Class FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step2
- Enclosing class:
FidoMetadataDownloader.FidoMetadataDownloaderBuilder
This step offers three mutually exclusive options:
- Use the default download URL and certificate hash. This is the main intended use case.
See
useDefaultTrustRoot(). - Use custom download URLs and certificate hashes. This is for future-proofing in case
the upstream trust roots change and there is no new release of this library. See
downloadTrustRoot(URL, Set)anddownloadTrustRoots(List, Set). - Use a pre-retrieved trust root certificate or set of trust anchors. It is up to you to
perform any integrity checks and caching as desired. See
useTrustRoot(X509Certificate)anduseTrustRoots(Set).
-
Method Summary
Modifier and TypeMethodDescriptiondownloadTrustRoot(@NonNull URL url, @NonNull Set<ByteArray> acceptedCertSha256) Download the trust root certificate from the given HTTPSurland verify its SHA-256 hash againstacceptedCertSha256.downloadTrustRoots(@NonNull List<URL> urls, @NonNull Set<ByteArray> acceptedCertSha256) Download the trust root certificate from the given HTTPSurland verify its SHA-256 hash againstacceptedCertSha256.Download the trust root certificate from a hard-coded URL and verify it against a hard-coded SHA-256 hash.useTrustRoot(@NonNull X509Certificate trustRootCertificate) Use the given trust root certificate.useTrustRoots(@NonNull Set<TrustAnchor> trustAnchors) Use the given set of trust anchors.
-
Method Details
-
useDefaultTrustRoot
Download the trust root certificate from a hard-coded URL and verify it against a hard-coded SHA-256 hash.This is an alias of:
downloadTrustRoot( new URL("https://secure.globalsign.com/cacert/rootr46.crt"), Collections.singletonList(ByteArray.fromHex("4fa3126d8d3a11d1c4855a4f807cbad6cf919d3a5a88b03bea2c6372d93c40c9")) )This is the current FIDO Metadata Service trust root certificate at the time of this library release.- See Also:
-
downloadTrustRoot
public FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step3 downloadTrustRoot(@NonNull @NonNull URL url, @NonNull @NonNull Set<ByteArray> acceptedCertSha256) Download the trust root certificate from the given HTTPSurland verify its SHA-256 hash againstacceptedCertSha256.The certificate will be downloaded if it does not exist in the cache, or if the cached certificate is not currently valid.
If the cert is downloaded, it is also written to the cache
FileorConsumerconfigured in thenext step.This is an alias of
downloadTrustRoots(Collections.singletonList(url), acceptedCertSha256). SeedownloadTrustRoots(List, Set).- Parameters:
url- the HTTP URL to download. It MUST use thehttps:scheme.acceptedCertSha256- a set of SHA-256 hashes to verify the downloaded certificate against. The downloaded certificate MUST match at least one of these hashes.- Throws:
IllegalArgumentException- ifurlis not a HTTPS URL.- See Also:
-
downloadTrustRoots
public FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step3 downloadTrustRoots(@NonNull @NonNull List<URL> urls, @NonNull @NonNull Set<ByteArray> acceptedCertSha256) Download the trust root certificate from the given HTTPSurland verify its SHA-256 hash againstacceptedCertSha256.The certificate will be downloaded if it does not exist in the cache, or if the cached certificate is not currently valid.
If the cert is downloaded, it is also written to the cache
FileorConsumerconfigured in thenext step.- Parameters:
urls- a non-empty list of HTTPS URLs to download. Each URL MUST use thehttps:scheme.acceptedCertSha256- a set of SHA-256 hashes to verify downloaded certificates against. Each downloaded certificate MUST match at least one of these hashes.- Throws:
IllegalArgumentException- ifurlsis empty or if any element ofurlsis not a HTTPS URL.- Since:
- 2.10.0
- See Also:
-
useTrustRoot
public FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step4 useTrustRoot(@NonNull @NonNull X509Certificate trustRootCertificate) Use the given trust root certificate. It is the caller's responsibility to perform any integrity checks and/or caching logic.This is a shortcut for
useTrustRoots(Set)withtrustRootCertificateimported into a singleton set.- Parameters:
trustRootCertificate- the certificate to use as the FIDO Metadata Service trust root.- See Also:
-
useTrustRoots
public FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step4 useTrustRoots(@NonNull @NonNull Set<TrustAnchor> trustAnchors) Use the given set of trust anchors. It is the caller's responsibility to perform any integrity checks and/or caching logic.- Parameters:
trustAnchors- the trust anchors to use as the FIDO Metadata Service trust root. The set will be copied, so subsequent modifications totrustAnchorswill not affect theFidoMetadataDownloaderinstance.- Since:
- 2.10.0
- See Also:
-