Class KEStoreUtilities
- java.lang.Object
-
- org.oa4mp.server.loader.oauth2.storage.keys.KEStoreUtilities
-
public class KEStoreUtilities extends Object
-
-
Constructor Summary
Constructors Constructor Description KEStoreUtilities()
-
Method Summary
All Methods Static Methods Concrete Methods Modifier and Type Method Description static KERecordcreateSingleKERecord(KEStore<KERecord> keStore, URI viID, boolean isValid, edu.uiuc.ncsa.security.util.jwk.JSONWebKey jwk, String defaultID)Create a single KE record from a JWK.static KERecordgetByKID(KEStore store, String kid)static edu.uiuc.ncsa.security.core.util.IdentifiableMap<KERecord>getByVI(KEStore<KERecord> store, VirtualIssuer vi)static edu.uiuc.ncsa.security.core.util.IdentifiableMap<KERecord>getByVI(KEStore<KERecord> store, VirtualIssuer vi, boolean validKeysOnly)static edu.uiuc.ncsa.security.util.jwk.JSONWebKeysgetCurrentKeys(KEStore<KERecord> store, VirtualIssuer vi)static HashSet<String>getKIDs(KEStore<KERecord> store)static List<String>ingest(KEStore<KERecord> keStore, edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jwks, VirtualIssuer vi, boolean isValid)Ingest a set of webkeys into the store.static edu.uiuc.ncsa.security.core.util.IdentifiableMap<KERecord>jwksToIDMap(edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jwks)Convert a set of JWKs to a map of KE records.static KEConfigurationresolveKeConfiguration(OA2SE oa2SE, VirtualIssuer vi)For a virtual issuer (may be null), resolve the key configuration.static edu.uiuc.ncsa.security.util.jwk.JSONWebKeyrotate(edu.uiuc.ncsa.security.util.jwk.JSONWebKey oldKey, long cacheGracePeriod, long atGracePeriod)Rotates a key using the given grace periods.static Map<edu.uiuc.ncsa.security.core.Identifier,KERecord>rotate(OA2SE oa2SE, List<edu.uiuc.ncsa.security.core.Identifier> vIDs, KEConfiguration keConfiguration, boolean forceFlag, boolean testOnly)Rotate the keys for the given virtual issuers, optionally removing the keys from the VI if retainInVI is true, Default should be false.static KERecordrotate(KEStore<KERecord> keStore, KERecord oldKER, long cacheGracePeriod, long atGracePeriod, boolean testOnly)Rotate the Key from the Key Entry record.static Map<edu.uiuc.ncsa.security.core.Identifier,KERecord>rotate(KEStore keStore, Map<edu.uiuc.ncsa.security.core.Identifier,KERecord> oldKERS, boolean force, long cacheGracePeriod, long atGracePeriod, boolean updateOldKeys, boolean testOnly)Rotate a set of records.static voidsetRotationDates(edu.uiuc.ncsa.security.util.jwk.JSONWebKey jwk, edu.uiuc.ncsa.security.util.jwk.JSONWebKey newKey, long cacheGracePeriod, long atGracePeriod)Sets the dates for rotation on the keys.
-
-
-
Method Detail
-
getByVI
public static edu.uiuc.ncsa.security.core.util.IdentifiableMap<KERecord> getByVI(KEStore<KERecord> store, VirtualIssuer vi)
-
getByVI
public static edu.uiuc.ncsa.security.core.util.IdentifiableMap<KERecord> getByVI(KEStore<KERecord> store, VirtualIssuer vi, boolean validKeysOnly)
-
getCurrentKeys
public static edu.uiuc.ncsa.security.util.jwk.JSONWebKeys getCurrentKeys(KEStore<KERecord> store, VirtualIssuer vi)
-
rotate
public static Map<edu.uiuc.ncsa.security.core.Identifier,KERecord> rotate(OA2SE oa2SE, List<edu.uiuc.ncsa.security.core.Identifier> vIDs, KEConfiguration keConfiguration, boolean forceFlag, boolean testOnly) throws InvalidAlgorithmParameterException, NoSuchAlgorithmException, InvalidKeySpecException
Rotate the keys for the given virtual issuers, optionally removing the keys from the VI if retainInVI is true, Default should be false. there are any.- Parameters:
oa2SE-vIDs-- Throws:
InvalidAlgorithmParameterExceptionNoSuchAlgorithmExceptionInvalidKeySpecException
-
rotate
public static Map<edu.uiuc.ncsa.security.core.Identifier,KERecord> rotate(KEStore keStore, Map<edu.uiuc.ncsa.security.core.Identifier,KERecord> oldKERS, boolean force, long cacheGracePeriod, long atGracePeriod, boolean updateOldKeys, boolean testOnly) throws InvalidAlgorithmParameterException, NoSuchAlgorithmException, InvalidKeySpecException
Rotate a set of records. This sets the new keys to be valid and updates the store with both new and old keys.Note that this returns the original keys if testOnly flag is set to true and in that case, no changes are done.
- Parameters:
keStore-oldKERS-cacheGracePeriod-atGracePeriod-- Returns:
- Map of the new key entry records.
- Throws:
InvalidAlgorithmParameterExceptionNoSuchAlgorithmExceptionInvalidKeySpecException
-
rotate
public static edu.uiuc.ncsa.security.util.jwk.JSONWebKey rotate(edu.uiuc.ncsa.security.util.jwk.JSONWebKey oldKey, long cacheGracePeriod, long atGracePeriod) throws InvalidAlgorithmParameterException, NoSuchAlgorithmExceptionRotates a key using the given grace periods. It will create a new key using the old key as a guide (same algorithm, etc.).- Parameters:
oldKey-cacheGracePeriod-atGracePeriod-- Returns:
- Throws:
InvalidAlgorithmParameterExceptionNoSuchAlgorithmException
-
rotate
public static KERecord rotate(KEStore<KERecord> keStore, KERecord oldKER, long cacheGracePeriod, long atGracePeriod, boolean testOnly) throws InvalidAlgorithmParameterException, NoSuchAlgorithmException, InvalidKeySpecException
Rotate the Key from the Key Entry record. Note that this sets everything except theKERecord.isValidin the result. Also, the new record is not saved and the expiration on the old record is updated, but also not saved. This allows you to control that directly.- Parameters:
keStore-oldKER-cacheGracePeriod-atGracePeriod-- Returns:
- Throws:
InvalidAlgorithmParameterExceptionNoSuchAlgorithmExceptionInvalidKeySpecException
-
setRotationDates
public static void setRotationDates(edu.uiuc.ncsa.security.util.jwk.JSONWebKey jwk, edu.uiuc.ncsa.security.util.jwk.JSONWebKey newKey, long cacheGracePeriod, long atGracePeriod)Sets the dates for rotation on the keys. This means- old key = expiration set to now + cache grace period + at grace period
- new key - issued at set to now, not valiud before is now + cache grace period
- Parameters:
jwk-newKey-cacheGracePeriod-atGracePeriod-
-
resolveKeConfiguration
public static KEConfiguration resolveKeConfiguration(OA2SE oa2SE, VirtualIssuer vi)
For a virtual issuer (may be null), resolve the key configuration. This means that if the VI has these configured, and the server allows for overrides, use the VI configuration. Otherwise use the server configuration. Note that it is assumed you have checked if the server allows key rotations separately.- Parameters:
oa2SE-vi-- Returns:
-
ingest
public static List<String> ingest(KEStore<KERecord> keStore, edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jwks, VirtualIssuer vi, boolean isValid) throws NoSuchAlgorithmException, InvalidKeySpecException
Ingest a set of webkeys into the store. Default values are set if needed.- Parameters:
keStore-jwks-vi-isValid- set all keys to valid.- Returns:
- Throws:
NoSuchAlgorithmExceptionInvalidKeySpecException
-
createSingleKERecord
public static KERecord createSingleKERecord(KEStore<KERecord> keStore, URI viID, boolean isValid, edu.uiuc.ncsa.security.util.jwk.JSONWebKey jwk, String defaultID) throws NoSuchAlgorithmException, InvalidKeySpecException
Create a single KE record from a JWK. This is not saved..- Parameters:
keStore-viID-isValid-jwk-defaultID-- Returns:
- Throws:
NoSuchAlgorithmExceptionInvalidKeySpecException
-
jwksToIDMap
public static edu.uiuc.ncsa.security.core.util.IdentifiableMap<KERecord> jwksToIDMap(edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jwks) throws NoSuchAlgorithmException, InvalidKeySpecException
Convert a set of JWKs to a map of KE records. This is a useful utility for many programs.- Parameters:
jwks-- Returns:
- Throws:
NoSuchAlgorithmExceptionInvalidKeySpecException
-
-