public class BundleSignerCondition extends Object
The condition expressed using a single String that specifies a Distinguished Name (DN) chain to match bundle signers against. DN's are encoded using IETF RFC 2253. Usually signers use certificates that are issued by certificate authorities, which also have a corresponding DN and certificate. The certificate authorities can form a chain of trust where the last DN and certificate is known by the framework. The signer of a bundle is expressed as signers DN followed by the DN of its issuer followed by the DN of the next issuer until the DN of the root certificate authority. Each DN is separated by a semicolon.
A bundle can satisfy this condition if one of its signers has a DN chain that matches the DN chain used to construct this condition. Wildcards (`*') can be used to allow greater flexibility in specifying the DN chains. Wildcards can be used in place of DNs, RDNs, or the value in an RDN. If a wildcard is used for a value of an RDN, the value must be exactly "*" and will match any value for the corresponding type in that RDN. If a wildcard is used for a RDN, it must be the first RDN and will match any number of RDNs (including zero RDNs).
Modifier and Type | Method and Description |
---|---|
static Condition |
getCondition(Bundle bundle,
ConditionInfo info)
Constructs a Condition that tries to match the passed Bundle's location
to the location pattern.
|
public static Condition getCondition(Bundle bundle, ConditionInfo info)
bundle
- The Bundle being evaluated.info
- The ConditionInfo from which to construct the condition. The
ConditionInfo must specify one or two arguments. The first
argument of the ConditionInfo specifies the chain of distinguished
names pattern to match against the signer of the bundle. The
Condition is satisfied if the signer of the bundle matches the
pattern. The second argument of the ConditionInfo is optional. If
a second argument is present and equal to "!", then the
satisfaction of the Condition is negated. That is, the Condition
is satisfied if the signer of the bundle does NOT match the
pattern. If the second argument is present but does not equal "!",
then the second argument is ignored.Copyright © 2018 JBoss by Red Hat. All rights reserved.