diff --git a/spring-vault-core/src/main/java/org/springframework/vault/support/SslConfiguration.java b/spring-vault-core/src/main/java/org/springframework/vault/support/SslConfiguration.java index edff86ac..af61aadc 100644 --- a/spring-vault-core/src/main/java/org/springframework/vault/support/SslConfiguration.java +++ b/spring-vault-core/src/main/java/org/springframework/vault/support/SslConfiguration.java @@ -150,6 +150,20 @@ public class SslConfiguration { trustStorePassword, DEFAULT_KEYSTORE_TYPE)); } + /** + * Create a new {@link SslConfiguration} for the given {@link KeyStoreConfiguration + * trust store}. + * + @param trustStore must not be {@literal null}. + * @return a new {@link SslConfiguration} with {@link KeyStoreConfiguration trust + * store configuration} applied. + * @since 2.2 + * @see java.security.KeyStore + */ + public static SslConfiguration forTrustStore(KeyStoreConfiguration trustStore) { + return unconfigured().withTrustStore(trustStore); + } + /** * Create a new {@link SslConfiguration} for the given key store with the default * {@link KeyStore} type. @@ -181,7 +195,39 @@ public class SslConfiguration { */ public static SslConfiguration forKeyStore(Resource keyStore, @Nullable char[] keyStorePassword) { - return forKeyStore(keyStore, keyStorePassword, KeyConfiguration.unconfigured()); + return forKeyStore(new KeyStoreConfiguration(keyStore, keyStorePassword, + DEFAULT_KEYSTORE_TYPE), KeyConfiguration.unconfigured()); + } + + /** + * Create a new {@link SslConfiguration} for the given {@link KeyStoreConfiguration + * key store}. + * + * @param keyStore resource pointing to an existing key store, must not be + * {@literal null}. + * @return the created {@link SslConfiguration}. + * @since 2.2 + * @see java.security.KeyStore + */ + public static SslConfiguration forKeyStore(KeyStoreConfiguration keyStore) { + return forKeyStore(keyStore, KeyConfiguration.unconfigured()); + } + + /** + * Create a new {@link SslConfiguration} for the given {@link KeyStoreConfiguration + * key store} and {@link KeyConfiguration}. + * + * @param keyStore resource pointing to an existing key store, must not be + * {@literal null}. + * @param keyConfiguration the configuration for a specific key in + * {@code keyStoreConfiguration} to use. + * @return the created {@link SslConfiguration}. + * @since 2.2 + * @see java.security.KeyStore + */ + public static SslConfiguration forKeyStore(KeyStoreConfiguration keyStore, + KeyConfiguration keyConfiguration) { + return unconfigured().withKeyStore(keyStore, keyConfiguration); } /** @@ -246,8 +292,9 @@ public class SslConfiguration { * @return the created {@link SslConfiguration}. * @see java.security.KeyStore */ - public SslConfiguration create(Resource keyStore, @Nullable char[] keyStorePassword, - Resource trustStore, @Nullable char[] trustStorePassword) { + public static SslConfiguration create(Resource keyStore, + @Nullable char[] keyStorePassword, Resource trustStore, + @Nullable char[] trustStorePassword) { Assert.notNull(keyStore, "KeyStore must not be null"); Assert.isTrue(keyStore.exists(), @@ -458,11 +505,12 @@ public class SslConfiguration { * * @param resource resource referencing the key store, must not be {@literal null} * . - * @param storePassword key store password, must not be {@literal null}. + * @param storePassword key store password, may be {@literal null}. * @return the {@link KeyStoreConfiguration} for {@code resource}. * @since 2.0 */ - public static KeyStoreConfiguration of(Resource resource, char[] storePassword) { + public static KeyStoreConfiguration of(Resource resource, + @Nullable char[] storePassword) { return new KeyStoreConfiguration(resource, storePassword, DEFAULT_KEYSTORE_TYPE); } diff --git a/src/main/asciidoc/reference/client-support.adoc b/src/main/asciidoc/reference/client-support.adoc index c721b586..39d5a0b2 100644 --- a/src/main/asciidoc/reference/client-support.adoc +++ b/src/main/asciidoc/reference/client-support.adoc @@ -77,25 +77,25 @@ to set SSL settings only for Spring Vault. [source,java] ---- -SslConfiguration sslConfiguration = new SslConfiguration( <1> - new FileSystemResource("client-cert.jks"), "changeit".toCharArray(), - new FileSystemResource("truststore.jks"), "changeit".toCharArray()); +SslConfiguration sslConfiguration = SslConfiguration.create( <1> + new FileSystemResource("client-cert.jks"), "changeit".toCharArray(), + new FileSystemResource("truststore.jks"), "changeit".toCharArray()); SslConfiguration.forTrustStore(new FileSystemResource("keystore.jks"), <2> - "changeit") + "changeit".toCharArray()) SslConfiguration.forKeyStore(new FileSystemResource("keystore.jks"), <3> "changeit".toCharArray()) SslConfiguration.forKeyStore(new FileSystemResource("keystore.jks"), <4> - "changeit".toCharArray() + "changeit".toCharArray(), KeyConfiguration.of("key-password".toCharArray(), "my-key-alias")) ---- <1> Full configuration. <2> Configuring only trust store settings. <3> Configuring only key store settings. -<3> Configuring only key store settings with providing a key-configuration. +<4> Configuring only key store settings with providing a key-configuration. ==== Please note that providing `SslConfiguration` can be only