public static final class ConnectionRequest.SSLCertificate
- Object
- ConnectionRequest.SSLCertificate
Encapsulates an SSL certificate fingerprint.
SSL Pinning
The recommended approach to SSL Pinning is to override the #checkSSLCertificates(com.codename1.io.ConnectionRequest.SSLCertificate[])
method in your ConnectionRequest object, and check the certificates that are provided
as a parameter. This callback if fired before sending data to the server, but after
the SSL handshake is complete so that you have an opportunity to kill the request before sending
your POST data.
Example:
`ConnectionRequest req = new ConnectionRequest() {
@Override
protected void checkSSLCertificates(ConnectionRequest.SSLCertificate[] certificates) {
if (!trust(certificates)) {
// Assume that you've implemented method trust(SSLCertificate[] certs)
// to tell you whether you trust some certificates.
this.kill();`
}
};
req.setCheckSSLCertificates(true);
....
}
See also
#getSSLCertificates()#canGetSSLCertificates()#isCheckSSLCertificates()#setCheckSSLCertificates(boolean)#checkSSLCertificates(com.codename1.io.ConnectionRequest.SSLCertificate[])
Constructors
public SSLCertificate() |
Methods
public String getCertificteUniqueKey() | Gets a fingerprint for the SSL certificate encoded using the algorithm specified by #getCertificteAlgorithm() |
public String getCertificteAlgorithm() | Gets the algorithm used to encode the fingerprint. |
public String getFingerprint() | Same value as getCertificteUniqueKey(), under a spelling that is not a typo. |
public String getFingerprintAlgorithm() | Same value as getCertificteAlgorithm(), under a spelling that is not a typo. |
public String getPublicKeyDigest() | A base64 digest of this certificate’s subject public key info, or null when the platform did not supply one. |
public String getPublicKeyDigestAlgorithm() | The digest algorithm behind getPublicKeyDigest(), normally SHA-256. |
public int getChainIndex() | Position in the chain the server presented; 0 is the leaf. |
public boolean isLeaf() | True for the server’s own certificate as opposed to an issuer in the chain. |
Inherited methods
Constructor details
SSLCertificate
public SSLCertificate()Method details
getCertificteUniqueKey
public String getCertificteUniqueKey()#getCertificteAlgorithm()getCertificteAlgorithm
public String getCertificteAlgorithm()Returns
getFingerprint
public String getFingerprint()getCertificteUniqueKey(), under a spelling that is not a typo.
The original name is kept because existing code calls it.getFingerprintAlgorithm
public String getFingerprintAlgorithm()getCertificteAlgorithm(), under a spelling that is not a typo.getPublicKeyDigest
public String getPublicKeyDigest()A base64 digest of this certificate’s subject public key info, or null when the platform did not supply one.
Prefer this over getFingerprint() when pinning. A whole-certificate fingerprint
changes every time the certificate is renewed, even on the same key pair, so pinning it
means an expiry can take the app offline. The public key survives renewal.
Populated only when something asked for it – an installed NetworkGuard that pins
this host. Otherwise it stays null so existing certificate handling is unaffected.
getPublicKeyDigestAlgorithm
public String getPublicKeyDigestAlgorithm()getPublicKeyDigest(), normally SHA-256.getChainIndex
public int getChainIndex()isLeaf
public boolean isLeaf()