Package io.netty.handler.ssl
SSL ·
TLS implementation based on
SSLEngine-
Interface Summary Interface Description ApplicationProtocolNegotiator Deprecated. CipherSuiteFilter Provides a means to filter the supplied cipher suite based upon the supported and default cipher suites.JdkApplicationProtocolNegotiator Deprecated. JdkApplicationProtocolNegotiator.ProtocolSelectionListener A listener to be notified by which protocol was select by its peer.JdkApplicationProtocolNegotiator.ProtocolSelectionListenerFactory Factory interface forJdkApplicationProtocolNegotiator.ProtocolSelectionListenerobjects.JdkApplicationProtocolNegotiator.ProtocolSelector Interface to define the role of an application protocol selector in the SSL handshake process.JdkApplicationProtocolNegotiator.ProtocolSelectorFactory Factory interface forJdkApplicationProtocolNegotiator.ProtocolSelectorobjects.JdkApplicationProtocolNegotiator.SslEngineWrapperFactory Abstract factory pattern for wrapping anSSLEngineobject.OpenSslApplicationProtocolNegotiator Deprecated. OpenSslAsyncPrivateKeyMethod OpenSslCertificateCompressionAlgorithm Provides compression and decompression implementations for TLS Certificate Compression (RFC 8879).OpenSslPrivateKeyMethod Allow to customize private key signing / decrypting (when using RSA).OpenSslSession SSLSessionsub-type that is used by our native implementation.ResumableX509ExtendedTrustManager An interface thatTrustManagerinstances can implement, to be notified of resumed SSL sessions. -
Class Summary Class Description AbstractSniHandler<T> Enables SNI (Server Name Indication) extension for server side SSL.ApplicationProtocolConfig Provides anSSLEngineagnostic way to configure aApplicationProtocolNegotiator.ApplicationProtocolNames Provides a set of protocol names used in ALPN and NPN.ApplicationProtocolNegotiationHandler Configures aChannelPipelinedepending on the application-level protocol negotiation result ofSslHandler.Ciphers Cipher suitesCipherSuiteConverter Converts a Java cipher suite string to an OpenSSL cipher suite string and vice versa.DelegatingSslContext Adapter class which allows to wrap anotherSslContextand initSSLEngineinstances.IdentityCipherSuiteFilter This class will not do any filtering of ciphers suites.JdkAlpnApplicationProtocolNegotiator Deprecated. JdkApplicationProtocolNegotiator.AllocatorAwareSslEngineWrapperFactory JdkSslClientContext Deprecated. JdkSslContext AnSslContextwhich uses JDK's SSL/TLS implementation.JdkSslServerContext Deprecated. OpenSsl Tells ifnetty-tcnativeand its OpenSSL support are available.OpenSslCachingX509KeyManagerFactory Wraps anotherKeyManagerFactoryand caches its chains / certs for an alias for better performance when usingSslProvider.OPENSSLorSslProvider.OPENSSL_REFCNT.OpenSslCertificateCompressionConfig Configuration for TLS1.3 certificate compression extension.OpenSslCertificateCompressionConfig.AlgorithmConfig The configuration for algorithm.OpenSslCertificateCompressionConfig.Builder Builder for anOpenSslCertificateCompressionAlgorithm.OpenSslClientContext A client-sideSslContextwhich uses OpenSSL's SSL/TLS implementation.OpenSslContext This class will use a finalizer to ensure native resources are automatically cleaned up.OpenSslContextOption<T> OpenSslDefaultApplicationProtocolNegotiator Deprecated. OpenSslEngine Implements aSSLEngineusing OpenSSL BIO abstractions.OpenSslNpnApplicationProtocolNegotiator Deprecated. OpenSslServerContext A server-sideSslContextwhich uses OpenSSL's SSL/TLS implementation.OpenSslServerSessionContext OpenSslSessionContextimplementation which offers extra methods which are only useful for the server-side.OpenSslSessionContext OpenSSL specificSSLSessionContextimplementation.OpenSslSessionStats Stats exposed by an OpenSSL session context.OpenSslSessionTicketKey Session Ticket KeyOpenSslX509KeyManagerFactory SpecialKeyManagerFactorythat pre-compute the keymaterial used whenSslProvider.OPENSSLorSslProvider.OPENSSL_REFCNTis used and so will improve handshake times and its performance.OptionalSslHandler OptionalSslHandleris a utility decoder to support both SSL and non-SSL handlers based on the first message received.PemPrivateKey This is a special purpose implementation of aPrivateKeywhich allows the user to pass PEM/PKCS#8 encoded key material straight intoOpenSslContextwithout having to parse and re-encode bytes in Java land.PemX509Certificate This is a special purpose implementation of aX509Certificatewhich allows the user to pass PEM/PKCS#8 encoded data straight intoOpenSslContextwithout having to parse and re-encode bytes in Java land.ReferenceCountedOpenSslClientContext A client-sideSslContextwhich uses OpenSSL's SSL/TLS implementation.ReferenceCountedOpenSslContext An implementation ofSslContextwhich works with libraries that support the OpenSsl C library API.ReferenceCountedOpenSslEngine Implements aSSLEngineusing OpenSSL BIO abstractions.ReferenceCountedOpenSslServerContext A server-sideSslContextwhich uses OpenSSL's SSL/TLS implementation.SniCompletionEvent Event that is fired once we did a selection of aSslContextbased on theSNI hostname, which may be because it was successful or there was an error.SniHandler Enables SNI (Server Name Indication) extension for server side SSL.SslClientHelloHandler<T> ByteToMessageDecoderwhich allows to be notified once a fullClientHellowas received.SslCloseCompletionEvent Event that is fired once the close_notify was received or if an failure happens before it was received.SslCompletionEvent SslContext A secure socket protocol implementation which acts as a factory forSSLEngineandSslHandler.SslContextBuilder Builder for configuring a new SslContext for creation.SslContextOption<T> ASslContextOptionallows to configure aSslContextin a type-safe way.SslHandler SslHandshakeCompletionEvent Event that is fired once the SSL handshake is complete, which may be because it was successful or there was an error.SslMasterKeyHandler TheSslMasterKeyHandleris a channel-handler you can include in your pipeline to consume the master key & session identifier for a TLS session.SslProtocols SSL/TLS protocolsSupportedCipherSuiteFilter This class will filter all requested ciphers out that are not supported by the currentSSLEngine. -
Enum Summary Enum Description ApplicationProtocolConfig.Protocol Defines which application level protocol negotiation to use.ApplicationProtocolConfig.SelectedListenerFailureBehavior Defines the most common behaviors for the peer which is notified of the selected protocol.ApplicationProtocolConfig.SelectorFailureBehavior Defines the most common behaviors for the peer that selects the application protocol.ClientAuth Indicates the state of theSSLEnginewith respect to client authentication.OpenSslCertificateCompressionConfig.AlgorithmMode The usage mode of theOpenSslCertificateCompressionAlgorithm.SslProvider An enumeration of SSL/TLS protocol providers. -
Exception Summary Exception Description NotSslRecordException SpecialSSLExceptionwhich will get thrown if a packet is received that not looks like a TLS/SSL record.OpenSslCertificateException A specialCertificateExceptionwhich allows to specify which error code is included in the SSL Record.SslClosedEngineException SSLExceptionwhich signals that the exception was caused by anSSLEnginewhich was closed already.SslHandshakeTimeoutException SSLHandshakeExceptionthat is used when a handshake failed due a configured timeout.