Class ConnectionRequest.SSLCertificate
- Enclosing class:
ConnectionRequest
Encapsulates an SSL certificate fingerprint.
SSL Pinning
The recommended approach to SSL Pinning is to override the #checkSSLCertificates(com.codename1.io.ConnectionRequest.SSLCertificate[])
method in your ConnectionRequest object, and check the certificates that are provided
as a parameter. This callback if fired before sending data to the server, but after
the SSL handshake is complete so that you have an opportunity to kill the request before sending
your POST data.
Example:
`ConnectionRequest req = new ConnectionRequest() {
@Override
protected void checkSSLCertificates(ConnectionRequest.SSLCertificate[] certificates) {
if (!trust(certificates)) {
// Assume that you've implemented method trust(SSLCertificate[] certs)
// to tell you whether you trust some certificates.
this.kill();`
}
};
req.setCheckSSLCertificates(true);
....
}
See also
-
#getSSLCertificates()
-
#canGetSSLCertificates()
-
#isCheckSSLCertificates()
-
#setCheckSSLCertificates(boolean)
-
#checkSSLCertificates(com.codename1.io.ConnectionRequest.SSLCertificate[])
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionGets the algorithm used to encode the fingerprint.Gets a fingerprint for the SSL certificate encoded using the algorithm specified by#getCertificteAlgorithm()intPosition in the chain the server presented; 0 is the leaf.Same value asgetCertificteUniqueKey(), under a spelling that is not a typo.Same value asgetCertificteAlgorithm(), under a spelling that is not a typo.A base64 digest of this certificate's subject public key info, or null when the platform did not supply one.The digest algorithm behindgetPublicKeyDigest(), normallySHA-256.booleanisLeaf()True for the server's own certificate as opposed to an issuer in the chain.
-
Constructor Details
-
SSLCertificate
public SSLCertificate()
-
-
Method Details
-
getCertificteUniqueKey
Gets a fingerprint for the SSL certificate encoded using the algorithm specified by#getCertificteAlgorithm() -
getCertificteAlgorithm
Gets the algorithm used to encode the fingerprint. Default is SHA1
Returns
The algorithm used to encode the certificate fingerprint.
-
getFingerprint
Same value asgetCertificteUniqueKey(), under a spelling that is not a typo. The original name is kept because existing code calls it. -
getFingerprintAlgorithm
Same value asgetCertificteAlgorithm(), under a spelling that is not a typo. -
getPublicKeyDigest
A base64 digest of this certificate's subject public key info, or null when the platform did not supply one.
Prefer this over
getFingerprint()when pinning. A whole-certificate fingerprint changes every time the certificate is renewed, even on the same key pair, so pinning it means an expiry can take the app offline. The public key survives renewal.Populated only when something asked for it -- an installed
NetworkGuardthat pins this host. Otherwise it stays null so existing certificate handling is unaffected. -
getPublicKeyDigestAlgorithm
The digest algorithm behindgetPublicKeyDigest(), normallySHA-256. -
getChainIndex
public int getChainIndex()Position in the chain the server presented; 0 is the leaf. Meaningful only when the platform reported per-certificate grouping, otherwise 0. -
isLeaf
public boolean isLeaf()True for the server's own certificate as opposed to an issuer in the chain.
-