Class FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step3

java.lang.Object
com.yubico.fido.metadata.FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step3
Enclosing class:
FidoMetadataDownloader.FidoMetadataDownloaderBuilder

public static class FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step3 extends Object
Step 3: Configure how to cache the trust root certificate.

This step offers two mutually exclusive options:

  1. Cache trust root certificates in a File. See useTrustRootCacheFile(File).
  2. Cache trust root certificates using a Supplier to read the cache and a Consumer to write the cache. See useTrustRootCache(Supplier, Consumer).
  • Method Details

    • useTrustRootCacheFile

      public FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step4 useTrustRootCacheFile(@NonNull @NonNull File cacheFile)
      Cache trust root certificates in the file cacheFile.

      If cacheFile exists, is a normal file and is readable, then trust root certificates will be attempted to be read from this file. The internal format of the file is opaque and subject to change without a major version release of the library.

      If reading from the cache fails, then trust root certificates will instead be downloaded and written to this file.

      The cache is invalidated whenever the configured list of trust root download URLs changes or differs in length from the number of cached certificates, or whenever any cached certificate matches none of the configured SHA-256 hashes.

    • useTrustRootCache

      public FidoMetadataDownloader.FidoMetadataDownloaderBuilder.Step4 useTrustRootCache(@NonNull @NonNull Supplier<Optional<ByteArray>> getCachedTrustRootCerts, @NonNull @NonNull Consumer<ByteArray> writeCachedTrustRootCerts)
      Cache the trust root certificate using a Supplier to read the cache, and using a Consumer to write the cache.

      If getCachedTrustRootCerts returns non-empty, then trust root certificates will be attempted to be read from the contained ByteArray. The internal format of the byte array is opaque and subject to change without a major version release of the library.

      If the supplier returns empty or reading from the contained byte array fails, then trust root certificates will be downloaded and written to writeCachedTrustRootCerts.

      The cache is invalidated whenever the configured list of trust root download URLs changes or differs in length from the number of cached certificates, or whenever any cached certificate matches none of the configured SHA-256 hashes.

      Parameters:
      getCachedTrustRootCerts - a Supplier that fetches cached trust root certificates if they exist. MUST NOT return null. The format of the returned value, if present, is opaque to the supplier.
      writeCachedTrustRootCerts - a Consumer that accepts trust root certificates in an unspecified opaque format and writes it to the cache. Its argument will never be null.