Polishing.

Add factory methods accepting KeyStoreConfiguration. Fix nullability constraints. Make SslConfiguration.create(…) static.
Update reference documentation.

See gh-416.
This commit is contained in:
Mark Paluch
2019-05-01 23:08:52 +02:00
parent 0070b78d55
commit afdbdd67f1
2 changed files with 59 additions and 11 deletions

View File

@@ -150,6 +150,20 @@ public class SslConfiguration {
trustStorePassword, DEFAULT_KEYSTORE_TYPE)); trustStorePassword, DEFAULT_KEYSTORE_TYPE));
} }
/**
* Create a new {@link SslConfiguration} for the given {@link KeyStoreConfiguration
* trust store}.
*
@param trustStore must not be {@literal null}.
* @return a new {@link SslConfiguration} with {@link KeyStoreConfiguration trust
* store configuration} applied.
* @since 2.2
* @see java.security.KeyStore
*/
public static SslConfiguration forTrustStore(KeyStoreConfiguration trustStore) {
return unconfigured().withTrustStore(trustStore);
}
/** /**
* Create a new {@link SslConfiguration} for the given key store with the default * Create a new {@link SslConfiguration} for the given key store with the default
* {@link KeyStore} type. * {@link KeyStore} type.
@@ -181,7 +195,39 @@ public class SslConfiguration {
*/ */
public static SslConfiguration forKeyStore(Resource keyStore, public static SslConfiguration forKeyStore(Resource keyStore,
@Nullable char[] keyStorePassword) { @Nullable char[] keyStorePassword) {
return forKeyStore(keyStore, keyStorePassword, KeyConfiguration.unconfigured()); return forKeyStore(new KeyStoreConfiguration(keyStore, keyStorePassword,
DEFAULT_KEYSTORE_TYPE), KeyConfiguration.unconfigured());
}
/**
* Create a new {@link SslConfiguration} for the given {@link KeyStoreConfiguration
* key store}.
*
* @param keyStore resource pointing to an existing key store, must not be
* {@literal null}.
* @return the created {@link SslConfiguration}.
* @since 2.2
* @see java.security.KeyStore
*/
public static SslConfiguration forKeyStore(KeyStoreConfiguration keyStore) {
return forKeyStore(keyStore, KeyConfiguration.unconfigured());
}
/**
* Create a new {@link SslConfiguration} for the given {@link KeyStoreConfiguration
* key store} and {@link KeyConfiguration}.
*
* @param keyStore resource pointing to an existing key store, must not be
* {@literal null}.
* @param keyConfiguration the configuration for a specific key in
* {@code keyStoreConfiguration} to use.
* @return the created {@link SslConfiguration}.
* @since 2.2
* @see java.security.KeyStore
*/
public static SslConfiguration forKeyStore(KeyStoreConfiguration keyStore,
KeyConfiguration keyConfiguration) {
return unconfigured().withKeyStore(keyStore, keyConfiguration);
} }
/** /**
@@ -246,8 +292,9 @@ public class SslConfiguration {
* @return the created {@link SslConfiguration}. * @return the created {@link SslConfiguration}.
* @see java.security.KeyStore * @see java.security.KeyStore
*/ */
public SslConfiguration create(Resource keyStore, @Nullable char[] keyStorePassword, public static SslConfiguration create(Resource keyStore,
Resource trustStore, @Nullable char[] trustStorePassword) { @Nullable char[] keyStorePassword, Resource trustStore,
@Nullable char[] trustStorePassword) {
Assert.notNull(keyStore, "KeyStore must not be null"); Assert.notNull(keyStore, "KeyStore must not be null");
Assert.isTrue(keyStore.exists(), Assert.isTrue(keyStore.exists(),
@@ -458,11 +505,12 @@ public class SslConfiguration {
* *
* @param resource resource referencing the key store, must not be {@literal null} * @param resource resource referencing the key store, must not be {@literal null}
* . * .
* @param storePassword key store password, must not be {@literal null}. * @param storePassword key store password, may be {@literal null}.
* @return the {@link KeyStoreConfiguration} for {@code resource}. * @return the {@link KeyStoreConfiguration} for {@code resource}.
* @since 2.0 * @since 2.0
*/ */
public static KeyStoreConfiguration of(Resource resource, char[] storePassword) { public static KeyStoreConfiguration of(Resource resource,
@Nullable char[] storePassword) {
return new KeyStoreConfiguration(resource, storePassword, return new KeyStoreConfiguration(resource, storePassword,
DEFAULT_KEYSTORE_TYPE); DEFAULT_KEYSTORE_TYPE);
} }

View File

@@ -77,25 +77,25 @@ to set SSL settings only for Spring Vault.
[source,java] [source,java]
---- ----
SslConfiguration sslConfiguration = new SslConfiguration( <1> SslConfiguration sslConfiguration = SslConfiguration.create( <1>
new FileSystemResource("client-cert.jks"), "changeit".toCharArray(), new FileSystemResource("client-cert.jks"), "changeit".toCharArray(),
new FileSystemResource("truststore.jks"), "changeit".toCharArray()); new FileSystemResource("truststore.jks"), "changeit".toCharArray());
SslConfiguration.forTrustStore(new FileSystemResource("keystore.jks"), <2> SslConfiguration.forTrustStore(new FileSystemResource("keystore.jks"), <2>
"changeit") "changeit".toCharArray())
SslConfiguration.forKeyStore(new FileSystemResource("keystore.jks"), <3> SslConfiguration.forKeyStore(new FileSystemResource("keystore.jks"), <3>
"changeit".toCharArray()) "changeit".toCharArray())
SslConfiguration.forKeyStore(new FileSystemResource("keystore.jks"), <4> SslConfiguration.forKeyStore(new FileSystemResource("keystore.jks"), <4>
"changeit".toCharArray() "changeit".toCharArray(),
KeyConfiguration.of("key-password".toCharArray(), KeyConfiguration.of("key-password".toCharArray(),
"my-key-alias")) "my-key-alias"))
---- ----
<1> Full configuration. <1> Full configuration.
<2> Configuring only trust store settings. <2> Configuring only trust store settings.
<3> Configuring only key store settings. <3> Configuring only key store settings.
<3> Configuring only key store settings with providing a key-configuration. <4> Configuring only key store settings with providing a key-configuration.
==== ====
Please note that providing `SslConfiguration` can be only Please note that providing `SslConfiguration` can be only