Class OpenSslServerContext
java.lang.Object
io.netty.handler.ssl.SslContext
io.netty.handler.ssl.ReferenceCountedOpenSslContext
io.netty.handler.ssl.OpenSslContext
io.netty.handler.ssl.OpenSslServerContext
- All Implemented Interfaces:
ReferenceCounted
A server-side
SslContext which uses OpenSSL's SSL/TLS implementation.
This class will use a finalizer to ensure native resources are automatically cleaned up. To avoid finalizers
and manually release the native memory see ReferenceCountedOpenSslServerContext.
-
Field Summary
Fields inherited from class ReferenceCountedOpenSslContext
ctx, VERIFY_DEPTHModifier and TypeFieldDescriptionprotected longThe OpenSSL SSL_CTX object.protected static final intFields inherited from class SslContext
defaultEndpointVerificationAlgorithmModifier and TypeFieldDescriptionprotected static final StringEndpoint verification is enabled by default from Netty 4.2 onward, but it wasn't in Netty 4.1 and earlier. -
Constructor Summary
ConstructorsConstructorDescriptionOpenSslServerContext(File certChainFile, File keyFile) Deprecated.OpenSslServerContext(File certChainFile, File keyFile, String keyPassword) Deprecated.OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, Iterable<String> ciphers, ApplicationProtocolConfig apn, long sessionCacheSize, long sessionTimeout) Deprecated.OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig apn, long sessionCacheSize, long sessionTimeout) Deprecated.OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, Iterable<String> ciphers, Iterable<String> nextProtocols, long sessionCacheSize, long sessionTimeout) Deprecated.OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, ApplicationProtocolConfig config, long sessionCacheSize, long sessionTimeout) Deprecated.OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig config, long sessionCacheSize, long sessionTimeout) Deprecated.OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, OpenSslApplicationProtocolNegotiator apn, long sessionCacheSize, long sessionTimeout) Deprecated.useSslContextBuilder}OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, OpenSslApplicationProtocolNegotiator apn, long sessionCacheSize, long sessionTimeout) Deprecated.OpenSslServerContext(File trustCertCollectionFile, TrustManagerFactory trustManagerFactory, File keyCertChainFile, File keyFile, String keyPassword, KeyManagerFactory keyManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig config, long sessionCacheSize, long sessionTimeout) Deprecated.OpenSslServerContext(File trustCertCollectionFile, TrustManagerFactory trustManagerFactory, File keyCertChainFile, File keyFile, String keyPassword, KeyManagerFactory keyManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, OpenSslApplicationProtocolNegotiator apn, long sessionCacheSize, long sessionTimeout) Deprecated. -
Method Summary
Methods inherited from class OpenSslContext
finalizeMethods inherited from class ReferenceCountedOpenSslContext
applicationProtocolNegotiator, certificates, chooseTrustManager, chooseX509KeyManager, cipherSuites, context, getBioNonApplicationBufferSize, getRejectRemoteInitiatedRenegotiation, isClient, newEngine, newEngine, newHandler, newHandler, newHandler, newHandler, refCnt, release, release, retain, retain, setBioNonApplicationBufferSize, setPrivateKeyMethod, setRejectRemoteInitiatedRenegotiation, setTicketKeys, setUseTasks, sslCtxPointer, stats, touch, touchModifier and TypeMethodDescriptionReturns the object responsible for negotiating application layer protocols for the TLS NPN/ALPN extensions.protected static X509Certificate[]certificates(byte[][] chain) protected static X509TrustManagerchooseTrustManager(TrustManager[] managers) Deprecated.This method is kept for API backwards compatibility.protected static X509KeyManagerchooseX509KeyManager(KeyManager[] kms) Returns the list of enabled cipher suites, in the order of preference.final longcontext()Deprecated.this method is considered unsafe as the returned pointer may be released later.intReturns the size of the buffer used by the BIO for non-application based writesbooleanDeprecated.final booleanisClient()Returns thetrueif and only if this context is for client-side.final SSLEnginenewEngine(ByteBufAllocator alloc) Returns a new server-sideSSLEnginewith the current configuration.final SSLEnginenewEngine(ByteBufAllocator alloc, String peerHost, int peerPort) Creates a newSSLEngineusing advisory peer information.protected final SslHandlernewHandler(ByteBufAllocator alloc, boolean startTls) Create a new SslHandler.protected SslHandlernewHandler(ByteBufAllocator alloc, boolean startTls, Executor executor) Create a new SslHandler.protected final SslHandlernewHandler(ByteBufAllocator alloc, String peerHost, int peerPort, boolean startTls) Create a new SslHandler.protected SslHandlernewHandler(ByteBufAllocator alloc, String peerHost, int peerPort, boolean startTls, Executor executor) final intrefCnt()Returns the reference count of this object.final booleanrelease()Decreases the reference count by1and deallocates this object if the reference count reaches at0.final booleanrelease(int decrement) Decreases the reference count by the specifieddecrementand deallocates this object if the reference count reaches at0.final ReferenceCountedretain()Increases the reference count by1.final ReferenceCountedretain(int increment) Increases the reference count by the specifiedincrement.voidsetBioNonApplicationBufferSize(int bioNonApplicationBufferSize) Set the size of the buffer used by the BIO for non-application based writes (e.g. handshake, renegotiation, etc...).final voidDeprecated.voidsetRejectRemoteInitiatedRenegotiation(boolean rejectRemoteInitiatedRenegotiation) Deprecated.final voidsetTicketKeys(byte[] keys) Deprecated.final voidsetUseTasks(boolean useTasks) Deprecated.final longDeprecated.this method is considered unsafe as the returned pointer may be released later.final OpenSslSessionStatsstats()Deprecated.use}invalid @link
{@link #sessionContext#stats()final ReferenceCountedtouch()Records the current access location of this object for debugging purposes.final ReferenceCountedRecords the current access location of this object with an additional arbitrary information for debugging purposes.Methods inherited from class SslContext
attributes, buildKeyManagerFactory, buildKeyStore, buildTrustManagerFactory, buildTrustManagerFactory, buildTrustManagerFactory, defaultClientProvider, defaultServerProvider, generateKeySpec, isServer, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newClientContext, newHandler, newHandler, newHandler, newHandler, newServerContext, newServerContext, newServerContext, newServerContext, newServerContext, newServerContext, newServerContext, newServerContext, newServerContext, newServerContext, nextProtocols, sessionCacheSize, sessionTimeout, toPrivateKey, toPrivateKey, toX509Certificates, toX509CertificatesModifier and TypeMethodDescriptionfinal AttributeMapReturns theAttributeMapthat belongs to thisSslContext.protected static KeyManagerFactorybuildKeyManagerFactory(X509Certificate[] certChainFile, String keyAlgorithm, PrivateKey key, String keyPassword, KeyManagerFactory kmf, String keyStore) protected static KeyStorebuildKeyStore(X509Certificate[] certChain, PrivateKey key, char[] keyPasswordChars, String keyStoreType) Generates a newKeyStore.protected static TrustManagerFactorybuildTrustManagerFactory(File certChainFile, TrustManagerFactory trustManagerFactory) Deprecated.protected static TrustManagerFactorybuildTrustManagerFactory(File certChainFile, TrustManagerFactory trustManagerFactory, String keyType) Build aTrustManagerFactoryfrom a certificate chain file.protected static TrustManagerFactorybuildTrustManagerFactory(X509Certificate[] certCollection, TrustManagerFactory trustManagerFactory, String keyStoreType) static SslProviderReturns the default client-side implementation provider currently in use.static SslProviderReturns the default server-side implementation provider currently in use.protected static PKCS8EncodedKeySpecgenerateKeySpec(char[] password, byte[] key) Deprecated.final booleanisServer()Returnstrueif and only if this context is for server-side.static SslContextDeprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(SslProvider provider) Deprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(SslProvider provider, File certChainFile) Deprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(SslProvider provider, File certChainFile, TrustManagerFactory trustManagerFactory) Deprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(SslProvider provider, File trustCertCollectionFile, TrustManagerFactory trustManagerFactory, File keyCertChainFile, File keyFile, String keyPassword, KeyManagerFactory keyManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig apn, long sessionCacheSize, long sessionTimeout) Deprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(SslProvider provider, File certChainFile, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig apn, long sessionCacheSize, long sessionTimeout) Deprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(SslProvider provider, File certChainFile, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, Iterable<String> nextProtocols, long sessionCacheSize, long sessionTimeout) Deprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(SslProvider provider, TrustManagerFactory trustManagerFactory) Deprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(File certChainFile) Deprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(File certChainFile, TrustManagerFactory trustManagerFactory) Deprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(File certChainFile, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig apn, long sessionCacheSize, long sessionTimeout) Deprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(File certChainFile, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, Iterable<String> nextProtocols, long sessionCacheSize, long sessionTimeout) Deprecated.Replaced bySslContextBuilderstatic SslContextnewClientContext(TrustManagerFactory trustManagerFactory) Deprecated.Replaced bySslContextBuilderfinal SslHandlernewHandler(ByteBufAllocator alloc) Create a new SslHandler.final SslHandlernewHandler(ByteBufAllocator alloc, String peerHost, int peerPort) Creates a newSslHandlernewHandler(ByteBufAllocator alloc, String peerHost, int peerPort, Executor delegatedTaskExecutor) Creates a newSslHandlerwith advisory peer information.newHandler(ByteBufAllocator alloc, Executor delegatedTaskExecutor) Creates a newSslHandler.static SslContextnewServerContext(SslProvider provider, File certChainFile, File keyFile) Deprecated.Replaced bySslContextBuilderstatic SslContextnewServerContext(SslProvider provider, File certChainFile, File keyFile, String keyPassword) Deprecated.Replaced bySslContextBuilderstatic SslContextnewServerContext(SslProvider provider, File certChainFile, File keyFile, String keyPassword, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig apn, long sessionCacheSize, long sessionTimeout) Deprecated.Replaced bySslContextBuilderstatic SslContextnewServerContext(SslProvider provider, File certChainFile, File keyFile, String keyPassword, Iterable<String> ciphers, Iterable<String> nextProtocols, long sessionCacheSize, long sessionTimeout) Deprecated.Replaced bySslContextBuilderstatic SslContextnewServerContext(SslProvider provider, File certChainFile, File keyFile, String keyPassword, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, Iterable<String> nextProtocols, long sessionCacheSize, long sessionTimeout) Deprecated.Replaced bySslContextBuilderstatic SslContextnewServerContext(SslProvider provider, File trustCertCollectionFile, TrustManagerFactory trustManagerFactory, File keyCertChainFile, File keyFile, String keyPassword, KeyManagerFactory keyManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig apn, long sessionCacheSize, long sessionTimeout) Deprecated.Replaced bySslContextBuilderstatic SslContextnewServerContext(File certChainFile, File keyFile) Deprecated.Replaced bySslContextBuilderstatic SslContextnewServerContext(File certChainFile, File keyFile, String keyPassword) Deprecated.Replaced bySslContextBuilderstatic SslContextnewServerContext(File certChainFile, File keyFile, String keyPassword, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig apn, long sessionCacheSize, long sessionTimeout) Deprecated.Replaced bySslContextBuilderstatic SslContextnewServerContext(File certChainFile, File keyFile, String keyPassword, Iterable<String> ciphers, Iterable<String> nextProtocols, long sessionCacheSize, long sessionTimeout) Deprecated.Replaced bySslContextBuilderDeprecated.UseSslContext.applicationProtocolNegotiator()instead.longReturns the size of the cache used for storing SSL session objects.longReturns the timeout for the cached SSL session objects, in seconds.protected static PrivateKeytoPrivateKey(File keyFile, String keyPassword) protected static PrivateKeytoPrivateKey(InputStream keyInputStream, String keyPassword) protected static X509Certificate[]toX509Certificates(File file) protected static X509Certificate[]
-
Constructor Details
-
OpenSslServerContext
Deprecated.Creates a new instance.- Parameters:
certChainFile- an X.509 certificate chain file in PEM formatkeyFile- a PKCS#8 private key file in PEM format- Throws:
SSLException
-
OpenSslServerContext
@Deprecated public OpenSslServerContext(File certChainFile, File keyFile, String keyPassword) throws SSLException Deprecated.Creates a new instance.- Parameters:
certChainFile- an X.509 certificate chain file in PEM formatkeyFile- a PKCS#8 private key file in PEM formatkeyPassword- the password of thekeyFile.nullif it's not password-protected.- Throws:
SSLException
-
OpenSslServerContext
@Deprecated public OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, Iterable<String> ciphers, ApplicationProtocolConfig apn, long sessionCacheSize, long sessionTimeout) throws SSLException Deprecated.Creates a new instance.- Parameters:
certChainFile- an X.509 certificate chain file in PEM formatkeyFile- a PKCS#8 private key file in PEM formatkeyPassword- the password of thekeyFile.nullif it's not password-protected.ciphers- the cipher suites to enable, in the order of preference.nullto use the default cipher suites.apn- Provides a means to configure parameters related to application protocol negotiation.sessionCacheSize- the size of the cache used for storing SSL session objects.0to use the default value.sessionTimeout- the timeout for the cached SSL session objects, in seconds.0to use the default value.- Throws:
SSLException
-
OpenSslServerContext
@Deprecated public OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, Iterable<String> ciphers, Iterable<String> nextProtocols, long sessionCacheSize, long sessionTimeout) throws SSLException Deprecated.Creates a new instance.- Parameters:
certChainFile- an X.509 certificate chain file in PEM formatkeyFile- a PKCS#8 private key file in PEM formatkeyPassword- the password of thekeyFile.nullif it's not password-protected.ciphers- the cipher suites to enable, in the order of preference.nullto use the default cipher suites.nextProtocols- the application layer protocols to accept, in the order of preference.nullto disable TLS NPN/ALPN extension.sessionCacheSize- the size of the cache used for storing SSL session objects.0to use the default value.sessionTimeout- the timeout for the cached SSL session objects, in seconds.0to use the default value.- Throws:
SSLException
-
OpenSslServerContext
@Deprecated public OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, ApplicationProtocolConfig config, long sessionCacheSize, long sessionTimeout) throws SSLException Deprecated.Creates a new instance.- Parameters:
certChainFile- an X.509 certificate chain file in PEM formatkeyFile- a PKCS#8 private key file in PEM formatkeyPassword- the password of thekeyFile.nullif it's not password-protected.ciphers- the cipher suites to enable, in the order of preference.nullto use the default cipher suites.config- Application protocol config.sessionCacheSize- the size of the cache used for storing SSL session objects.0to use the default value.sessionTimeout- the timeout for the cached SSL session objects, in seconds.0to use the default value.- Throws:
SSLException
-
OpenSslServerContext
@Deprecated public OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, OpenSslApplicationProtocolNegotiator apn, long sessionCacheSize, long sessionTimeout) throws SSLException Deprecated.Creates a new instance.- Parameters:
certChainFile- an X.509 certificate chain file in PEM formatkeyFile- a PKCS#8 private key file in PEM formatkeyPassword- the password of thekeyFile.nullif it's not password-protected.ciphers- the cipher suites to enable, in the order of preference.nullto use the default cipher suites.apn- Application protocol negotiator.sessionCacheSize- the size of the cache used for storing SSL session objects.0to use the default value.sessionTimeout- the timeout for the cached SSL session objects, in seconds.0to use the default value.- Throws:
SSLException
-
OpenSslServerContext
@Deprecated public OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig apn, long sessionCacheSize, long sessionTimeout) throws SSLException Deprecated.Creates a new instance.- Parameters:
certChainFile- an X.509 certificate chain file in PEM formatkeyFile- a PKCS#8 private key file in PEM formatkeyPassword- the password of thekeyFile.nullif it's not password-protected.ciphers- the cipher suites to enable, in the order of preference.nullto use the default cipher suites.cipherFilter- a filter to apply over the supplied list of ciphersapn- Provides a means to configure parameters related to application protocol negotiation.sessionCacheSize- the size of the cache used for storing SSL session objects.0to use the default value.sessionTimeout- the timeout for the cached SSL session objects, in seconds.0to use the default value.- Throws:
SSLException
-
OpenSslServerContext
@Deprecated public OpenSslServerContext(File trustCertCollectionFile, TrustManagerFactory trustManagerFactory, File keyCertChainFile, File keyFile, String keyPassword, KeyManagerFactory keyManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig config, long sessionCacheSize, long sessionTimeout) throws SSLException Deprecated.Creates a new instance.- Parameters:
trustCertCollectionFile- an X.509 certificate collection file in PEM format. This provides the certificate collection used for mutual authentication.nullto use the system defaulttrustManagerFactory- theTrustManagerFactorythat provides theTrustManagers that verifies the certificates sent from clients.nullto use the default or the results of parsingtrustCertCollectionFile.keyCertChainFile- an X.509 certificate chain file in PEM formatkeyFile- a PKCS#8 private key file in PEM formatkeyPassword- the password of thekeyFile.nullif it's not password-protected.keyManagerFactory- theKeyManagerFactorythat provides theKeyManagers that is used to encrypt data being sent to clients.nullto use the default or the results of parsingkeyCertChainFileandkeyFile.ciphers- the cipher suites to enable, in the order of preference.nullto use the default cipher suites.cipherFilter- a filter to apply over the supplied list of ciphers Only required ifproviderisSslProvider.JDKconfig- Provides a means to configure parameters related to application protocol negotiation.sessionCacheSize- the size of the cache used for storing SSL session objects.0to use the default value.sessionTimeout- the timeout for the cached SSL session objects, in seconds.0to use the default value.- Throws:
SSLException
-
OpenSslServerContext
@Deprecated public OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, ApplicationProtocolConfig config, long sessionCacheSize, long sessionTimeout) throws SSLException Deprecated.Creates a new instance.- Parameters:
certChainFile- an X.509 certificate chain file in PEM formatkeyFile- a PKCS#8 private key file in PEM formatkeyPassword- the password of thekeyFile.nullif it's not password-protected.ciphers- the cipher suites to enable, in the order of preference.nullto use the default cipher suites.cipherFilter- a filter to apply over the supplied list of ciphersconfig- Application protocol config.sessionCacheSize- the size of the cache used for storing SSL session objects.0to use the default value.sessionTimeout- the timeout for the cached SSL session objects, in seconds.0to use the default value.- Throws:
SSLException
-
OpenSslServerContext
@Deprecated public OpenSslServerContext(File certChainFile, File keyFile, String keyPassword, TrustManagerFactory trustManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, OpenSslApplicationProtocolNegotiator apn, long sessionCacheSize, long sessionTimeout) throws SSLException Deprecated.useSslContextBuilder}Creates a new instance.- Parameters:
certChainFile- an X.509 certificate chain file in PEM formatkeyFile- a PKCS#8 private key file in PEM formatkeyPassword- the password of thekeyFile.nullif it's not password-protected.ciphers- the cipher suites to enable, in the order of preference.nullto use the default cipher suites.cipherFilter- a filter to apply over the supplied list of ciphersapn- Application protocol negotiator.sessionCacheSize- the size of the cache used for storing SSL session objects.0to use the default value.sessionTimeout- the timeout for the cached SSL session objects, in seconds.0to use the default value.- Throws:
SSLException
-
OpenSslServerContext
@Deprecated public OpenSslServerContext(File trustCertCollectionFile, TrustManagerFactory trustManagerFactory, File keyCertChainFile, File keyFile, String keyPassword, KeyManagerFactory keyManagerFactory, Iterable<String> ciphers, CipherSuiteFilter cipherFilter, OpenSslApplicationProtocolNegotiator apn, long sessionCacheSize, long sessionTimeout) throws SSLException Deprecated.Creates a new instance.- Parameters:
trustCertCollectionFile- an X.509 certificate collection file in PEM format. This provides the certificate collection used for mutual authentication.nullto use the system defaulttrustManagerFactory- theTrustManagerFactorythat provides theTrustManagers that verifies the certificates sent from clients.nullto use the default or the results of parsingtrustCertCollectionFile.keyCertChainFile- an X.509 certificate chain file in PEM formatkeyFile- a PKCS#8 private key file in PEM formatkeyPassword- the password of thekeyFile.nullif it's not password-protected.keyManagerFactory- theKeyManagerFactorythat provides theKeyManagers that is used to encrypt data being sent to clients.nullto use the default or the results of parsingkeyCertChainFileandkeyFile.ciphers- the cipher suites to enable, in the order of preference.nullto use the default cipher suites.cipherFilter- a filter to apply over the supplied list of ciphers Only required ifproviderisSslProvider.JDKapn- Application Protocol Negotiator objectsessionCacheSize- the size of the cache used for storing SSL session objects.0to use the default value.sessionTimeout- the timeout for the cached SSL session objects, in seconds.0to use the default value.- Throws:
SSLException
-
-
Method Details
-
sessionContext
Description copied from class:SslContextReturns theSSLSessionContextobject held by this context.- Specified by:
sessionContextin classReferenceCountedOpenSslContext
-
SslContextBuilder