Class PolicyQualifierInfo

java.lang.Object
java.security.cert.PolicyQualifierInfo

public class PolicyQualifierInfo extends Object
An immutable policy qualifier represented by the ASN.1 PolicyQualifierInfo structure.

The ASN.1 definition is as follows:

  PolicyQualifierInfo ::= SEQUENCE {
       policyQualifierId       PolicyQualifierId,
       qualifier               ANY DEFINED BY policyQualifierId }

A certificate policies extension, if present in an X.509 version 3 certificate, contains a sequence of one or more policy information terms, each of which consists of an object identifier (OID) and optional qualifiers. In an end-entity certificate, these policy information terms indicate the policy under which the certificate has been issued and the purposes for which the certificate may be used. In a CA certificate, these policy information terms limit the set of policies for certification paths which include this certificate.

A Set of PolicyQualifierInfo objects are returned by the PolicyNode.getPolicyQualifiers method. This allows applications with specific policy requirements to process and validate each policy qualifier. Applications that need to process policy qualifiers should explicitly set the policyQualifiersRejected flag to false (by calling the PKIXParameters.setPolicyQualifiersRejected method) before validating a certification path.

Note that the PKIX certification path validation algorithm specifies that any policy qualifier in a certificate policies extension that is marked critical must be processed and validated. Otherwise, the certification path must be rejected. If the policyQualifiersRejected flag is set to false, it is up to the application to validate all policy qualifiers in this manner in order to be PKIX compliant.

Concurrent Access

All PolicyQualifierInfo objects must be immutable and thread-safe. That is, multiple threads may concurrently invoke the methods defined in this class on a single PolicyQualifierInfo object (or more than one) with no ill effects. Requiring PolicyQualifierInfo objects to be immutable and thread-safe allows them to be passed around to various pieces of code without worrying about coordinating access.

Since:
1.4
  • Constructor Summary

    Constructors
    Constructor
    Description
    PolicyQualifierInfo(byte[] encoded)
    Creates an instance of PolicyQualifierInfo from the encoded bytes.
  • Method Summary

    Modifier and Type
    Method
    Description
    final byte[]
    Returns the ASN.1 DER encoded form of this PolicyQualifierInfo.
    final byte[]
    Returns the ASN.1 DER encoded form of the qualifier field of this PolicyQualifierInfo.
    final String
    Returns the policyQualifierId field of this PolicyQualifierInfo.
    Return a printable representation of this PolicyQualifierInfo.

    Methods declared in class Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, wait, wait, wait
    Modifier and Type
    Method
    Description
    protected Object
    Answers a new instance of the same class as the receiver, whose slots have been filled in with the values in the slots of the receiver.
    boolean
    Compares the argument to the receiver, and answers true if they represent the same object using a class specific comparison.
    protected void
    Deprecated, for removal: This API element is subject to removal in a future version.
    May cause performance issues, deadlocks and hangs.
    final Class<? extends Object>
    Answers the unique instance of java.lang.Class which represents the class of the receiver.
    int
    Answers an integer hash code for the receiver.
    final void
    Causes one thread which is waiting on the receiver to be made ready to run.
    final void
    Causes all threads which are waiting on the receiver to be made ready to run.
    final void
    Causes the thread which sent this message to be made not ready to run pending some change in the receiver (as indicated by notify or notifyAll).
    final void
    wait(long time)
    Causes the thread which sent this message to be made not ready to run either pending some change in the receiver (as indicated by notify or notifyAll) or the expiration of the timeout.
    final void
    wait(long time, int frac)
    Causes the thread which sent this message to be made not ready to run either pending some change in the receiver (as indicated by notify or notifyAll) or the expiration of the timeout.
  • Constructor Details

    • PolicyQualifierInfo

      public PolicyQualifierInfo(byte[] encoded) throws IOException
      Creates an instance of PolicyQualifierInfo from the encoded bytes. The encoded byte array is copied on construction.
      Parameters:
      encoded - a byte array containing the qualifier in DER encoding
      Throws:
      IOException - thrown if the byte array does not represent a valid and parsable policy qualifier
  • Method Details

    • getPolicyQualifierId

      public final String getPolicyQualifierId()
      Returns the policyQualifierId field of this PolicyQualifierInfo. The policyQualifierId is an Object Identifier (OID) represented by a set of nonnegative integers separated by periods.
      Returns:
      the OID (never null)
    • getEncoded

      public final byte[] getEncoded()
      Returns the ASN.1 DER encoded form of this PolicyQualifierInfo.
      Returns:
      the ASN.1 DER encoded bytes (never null). Note that a copy is returned, so the data is cloned each time this method is called.
    • getPolicyQualifier

      public final byte[] getPolicyQualifier()
      Returns the ASN.1 DER encoded form of the qualifier field of this PolicyQualifierInfo.
      Returns:
      the ASN.1 DER encoded bytes of the qualifier field. Note that a copy is returned, so the data is cloned each time this method is called.
    • toString

      public String toString()
      Return a printable representation of this PolicyQualifierInfo.
      Overrides:
      toString in class Object
      Returns:
      a String describing the contents of this PolicyQualifierInfo