDescriptionDomainLoadStoreParameter(URI configuration, Map<String, KeyStore.ProtectionParameter> protectionParams) Constructs aDomainLoadStoreParameterfor a keystore domain with the parameters used to protect keystore data. -
Method Summary
Modifier and TypeMethodDescriptionGets the identifier for the domain configuration data.Gets the keystore protection parameters for this domain.Gets the keystore protection parameters for keystores in this domain.Methods declared in class Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitModifier and TypeMethodDescriptionprotected Objectclone()Answers a new instance of the same class as the receiver, whose slots have been filled in with the values in the slots of the receiver.booleanCompares the argument to the receiver, and answers true if they represent the same object using a class specific comparison.protected voidfinalize()Deprecated, for removal: This API element is subject to removal in a future version.May cause performance issues, deadlocks and hangs.getClass()Answers the unique instance of java.lang.Class which represents the class of the receiver.inthashCode()Answers an integer hash code for the receiver.final voidnotify()Causes one thread which iswaiting on the receiver to be made ready to run.final voidCauses all threads which arewaiting on the receiver to be made ready to run.toString()Answers a string containing a concise, human-readable description of the receiver.final voidwait()Causes the thread which sent this message to be made not ready to run pending some change in the receiver (as indicated bynotifyornotifyAll).final voidwait(long time) Causes the thread which sent this message to be made not ready to run either pending some change in the receiver (as indicated bynotifyornotifyAll) or the expiration of the timeout.final voidwait(long time, int frac) Causes the thread which sent this message to be made not ready to run either pending some change in the receiver (as indicated bynotifyornotifyAll) or the expiration of the timeout.
-
Constructor Details
-
DomainLoadStoreParameter
public DomainLoadStoreParameter(URI configuration, Map<String, KeyStore.ProtectionParameter> protectionParams) Constructs aDomainLoadStoreParameterfor a keystore domain with the parameters used to protect keystore data.- Parameters:
configuration- identifier for the domain configuration data. The name of the target domain should be specified in thejava.net.URIfragment component when it is necessary to distinguish between several domain configurations at the same location.protectionParams- the map from keystore name to the parameter used to protect keystore data. Ajava.util.Collections.EMPTY_MAPshould be used when protection parameters are not required or when they have been specified by properties in the domain configuration data. It is cloned to prevent subsequent modification.- Throws:
NullPointerException- ifconfigurationorprotectionParamsisnull
-
-
Method Details
-
getConfiguration
Gets the identifier for the domain configuration data.- Returns:
- the identifier for the configuration data
-
getProtectionParams
Gets the keystore protection parameters for keystores in this domain.- Returns:
- an unmodifiable map of keystore names to protection parameters
-
getProtectionParameter
Gets the keystore protection parameters for this domain. Keystore domains do not support a protection parameter.- Specified by:
getProtectionParameterin interfaceKeyStore.LoadStoreParameter- Returns:
- always returns
null
-