|
JavaTM 2 Platform Std. Ed. v1. 4.0 |
||||||||||
ÀüÀÇ Å¬·¡½º ´ÙÀ½ÀÇ Å¬·¡½º | ÇÁ·¹ÀÓ ÀÖ¾î ÇÁ·¹ÀÓ ¾øÀ½ | ||||||||||
°³¿ä: »óÀÚ | Çʵå | constructor | ¸Þ¼Òµå | »ó¼¼: Çʵå | constructor | ¸Þ¼Òµå |
java.lang.Object | +--java.security.cert.CRL | +--java.security.cert.X509CRL
X. 509 Áõ¸í¼ÀÇ Ãë¼Ò ¸®½ºÆ® (CRL)ÀÇ Ãß»ó Ŭ·¡½ºÀÔ´Ï´Ù. CRL ´Â »èÁ¦µÈ Áõ¸í¼¸¦ ½Äº°Çϴ ŸÀÓ ½ºÅÆÇÁ ÷ºÎÀÇ ¸®½ºÆ®ÀÔ´Ï´Ù. CRL ´Â Áõ¸í¼ ¹ßÇà±¹ (CA)¿¡ ÀÇÇØ ¼¸íµÇ¾î °ø¿ë ¸®Æ÷ÁöÅ͸®(repository)·Î ÀÚÀ¯·Ó°Ô ÀÌ¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
»èÁ¦µÈ °¢ Áõ¸í¼´Â CRL ¿¡¼´Â Áõ¸í¼ÀÇ ½Ã¸®¾ó ¹øÈ£¿¡ ÀÇÇØ ½Äº°µË´Ï´Ù. Áõ¸í¼ »ç¿ë ½Ã½ºÅÛÀÌ Áõ¸í¼¸¦ »ç¿ëÇÒ ¶§ (¿¹¸¦ µé¾î, ¸®¸ðÆ® À¯ÀúÀÇ µðÁöÅÐ ¼¸íÀÇ °ËÁõÀ» À§ÇØ), ½Ã½ºÅÛÀº Áõ¸í¼ÀÇ ¼¸í°ú À¯È¿±â°£À» È®ÀÎÇÒ »Ó¸¸ ¾Æ´Ï¶ó, »õ·Î¿î CRL ¸¦ ÃëµæÇØ, Áõ¸í¼ÀÇ ½Ã¸®¾ó ¹øÈ£°¡ ±× CRL ¿¡ ¾ø´Â °Íµµ È®ÀÎÇÕ´Ï´Ù. ¡¸»õ·Ó´Ù¡¹ÀÇ Àǹ̴ ·ÎÄà Æú¸®½Ã¿¡ µû¶ó¼ ´Ù¸¨´Ï´Ù¸¸, Åë»óÀº °¡Àå »õ·Ó°Ô ¹ßÇàµÈ CRL ¸¦ ÀǹÌÇÕ´Ï´Ù. CA ´Â »õ·Î¿î CRL ¸¦ Á¤±âÀû (¿¹¸¦ µé¾î, ¸Å½Ã, ¸ÅÀÏ, ¸ÅÁÖ)À¸·Î ¹ßÇàÇÕ´Ï´Ù. Ãë¼Ò°¡ ÀÖÀ» ¶§¸¶´Ù ¿£Æ®¸®°¡ CRL ¿¡ Ãß°¡µÇ¾î Áõ¸í¼ÀÇ À¯È¿±â°£ÀÌ ²÷¾îÁö¸é(ÀÚ) ¿£Æ®¸®°¡ »èÁ¦µË´Ï´Ù.
X. 509 v2 CRL Çü½ÄÀº ASN. 1 À¸·Î ´ÙÀ½°ú °°ÀÌ ±â¼úµË´Ï´Ù.
CertificateList ::= SEQUENCE { tbsCertList TBSCertList, signatureAlgorithm AlgorithmIdentifier, signature BIT STRING }
ÀÚ¼¼ÇÑ °ÍÀº http://www.ietf.org/rfc/rfc2459.txt ¿¡ ÀÖ´Â RFC 2459 ÀÇ ¡¸Internet X. 509 Public Key Infrastructure Certificate and CRL Profile¡¹¸¦ ÂüÁ¶ÇØ ÁÖ¼¼¿ä.
tbsCertList
ÀÇ ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
TBSCertList ::= SEQUENCE { version Version OPTIONAL, -- if present, must be v2 signature AlgorithmIdentifier, issuer Name, thisUpdate ChoiceOfTime, nextUpdate ChoiceOfTime OPTIONAL, revokedCertificates SEQUENCE OF SEQUENCE { userCertificate CertificateSerialNumber, revocationDate ChoiceOfTime, crlEntryExtensions Extensions OPTIONAL -- if present, must be v2 } OPTIONAL, crlExtensions [0] EXPLICIT Extensions OPTIONAL -- if present, must be v2 }
CRL ÀÇ ÀνºÅϽº´Â Áõ¸í¼ ÆÑÅ丮¸¦ »ç¿ëÇØ »ý¼ºµË´Ï´Ù. ÀÌÇÏÀÇ ¿¹´Â X. 509 CRL ÀÇ ÀνºÅϽº¸¦ »ý¼ºÇÏ´Â ¹æ¹ýÀ» ³ªÅ¸³»°í ÀÖ½À´Ï´Ù.
InputStream inStream = new FileInputStream("fileName-of-crl");
CertificateFactory cf = CertificateFactory.getInstance("X. 509");
X509CRL crl = (X509CRL) cf.generateCRL(inStream);
inStream.close();
CRL
,
CertificateFactory
,
X509Extension
»ý¼ºÀÚÀÇ °³¿ä | |
protected |
X509CRL ()
X. 509 CRL ÀÇ constructor ÀÔ´Ï´Ù. |
¸Þ¼ÒµåÀÇ °³¿ä | |
boolean |
equals (Object other)
ÁöÁ¤µÈ ¿ÀºêÁ§Æ®¿Í ÀÌ CRL °¡ µ¿ÀÏÇÑÁö ¾î¶²Áö¸¦ ÆÇÁ¤ÇÕ´Ï´Ù. |
abstract byte[] |
getEncoded ()
ÀÌ CRL ÀÇ ASN. 1 DER ·Î encode µÈ Çü½ÄÀ» µ¹·ÁÁÝ´Ï´Ù. |
abstract Principal |
getIssuerDN ()
CRL ·ÎºÎÅÍ issuer (¹ßÇàÀÚ ½Äº°¸í) Ä¡¸¦ ÃëµæÇÕ´Ï´Ù. |
X500Principal |
getIssuerX500Principal ()
CRL ·ÎºÎÅÍ ¹ßÇàÀÚ (¹ßÇàÀÚÀÇ ½Äº°¸í)ÀÇ °ªÀ» X500Principal ·Î¼ µ¹·ÁÁÝ´Ï´Ù. |
abstract Date |
getNextUpdate ()
CRL ·ÎºÎÅÍ nextUpdate ÀÇ ÀÏÀÚ¸¦ ÃëµæÇÕ´Ï´Ù. |
abstract X509CRLEntry |
getRevokedCertificate (BigInteger serialNumber)
ÁöÁ¤µÈ Áõ¸í¼ÀÇ serialNumber ¸¦ °¡Áö´Â CRL ¿£Æ®¸®¸¦ ÃëµæÇÕ´Ï´Ù (ÀÖ´Â °æ¿ì). |
abstract Set |
getRevokedCertificates ()
¸ðµç ¿£Æ®¸®¸¦ ÃëµæÇÕ´Ï´Ù. |
abstract String |
getSigAlgName ()
¼¸í ¾Ë°í¸®Áò¸íÀ» ÃëµæÇÕ´Ï´Ù. |
abstract String |
getSigAlgOID ()
CRL ·ÎºÎÅÍ ¼¸í ¾Ë°í¸®ÁòÀÇ OID ij¸¯ÅÍ ¶óÀÎÀ» ÃëµæÇÕ´Ï´Ù. |
abstract byte[] |
getSigAlgParams ()
¼¸í ¾Ë°í¸®ÁòÀ¸·ÎºÎÅÍ DER ·Î encode µÈ ¼¸í ¾Ë°í¸®Áò ÆÄ¶ó¹ÌÅ͸¦ ÃëµæÇÕ´Ï´Ù. |
abstract byte[] |
getSignature ()
signature Ä¡ (»ýÀÇ ÇüźøÆ®)¸¦ ÃëµæÇÕ´Ï´Ù. |
abstract byte[] |
getTBSCertList ()
DER ·Î encode µÈ CRL Á¤º¸ tbsCertList ¸¦ CRL ·ÎºÎÅÍ ÃëµæÇÕ´Ï´Ù. |
abstract Date |
getThisUpdate ()
CRL ·ÎºÎÅÍ thisUpdate ÀÇ ÀÏÀÚ¸¦ ÃëµæÇÕ´Ï´Ù. |
abstract int |
getVersion ()
CRL ·ÎºÎÅÍ version (¹öÁ¯ ¹øÈ£) Ä¡¸¦ ÃëµæÇÕ´Ï´Ù. |
int |
hashCode ()
encode µÈ Çü½ÄÀ¸·ÎºÎÅÍ ÀÌ CRL ÀÇ ÇØ½Ã ÄÚµåÄ¡¸¦ µ¹·ÁÁÝ´Ï´Ù. |
abstract void |
verify (PublicKey key)
ÁöÁ¤µÈ °ø°³¿¼è¿¡ ´ëÀÀÇÏ´Â ºñ°ø°³¿¼è¸¦ »ç¿ëÇØ, ÀÌ CRL °¡ ¼¸íµÈ °ÍÀ» °ËÁõÇÕ´Ï´Ù. |
abstract void |
verify (PublicKey key,
String sigProvider)
ÀÌ CRL °¡, ÁöÁ¤µÈ °ø°³¿¼è¿¡ ´ëÀÀÇÏ´Â ºñ°ø°³¿¼è¸¦ »ç¿ëÇØ ¼¸íµÈ °ÍÀ» °ËÁõÇÕ´Ï´Ù. |
Ŭ·¡½º java.security.cert. CRL ¿¡¼ »ó¼Ó¹ÞÀº ¸Þ¼Òµå |
getType , isRevoked , toString |
Ŭ·¡½º java.lang. Object ¿¡¼ »ó¼Ó¹ÞÀº ¸Þ¼Òµå |
clone , finalize , getClass , notify , notifyAll , wait , wait , wait |
ÀÎÅÍÆäÀ̽º java.security.cert. X509Extension ¿¡¼ »ó¼Ó¹ÞÀº ¸Þ¼Òµå |
getCriticalExtensionOIDs , getExtensionValue , getNonCriticalExtensionOIDs , hasUnsupportedCriticalExtension |
»ý¼ºÀÚÀÇ »ó¼¼ |
protected X509CRL()
¸Þ¼ÒµåÀÇ »ó¼¼ |
public boolean equals(Object other)
other
¿ÀºêÁ§Æ®°¡ X509CRL
ÀÇ ÀνºÅϽºÀÇ °æ¿ì´Â encode µÈ Çü½ÄÀÌ ²¨³»Á® ÀÌ CRL ÀÇ encode µÈ Çü½ÄÀ̶ó°í ºñ±³µË´Ï´Ù.
Object
³»ÀÇ equals
other
- ÀÌ CRL ¿Í µ¿ÀÏÇÑÁö ¾î¶²Áö°¡ ÆÇÁ¤µÇ´Â ¿ÀºêÁ§Æ®
Object.hashCode()
,
Hashtable
public int hashCode()
Object
³»ÀÇ hashCode
Object.equals(java.lang.Object)
,
Hashtable
public abstract byte[] getEncoded() throws CRLException
CRLException
- encode ¿¡·¯°¡ ¹ß»ýÇßÀ» °æ¿ìpublic abstract void verify(PublicKey key) throws CRLException , NoSuchAlgorithmException , InvalidKeyException , NoSuchProviderException , SignatureException
key
- °ËÁõ¿¡ »ç¿ëÇÏ´Â PublicKey
NoSuchAlgorithmException
- ¼Æ÷Æ®µÇ¾î ÀÖÁö ¾ÊÀº ¼¸í ¾Ë°í¸®ÁòÀÇ °æ¿ì
InvalidKeyException
- ¹«È¿ÀÎ ¿¼èÀÇ °æ¿ì
NoSuchProviderException
- µðÆúÆ®ÀÇ ÇÁ·Î¹ÙÀÌ´õ°¡ ¾ø´Â °æ¿ì
SignatureException
- ¼¸í ¿¡·¯ÀÇ °æ¿ì
CRLException
- encode ¿¡·¯ÀÇ °æ¿ìpublic abstract void verify(PublicKey key, String sigProvider) throws CRLException , NoSuchAlgorithmException , InvalidKeyException , NoSuchProviderException , SignatureException
key
- °ËÁõ¿¡ »ç¿ëÇÏ´Â PublicKeysigProvider
- ¼¸í ÇÁ·Î¹ÙÀÌ´õÀÇ À̸§
NoSuchAlgorithmException
- ¼Æ÷Æ®µÇ¾î ÀÖÁö ¾ÊÀº ¼¸í ¾Ë°í¸®ÁòÀÇ °æ¿ì
InvalidKeyException
- ¹«È¿ÀÎ ¿¼èÀÇ °æ¿ì
NoSuchProviderException
- ¹«È¿ÀÎ ÇÁ·Î¹ÙÀÌ´õÀÇ °æ¿ì
SignatureException
- ¼¸í ¿¡·¯ÀÇ °æ¿ì
CRLException
- encode ¿¡·¯ÀÇ °æ¿ìpublic abstract int getVersion()
version
(¹öÁ¯ ¹øÈ£) Ä¡¸¦ ÃëµæÇÕ´Ï´Ù. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
version Version OPTIONAL, -- if present, must be v2Version ::= INTEGER { v1(0), v2(1), v3(2) } -- v3 does not apply to CRLs but appears for consistency -- with definition of Version for certs
public abstract Principal getIssuerDN()
issuer
(¹ßÇàÀÚ ½Äº°¸í) Ä¡¸¦ ÃëµæÇÕ´Ï´Ù. ¹ßÇàÀÚ¸íÀº CRL ÀÇ ¼¸í°ú ¹ßÇàÀ» ÇàÇÑ ¿£Æ¼Æ¼¸¦ ½Äº°ÇÕ´Ï´Ù.
¹ßÇàÀÚ¸í Çʵ忡´Â X. 500 ½Äº°¸í (DN)ÀÌ ÀúÀåµË´Ï´Ù. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
issuer Name Name ::= CHOICE { RDNSequence } RDNSequence ::= SEQUENCE OF RelativeDistinguishedName RelativeDistinguishedName ::= SET OF AttributeValueAssertion AttributeValueAssertion ::= SEQUENCE { AttributeType, AttributeValue } AttributeType ::= OBJECT IDENTIFIER AttributeValue ::= ANY
Name
¿¡´Â ±¹¸íµîÀÇ ¼Ó¼º°ú °Å±â¿¡ ´ëÀÀÇÏ´Â US µîÀÇ °ªÀ¸·ÎºÎÅÍ µÇ´Â °èÃþÀûÀÎ À̸§À» ±â¼úÇÕ´Ï´Ù. AttributeValue
ÄÄÆÛ³ÍÆ®ÀÇ ÇüÅ´ AttributeType
¿¡ ÀÇÇØ Á¤ÇØÁý´Ï´Ù. ÀϹÝÀûÀ¸·Î´Â directoryString
ÀÔ´Ï´Ù. directoryString
Àº Åë»ó PrintableString
,TeletexString
,UniversalString
ÀÇ ¾î¶² °ÍÀΰ¡ÀÔ´Ï´Ù.
public X500Principal getIssuerX500Principal()
X500Principal
·Î¼ µ¹·ÁÁÝ´Ï´Ù.
X500Principal
public abstract Date getThisUpdate()
thisUpdate
ÀÇ ÀÏÀÚ¸¦ ÃëµæÇÕ´Ï´Ù. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
thisUpdate ChoiceOfTime ChoiceOfTime ::= CHOICE { utcTime UTCTime, generalTime GeneralizedTime }
thisUpdate
ÀÇ ÀÏÀÚpublic abstract Date getNextUpdate()
nextUpdate
ÀÇ ÀÏÀÚ¸¦ ÃëµæÇÕ´Ï´Ù.
nextUpdate
ÀÇ ÀÏÀÚ. ÀÏÀÚ°¡ ¾ø´Â °æ¿ì´Â nullpublic abstract X509CRLEntry getRevokedCertificate(BigInteger serialNumber)
serialNumber
- CRL ÀÔ·ÂÀÌ ÂüÁ¶µÇ´Â Áõ¸í¼ÀÇ ½Ã¸®¾ó ¹øÈ£
X509CRLEntry
public abstract Set getRevokedCertificates()
X509CRLEntry
public abstract byte[] getTBSCertList() throws CRLException
tbsCertList
¸¦ CRL ·ÎºÎÅÍ ÃëµæÇÕ´Ï´Ù. ÀÌ Á¤º¸´Â ¼¸íÀ» °³º°ÀûÀ¸·Î °ËÁõÇϱâ À§Çؼ »ç¿ëµË´Ï´Ù.
CRLException
- encode ¿¡·¯°¡ ¹ß»ýÇßÀ» °æ¿ìpublic abstract byte[] getSignature()
signature
Ä¡ (»ýÀÇ ÇüźøÆ®)¸¦ ÃëµæÇÕ´Ï´Ù. ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.
signature BIT STRING
public abstract String getSigAlgName()
signatureAlgorithm AlgorithmIdentifierAlgorithmIdentifier ::= SEQUENCE { algorithm OBJECT IDENTIFIER, parameters ANY DEFINED BY algorithm OPTIONAL } -- contains a value of the type -- registered for use with the -- algorithm object identifier value
¾Ë°í¸®Áò¸íÀº algorithm
OID ij¸¯ÅÍ ¶óÀÎÀ¸·ÎºÎÅÍ ÆÇÁ¤µË´Ï´Ù.
public abstract String getSigAlgOID()
°ü·ÃÇÏ´Â ASN. 1 Á¤ÀÇ¿¡ ´ëÇØ¼´Â getSigAlgName() #getSigAlgName
¸¦ ÂüÁ¶ÇØ ÁÖ¼¼¿ä.
public abstract byte[] getSigAlgParams()
AlgorithmParameters
¸¦ »ç¿ëÇØ,getSigAlgName() #getSigAlgName
¿¡ ÀÇÇØ µ¹·ÁÁÖ¾îÁö´Â À̸§À» »ç¿ëÇØ ÀνºÅϽº¸¦ »ý¼ºÇÕ´Ï´Ù.
°ü·ÃÇÏ´Â ASN. 1 Á¤ÀÇ¿¡ ´ëÇØ¼´Â getSigAlgName() #getSigAlgName
¸¦ ÂüÁ¶ÇØ ÁÖ¼¼¿ä.
|
JavaTM 2 Platform Std. Ed. v1. 4.0 |
||||||||||
ÀüÀÇ Å¬·¡½º ´ÙÀ½ÀÇ Å¬·¡½º | ÇÁ·¹ÀÓ ÀÖ¾î ÇÁ·¹ÀÓ ¾øÀ½ | ||||||||||
°³¿ä: »óÀÚ | Çʵå | constructor | ¸Þ¼Òµå | »ó¼¼: Çʵå | constructor | ¸Þ¼Òµå |
Java, Java 2 D, ¹× JDBC ´Â ¹Ì±¹ ¹× ±× ¿ÜÀÇ ³ª¶ó¿¡ ÀÖ¾î¼ÀÇ ¹Ì±¹ Sun Microsystems, Inc. ÀÇ »óÇ¥ ȤÀº µî·Ï»óÇ¥ÀÔ´Ï´Ù.
Copyright 1993-2002 Sun Microsystems, Inc. 901 San Antonio Road
Palo Alto, California, 94303, U.S.A. All Rights Reserved.