Class ConnectionRequest.SSLCertificate

java.lang.Object
com.codename1.io.ConnectionRequest.SSLCertificate
Enclosing class:
ConnectionRequest

public static final class ConnectionRequest.SSLCertificate extends Object

Encapsulates an SSL certificate fingerprint.

SSL Pinning

The recommended approach to SSL Pinning is to override the #checkSSLCertificates(com.codename1.io.ConnectionRequest.SSLCertificate[]) method in your ConnectionRequest object, and check the certificates that are provided as a parameter. This callback if fired before sending data to the server, but after the SSL handshake is complete so that you have an opportunity to kill the request before sending your POST data.

Example:

`ConnectionRequest req = new ConnectionRequest() {
@Override
    protected void checkSSLCertificates(ConnectionRequest.SSLCertificate[] certificates) {
        if (!trust(certificates)) {
            // Assume that you've implemented method trust(SSLCertificate[] certs)
            // to tell you whether you trust some certificates.
            this.kill();`
    }
};
req.setCheckSSLCertificates(true);
....
}
See also
  • #getSSLCertificates()

  • #canGetSSLCertificates()

  • #isCheckSSLCertificates()

  • #setCheckSSLCertificates(boolean)

  • #checkSSLCertificates(com.codename1.io.ConnectionRequest.SSLCertificate[])

  • Constructor Details

    • SSLCertificate

      public SSLCertificate()
  • Method Details

    • getCertificteUniqueKey

      public String getCertificteUniqueKey()
      Gets a fingerprint for the SSL certificate encoded using the algorithm specified by #getCertificteAlgorithm()
    • getCertificteAlgorithm

      public String getCertificteAlgorithm()

      Gets the algorithm used to encode the fingerprint. Default is SHA1

      Returns

      The algorithm used to encode the certificate fingerprint.

    • getFingerprint

      public String getFingerprint()
      Same value as getCertificteUniqueKey(), under a spelling that is not a typo. The original name is kept because existing code calls it.
    • getFingerprintAlgorithm

      public String getFingerprintAlgorithm()
      Same value as getCertificteAlgorithm(), under a spelling that is not a typo.
    • getPublicKeyDigest

      public String getPublicKeyDigest()

      A base64 digest of this certificate's subject public key info, or null when the platform did not supply one.

      Prefer this over getFingerprint() when pinning. A whole-certificate fingerprint changes every time the certificate is renewed, even on the same key pair, so pinning it means an expiry can take the app offline. The public key survives renewal.

      Populated only when something asked for it -- an installed NetworkGuard that pins this host. Otherwise it stays null so existing certificate handling is unaffected.

    • getPublicKeyDigestAlgorithm

      public String getPublicKeyDigestAlgorithm()
      The digest algorithm behind getPublicKeyDigest(), normally SHA-256.
    • getChainIndex

      public int getChainIndex()
      Position in the chain the server presented; 0 is the leaf. Meaningful only when the platform reported per-certificate grouping, otherwise 0.
    • isLeaf

      public boolean isLeaf()
      True for the server's own certificate as opposed to an issuer in the chain.