Class FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step2

java.lang.Object
com.yubico.fido.metadata.FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step2
Enclosing class:
FidoMetadataDownloader.FidoMetadataDownloaderBuilder

public static class FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step2 extends Object
Step 2: Configure how to retrieve the FIDO Metadata Service trust root certificate when necessary.

This step offers three mutually exclusive options:

  1. Use the default download URL and certificate hash. This is the main intended use case. See useDefaultTrustRoot().
  2. Use custom download URLs and certificate hashes. This is for future-proofing in case the upstream trust roots change and there is no new release of this library. See downloadTrustRoot(URL, Set) and downloadTrustRoots(List, Set).
  3. Use a pre-retrieved trust root certificate or set of trust anchors. It is up to you to perform any integrity checks and caching as desired. See useTrustRoot(X509Certificate) and useTrustRoots(Set).
  • Method Details

    • useDefaultTrustRoot

      Download the trust root certificate from a hard-coded URL and verify it against a hard-coded SHA-256 hash.

      This is an alias of:

      downloadTrustRoot(
        new URL("https://secure.globalsign.com/cacert/rootr46.crt"),
        Collections.singletonList(ByteArray.fromHex("4fa3126d8d3a11d1c4855a4f807cbad6cf919d3a5a88b03bea2c6372d93c40c9"))
      )
      
      This is the current FIDO Metadata Service trust root certificate at the time of this library release.
      See Also:
    • downloadTrustRoot

      public FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step3 downloadTrustRoot(@NonNull @NonNull URL url, @NonNull @NonNull Set<ByteArray> acceptedCertSha256)
      Download the trust root certificate from the given HTTPS url and verify its SHA-256 hash against acceptedCertSha256.

      The certificate will be downloaded if it does not exist in the cache, or if the cached certificate is not currently valid.

      If the cert is downloaded, it is also written to the cache File or Consumer configured in the next step.

      This is an alias of downloadTrustRoots(Collections.singletonList(url), acceptedCertSha256). See downloadTrustRoots(List, Set).

      Parameters:
      url - the HTTP URL to download. It MUST use the https: scheme.
      acceptedCertSha256 - a set of SHA-256 hashes to verify the downloaded certificate against. The downloaded certificate MUST match at least one of these hashes.
      Throws:
      IllegalArgumentException - if url is not a HTTPS URL.
      See Also:
    • downloadTrustRoots

      public FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step3 downloadTrustRoots(@NonNull @NonNull List<URL> urls, @NonNull @NonNull Set<ByteArray> acceptedCertSha256)
      Download the trust root certificate from the given HTTPS url and verify its SHA-256 hash against acceptedCertSha256.

      The certificate will be downloaded if it does not exist in the cache, or if the cached certificate is not currently valid.

      If the cert is downloaded, it is also written to the cache File or Consumer configured in the next step.

      Parameters:
      urls - a non-empty list of HTTPS URLs to download. Each URL MUST use the https: scheme.
      acceptedCertSha256 - a set of SHA-256 hashes to verify downloaded certificates against. Each downloaded certificate MUST match at least one of these hashes.
      Throws:
      IllegalArgumentException - if urls is empty or if any element of urls is not a HTTPS URL.
      Since:
      2.10.0
      See Also:
    • useTrustRoot

      public FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step4 useTrustRoot(@NonNull @NonNull X509Certificate trustRootCertificate)
      Use the given trust root certificate. It is the caller's responsibility to perform any integrity checks and/or caching logic.

      This is a shortcut for useTrustRoots(Set) with trustRootCertificate imported into a singleton set.

      Parameters:
      trustRootCertificate - the certificate to use as the FIDO Metadata Service trust root.
      See Also:
    • useTrustRoots

      public FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step4 useTrustRoots(@NonNull @NonNull Set<TrustAnchor> trustAnchors)
      Use the given set of trust anchors. It is the caller's responsibility to perform any integrity checks and/or caching logic.
      Parameters:
      trustAnchors - the trust anchors to use as the FIDO Metadata Service trust root. The set will be copied, so subsequent modifications to trustAnchors will not affect the FidoMetadataDownloader instance.
      Since:
      2.10.0
      See Also: