Class SSLContextSpi

java.lang.Object
javax.net.ssl.SSLContextSpi

public abstract class SSLContextSpi extends Object
This class defines the Service Provider Interface (SPI) for the SSLContext class.

All the abstract methods in this class must be implemented by each cryptographic service provider who wishes to supply the implementation of a particular SSL context.

Since:
1.4
See Also:
  • Constructor Summary

    Constructors
    Constructor
    Description
    Constructor for subclasses to call.
  • Method Summary

    Modifier and Type
    Method
    Description
    protected abstract SSLEngine
    Creates a new SSLEngine using this context.
    protected abstract SSLEngine
    engineCreateSSLEngine(String host, int port)
    Creates a SSLEngine using this context.
    protected abstract SSLSessionContext
    Returns a client SSLSessionContext object for this context.
    protected SSLParameters
    Returns a copy of the SSLParameters indicating the default settings for this SSL context.
    protected abstract SSLSessionContext
    Returns a server SSLSessionContext object for this context.
    protected abstract SSLServerSocketFactory
    Returns a ServerSocketFactory object for this context.
    protected abstract SSLSocketFactory
    Returns a SocketFactory object for this context.
    protected SSLParameters
    Returns a copy of the SSLParameters indicating the maximum supported settings for this SSL context.
    protected abstract void
    Initializes this context.

    Methods declared in class Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
    Modifier and Type
    Method
    Description
    protected Object
    Answers a new instance of the same class as the receiver, whose slots have been filled in with the values in the slots of the receiver.
    boolean
    Compares the argument to the receiver, and answers true if they represent the same object using a class specific comparison.
    protected void
    Deprecated, for removal: This API element is subject to removal in a future version.
    May cause performance issues, deadlocks and hangs.
    final Class<? extends Object>
    Answers the unique instance of java.lang.Class which represents the class of the receiver.
    int
    Answers an integer hash code for the receiver.
    final void
    Causes one thread which is waiting on the receiver to be made ready to run.
    final void
    Causes all threads which are waiting on the receiver to be made ready to run.
    Answers a string containing a concise, human-readable description of the receiver.
    final void
    Causes the thread which sent this message to be made not ready to run pending some change in the receiver (as indicated by notify or notifyAll).
    final void
    wait(long time)
    Causes the thread which sent this message to be made not ready to run either pending some change in the receiver (as indicated by notify or notifyAll) or the expiration of the timeout.
    final void
    wait(long time, int frac)
    Causes the thread which sent this message to be made not ready to run either pending some change in the receiver (as indicated by notify or notifyAll) or the expiration of the timeout.
  • Constructor Details

    • SSLContextSpi

      public SSLContextSpi()
      Constructor for subclasses to call.
  • Method Details

    • engineInit

      protected abstract void engineInit(KeyManager[] km, TrustManager[] tm, SecureRandom sr) throws KeyManagementException
      Initializes this context.
      Parameters:
      km - the sources of authentication keys
      tm - the sources of peer authentication trust decisions
      sr - the source of randomness
      Throws:
      KeyManagementException - if this operation fails
      See Also:
    • engineGetSocketFactory

      protected abstract SSLSocketFactory engineGetSocketFactory()
      Returns a SocketFactory object for this context.
      Returns:
      the SocketFactory object
      Throws:
      UnsupportedOperationException - if the underlying provider does not implement the operation.
      IllegalStateException - if the SSLContextImpl requires initialization and the engineInit() has not been called
      See Also:
    • engineGetServerSocketFactory

      protected abstract SSLServerSocketFactory engineGetServerSocketFactory()
      Returns a ServerSocketFactory object for this context.
      Returns:
      the ServerSocketFactory object
      Throws:
      UnsupportedOperationException - if the underlying provider does not implement the operation.
      IllegalStateException - if the SSLContextImpl requires initialization and the engineInit() has not been called
      See Also:
    • engineCreateSSLEngine

      protected abstract SSLEngine engineCreateSSLEngine()
      Creates a new SSLEngine using this context.

      Applications using this factory method are providing no hints for an internal session reuse strategy. If hints are desired, engineCreateSSLEngine(String, int) should be used instead.

      Some cipher suites (such as Kerberos) require remote hostname information, in which case this factory method should not be used.

      Implementation Note:
      It is provider-specific if the returned SSLEngine uses client or server mode by default for the (D)TLS connection. The JDK SunJSSE provider implementation uses server mode by default. However, it is recommended to always set the desired mode explicitly by calling SSLEngine.setUseClientMode() before invoking other methods of the SSLEngine.
      Returns:
      the SSLEngine Object
      Throws:
      IllegalStateException - if the SSLContextImpl requires initialization and the engineInit() has not been called
      Since:
      1.5
      See Also:
    • engineCreateSSLEngine

      protected abstract SSLEngine engineCreateSSLEngine(String host, int port)
      Creates a SSLEngine using this context.

      Applications using this factory method are providing hints for an internal session reuse strategy.

      Some cipher suites (such as Kerberos) require remote hostname information, in which case peerHost needs to be specified.

      Implementation Note:
      It is provider-specific if the returned SSLEngine uses client or server mode by default for the (D)TLS connection. The JDK SunJSSE provider implementation uses server mode by default. However, it is recommended to always set the desired mode explicitly by calling SSLEngine.setUseClientMode() before invoking other methods of the SSLEngine.
      Parameters:
      host - the non-authoritative name of the host
      port - the non-authoritative port
      Returns:
      the SSLEngine Object
      Throws:
      IllegalStateException - if the SSLContextImpl requires initialization and the engineInit() has not been called
      Since:
      1.5
      See Also:
    • engineGetServerSessionContext

      protected abstract SSLSessionContext engineGetServerSessionContext()
      Returns a server SSLSessionContext object for this context.
      Returns:
      the SSLSessionContext object
      See Also:
    • engineGetClientSessionContext

      protected abstract SSLSessionContext engineGetClientSessionContext()
      Returns a client SSLSessionContext object for this context.
      Returns:
      the SSLSessionContext object
      See Also:
    • engineGetDefaultSSLParameters

      protected SSLParameters engineGetDefaultSSLParameters()
      Returns a copy of the SSLParameters indicating the default settings for this SSL context.

      The parameters will always have the ciphersuite and protocols arrays set to non-null values.

      The default implementation obtains the parameters from an SSLSocket created by calling the SocketFactory.createSocket() method of this context's SocketFactory.

      Returns:
      a copy of the SSLParameters object with the default settings
      Throws:
      UnsupportedOperationException - if the default SSL parameters could not be obtained.
      Since:
      1.6
    • engineGetSupportedSSLParameters

      protected SSLParameters engineGetSupportedSSLParameters()
      Returns a copy of the SSLParameters indicating the maximum supported settings for this SSL context.

      The parameters will always have the ciphersuite and protocols arrays set to non-null values.

      The default implementation obtains the parameters from an SSLSocket created by calling the SocketFactory.createSocket() method of this context's SocketFactory.

      Returns:
      a copy of the SSLParameters object with the maximum supported settings
      Throws:
      UnsupportedOperationException - if the supported SSL parameters could not be obtained.
      Since:
      1.6