JavaTM 2 Platform
Standard Ed. 5.0

java.security.cert
Ŭ·¡½º TrustAnchor

java.lang.Object 
  »óÀ§¸¦ È®Àå java.security.cert.TrustAnchor

public class TrustAnchor
extends Object

Æ®·¯½ºÆ® ¿¨Ä¿, ¶Ç´Â °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â ÀÎÁõ¼­ ¹ßÇà±¹ (CA)ÀÔ´Ï´Ù.

ÀÌ Å¬·¡½º´Â ¡¸°¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA¡¹¸¦ ³ªÅ¸³», X. 509 ÀÎÁõ¼­ ÆнºÀÇ Å¸´ç¼ºÀ» °Ë»çÇÏ´Â Æ®·¯½ºÆ® ¿¨Ä¿·Î¼­ »ç¿ëÇÕ´Ï´Ù. ¹«¾ùº¸´Ù ½Å·ÚÇÒ ¼ö ÀÖ´Â CA¿¡´Â CA °ø°³Å°, CA À̸§, ±×¸®°í ±× Å°¸¦ »ç¿ëÇØ °Ë»çµÈ Æнº¼¼Æ®¿¡ ´ëÇÑ Á¦¾àÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. ÀÌ·¯ÇÑ ÆĶó¹ÌÅÍ´Â ½Å·ÚµÈ X509Certificate Çü½ÄÀΰ¡ °³º°ÀÇ ÆĶó¹ÌÅͷμ­ ÁöÁ¤µË´Ï´Ù.

º´Çà ¾×¼¼½º

¸ðµç TrustAnchor°´Ã¼´Â ºÒº¯À¸·Î thread¿¡ ´ëÇؼ­ ¾ÈÀüÇÏÁö ¾ÊÀ¸¸é ¾ÈµË´Ï´Ù. Áï, ÀÌ Å¬·¡½º¿¡¼­ Á¤ÀÇµÈ ¸Þ¼­µå´Â ¾Ç¿µÇâÀ» ÁÖ´Â ÀÏ ¾øÀÌ, º¹¼ö thread°¡ º´ÇàÇØ ´ÜÀÏ TrustAnchor °´Ã¼ (¶Ç´Â 1°³ ÀÌ»ó)·Î È£ÃâÇÒ ¼ö ÀÖ½À´Ï´Ù . TrustAnchor°´Ã¼´Â ºÒº¯À¸·Î ÇÑÆí thread¿¡ ´ëÇؼ­ ¾ÈÀüÇÏÁö ¾ÊÀ¸¸é ¾È µÇ±â ¶§¹®¿¡ ¾×¼¼½ºÀÇ µ¿±âÀÇ °ÆÁ¤À» ÇÏ´Â ÀÏ ¾øÀÌ, ´Ù¾çÇÑ Äڵ忡 ÀÌ °´Ã¼¸¦ °Ç³×ÁÙ ¼ö°¡ ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº ÀÌ Å¬·¡½ºÀÇ ¸ðµç public Çʵå¿Í ¸Þ¼­µå, ±×¸®°í ¼­ºê Ŭ·¡½º¿¡¼­ Ãß°¡ ¶Ç´Â ¿À¹ö¶óÀ̵å(override) µÈ public Çʵå¿Í ¸Þ¼­µå¿¡ µé¾î¸ÂÀ¾´Ï´Ù.

µµÀÔµÈ ¹öÀü :
1.4
°ü·Ã Ç׸ñ:
PKIXParameters.PKIXParameters(Set), PKIXBuilderParameters.PKIXBuilderParameters(Set, CertSelector)

»ý¼ºÀÚ °³¿ä
TrustAnchor (String  caName, PublicKey  pubKey, byte[] nameConstraints)
          ½Äº°¸í°ú °ø°³Å°¶ó°íµµ¿Í µµ ½Å·ÚÇÒ ¼ö ÀÖ´Â CA°¡ °¡¸®Å°´Â TrustAnchor ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù.
TrustAnchor (X500Principal  caPrincipal, PublicKey  pubKey, byte[] nameConstraints)
          X500Principal¿Í °ø°³Å°¶ó°íµµ¿Í µµ ½Å·ÚÇÒ ¼ö ÀÖ´Â CA°¡ °¡¸®Å°´Â TrustAnchor ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù.
TrustAnchor (X509Certificate  trustedCert, byte[] nameConstraints)
          ÁöÁ¤ÇÑ X509Certificate¿Í À̸§ Á¦¾à (»ý·« °¡´É)À¸·Î TrustAnchor ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù.
 
¸Þ¼­µå °³¿ä
 X500Principal getCA ()
          °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA X500Principal·Î¼­ÀÇ À̸§À» ¸®ÅÏÇÕ´Ï´Ù.
 String getCAName ()
          RFC 2253 String Çü½Ä¿¡ ÇÑ, °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA À̸§À» ¸®ÅÏÇÕ´Ï´Ù.
 PublicKey getCAPublicKey ()
          °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA °ø°³Å°¸¦ ¸®ÅÏÇÕ´Ï´Ù.
 byte[] getNameConstraints ()
          À̸§ Á¦¾àÀÇ ÆĶó¹ÌÅ͸¦ ¸®ÅÏÇÕ´Ï´Ù.
 X509Certificate getTrustedCert ()
          °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA ÀÎÁõ¼­¸¦ ¸®ÅÏÇÕ´Ï´Ù.
 String toString ()
          TrustAnchor¸¦ ¼³¸íÇÏ´Â ¼­½Ä ÷ºÎ ij¸¯ÅÍ ¶óÀÎÀ» ¸®ÅÏÇÕ´Ï´Ù.
 
Ŭ·¡½º java.lang. Object ·ÎºÎÅÍ »ó¼ÓµÈ ¸Þ¼­µå
clone, equals, finalize, getClass, hashCode, notify, notifyAll, wait, wait, wait
 

»ý¼ºÀÚ »ó¼¼

TrustAnchor

public TrustAnchor(X509Certificate  trustedCert,
                   byte[] nameConstraints)
ÁöÁ¤ÇÑ X509Certificate¿Í À̸§ Á¦¾à (»ý·« °¡´É)À¸·Î TrustAnchor ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù. À̸§ Á¦¾àÀº X. 509 ÀÎÁõ¼­ ÆнºÀÇ Å¸´ç¼ºÀ» °Ë»çÇÒ ¶§ÀÇ Á¦¾àÀ» Ãß°¡Çϱâ À§Çؼ­ »ç¿ëµË´Ï´Ù.

À̸§ Á¦¾àÀº ¹ÙÀÌÆ® ¹è¿­·Î ÁöÁ¤µË´Ï´Ù. ÀÌ ¹ÙÀÌÆ® ¹è¿­¿¡´Â RFC 2459 ·Î X. 509 ·Î Á¤Àǵǰí ÀÖ´Â NameConstraints ±¸Á¶Ã¼¿¡ ÀÖ´Â °Í °°Àº À̸§ Á¦¾àÀÇ DER encode Çü½ÄÀÌ Æ÷ÇÔµÇÁö ¾ÊÀ¸¸é ¾ÈµË´Ï´Ù. NameConstraints ±¸Á¶Ã¼ÀÇ ASN. 1 Á¤ÀÇ´Â ´ÙÀ½°ú °°½À´Ï´Ù.


  NameConstraints ::= SEQUENCE {
       permittedSubtrees       [0]     GeneralSubtrees OPTIONAL,
       excludedSubtrees        [1]     GeneralSubtrees OPTIONAL }

  GeneralSubtrees ::= SEQUENCE SIZE (1..MAX) OF GeneralSubtree

  GeneralSubtree ::= SEQUENCE {
       base                    GeneralName,
       minimum         [0]     BaseDistance DEFAULT 0,
       maximum         [1]     BaseDistance OPTIONAL }

  BaseDistance ::= INTEGER (0..MAX)

  GeneralName ::= CHOICE {
       otherName                       [0]     OtherName,
       rfc822Name                      [1]     IA5String,
       dNSName                         [2]     IA5String,
       x400Address                     [3]     ORAddress,
       directoryName                   [4]     Name,
       ediPartyName                    [5]     EDIPartyName,
       uniformResourceIdentifier       [6]     IA5String,
       iPAddress                       [7]     OCTET STRING,
       registeredID                    [8]     OBJECT IDENTIFIER}
 

ÀÌÈÄÀÇ º¯°æÀ¸·ÎºÎÅÍ º¸È£Çϱâ À§Çؼ­ Á¦°øµÇ´Â À̸§ Á¦¾àÀÇ ¹ÙÀÌÆ® ¹è¿­Àº º¹Á¦µÇ°í ÀÖ½À´Ï´Ù.

ÆĶó¹ÌÅÍ:
trustedCert - ½Å·ÚµÈ X509Certificate
nameConstraints - À̸§ Á¦¾àÀ» üũÇϱâ À§Çؼ­ »ç¿ëµÇ´Â NameConstraints È®Àå Á¤º¸¸¦ ASN. 1 DER ·Î encode ÇÑ °ªÀ» Æ÷ÇÔÇÑ ¹ÙÀÌÆ® ¹è¿­. È®Àå Á¤º¸ÀÇ °ª¸¸ÀÌ Æ÷ÇԵǾî OID ³ª À§±âÀÇ Á¤µµ¸¦ ³ªÅ¸³»´Â Ç÷¡±×´Â Æ÷ÇÔµÇÁö ¾Ê´Â´Ù. ÀÌ ÆĶó¹ÌÅ͸¦ ¹«½ÃÇÏ·Á¸é nullÀ» ÁöÁ¤ÇÑ´Ù
¿¹¿Ü:
IllegalArgumentException - À̸§ Á¦¾àÀÌ º¹È£È­ ÇÒ ¼ö ¾ø´Â °æ¿ì
NullPointerException - ÁöÁ¤ÇÑ X509Certificate°¡ nullÀÎ °æ¿ì

TrustAnchor

public TrustAnchor(X500Principal  caPrincipal,
                   PublicKey  pubKey,
                   byte[] nameConstraints)
X500Principal¿Í °ø°³Å°¶ó°íµµ¿Í µµ ½Å·ÚÇÒ ¼ö ÀÖ´Â CA°¡ °¡¸®Å°´Â TrustAnchor ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù. À̸§ Á¦¾àÀº »ý·« °¡´ÉÇÑ ÆĶó¹ÌÅÍ·Î X. 509 ÀÎÁõ¼­ ÆнºÀÇ Å¸´ç¼ºÀ» °Ë»çÇÒ ¶§ÀÇ Á¦¾àÀ» Ãß°¡Çϱâ À§Çؼ­ »ç¿ëµË´Ï´Ù.

À̸§ Á¦¾àÀº ¹ÙÀÌÆ® ¹è¿­·Î ÁöÁ¤µË´Ï´Ù. ÀÌ ¹ÙÀÌÆ® ¹è¿­¿¡´Â RFC 2459 ·Î X. 509 ·Î Á¤Àǵǰí ÀÖ´Â NameConstraints ±¸Á¶Ã¼¿¡ ÀÖ´Â °Í °°Àº À̸§ Á¦¾àÀÇ DER encode Çü½ÄÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. NameConstraints ±¸Á¶Ã¼ÀÇ ASN. 1 ÁöÁ¤Àº, TrustAnchor(X509Certificate trustedCert, byte[] nameConstraints) ·Î ¼³¸íÇÏ°í ÀÖ½À´Ï´Ù.

ÀÌÈÄÀÇ º¯°æÀ¸·ÎºÎÅÍ º¸È£Çϱâ À§Çؼ­ ¿©±â¼­ Á¦°øµÇ°í ÀÖ´Â À̸§ Á¦¾àÀÇ ¹ÙÀÌÆ® ¹è¿­Àº º¹Á¦µÇ°í ÀÖ½À´Ï´Ù.

ÆĶó¹ÌÅÍ:
caPrincipal - °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA X500Principal·Î¼­ÀÇ À̸§
pubKey - °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA °ø°³Å°
nameConstraints - À̸§ Á¦¾àÀ» üũÇϱâ À§Çؼ­ »ç¿ëµÇ´Â NameConstraints È®Àå Á¤º¸¸¦ ASN. 1 DER ·Î encode ÇÑ °ªÀ» Æ÷ÇÔÇÑ ¹ÙÀÌÆ® ¹è¿­. È®Àå Á¤º¸ÀÇ °ª¸¸ÀÌ Æ÷ÇԵǾî OID ³ª À§±âÀÇ Á¤µµ¸¦ ³ªÅ¸³»´Â Ç÷¡±×´Â Æ÷ÇÔµÇÁö ¾Ê´Â´Ù. ÀÌ ÆĶó¹ÌÅ͸¦ ¹«½ÃÇÏ·Á¸é nullÀ» ÁöÁ¤ÇÑ´Ù
¿¹¿Ü:
NullPointerException - ÁöÁ¤µÈ caPrincipal ÆĶó¹ÌÅͳª pubKey ÆĶó¹ÌÅÍ°¡ nullÀÎ °æ¿ì
µµÀÔµÈ ¹öÀü :
1.5

TrustAnchor

public TrustAnchor(String  caName,
                   PublicKey  pubKey,
                   byte[] nameConstraints)
½Äº°¸í°ú °ø°³Å°¶ó°íµµ¿Í µµ ½Å·ÚÇÒ ¼ö ÀÖ´Â CA°¡ °¡¸®Å°´Â TrustAnchor ÀνºÅϽº¸¦ ÀÛ¼ºÇÕ´Ï´Ù. À̸§ Á¦¾àÀº »ý·« °¡´ÉÇÑ ÆĶó¹ÌÅÍ·Î X. 509 ÀÎÁõ¼­ ÆнºÀÇ Å¸´ç¼ºÀ» °Ë»çÇÒ ¶§ÀÇ Á¦¾àÀ» Ãß°¡Çϱâ À§Çؼ­ »ç¿ëµË´Ï´Ù.

À̸§ Á¦¾àÀº ¹ÙÀÌÆ® ¹è¿­·Î ÁöÁ¤µË´Ï´Ù. ÀÌ ¹ÙÀÌÆ® ¹è¿­¿¡´Â RFC 2459 ·Î X. 509 ·Î Á¤Àǵǰí ÀÖ´Â NameConstraints ±¸Á¶Ã¼¿¡ ÀÖ´Â °Í °°Àº À̸§ Á¦¾àÀÇ DER encode Çü½ÄÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. NameConstraints ±¸Á¶Ã¼ÀÇ ASN. 1 ÁöÁ¤Àº, TrustAnchor(X509Certificate trustedCert, byte[] nameConstraints) ·Î ¼³¸íÇÏ°í ÀÖ½À´Ï´Ù.

ÀÌÈÄÀÇ º¯°æÀ¸·ÎºÎÅÍ º¸È£Çϱâ À§Çؼ­ ¿©±â¼­ Á¦°øµÇ°í ÀÖ´Â À̸§ Á¦¾àÀÇ ¹ÙÀÌÆ® ¹è¿­Àº º¹Á¦µÇ°í ÀÖ½À´Ï´Ù.

ÆĶó¹ÌÅÍ:
caName - RFC 2253 String Çü½Ä¿¡ ÇÑ, °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA X. 500 ½Äº°¸í
pubKey - °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA °ø°³Å°
nameConstraints - À̸§ Á¦¾àÀ» üũÇϱâ À§Çؼ­ »ç¿ëµÇ´Â NameConstraints È®Àå Á¤º¸¸¦ ASN. 1 DER ·Î encode ÇÑ °ªÀ» Æ÷ÇÔÇÑ ¹ÙÀÌÆ® ¹è¿­. È®Àå Á¤º¸ÀÇ °ª¸¸ÀÌ Æ÷ÇԵǾî OID ³ª À§±âÀÇ Á¤µµ¸¦ ³ªÅ¸³»´Â Ç÷¡±×´Â Æ÷ÇÔµÇÁö ¾Ê´Â´Ù. ÀÌ ÆĶó¹ÌÅ͸¦ ¹«½ÃÇÏ·Á¸é nullÀ» ÁöÁ¤ÇÑ´Ù
¿¹¿Ü:
IllegalArgumentException - ÁöÁ¤ÇÑ caName ÆĶó¹ÌÅÍ°¡ °ø¹é (caName.length() == 0)ÀÎÁö, ±× Çü½ÄÀÌ ¿Ã¹Ù¸£Áö ¾ÊÀº °æ¿ì. ȤÀº À̸§ Á¦¾àÀÌ º¹È£È­ ÇÒ ¼ö ¾ø´Â °æ¿ì
NullPointerException - ÁöÁ¤µÈ caName ÆĶó¹ÌÅͳª pubKey ÆĶó¹ÌÅÍ°¡ nullÀÎ °æ¿ì
¸Þ¼­µåÀÇ »ó¼¼

getTrustedCert

public final X509Certificate  getTrustedCert()
¹«¾ùº¸´Ù ½Å·ÚÇÒ ¼ö ÀÖ´Â CA ÀÎÁõ¼­¸¦ ¸®ÅÏÇÕ´Ï´Ù.

¹Ýȯ°ª:
½Å·ÚÇÒ ¼ö ÀÖ´Â X509Certificate. Æ®·¯½ºÆ® ¿¨Ä¿¸¦ ½Å·ÚÇÒ ¼ö ÀÖ´Â ÀÎÁõ¼­ ·Î¼­ ÁöÁ¤µÇ¾î ÀÖÁö ¾ÊÀº °æ¿ì´Â null

getCA

public final X500Principal  getCA()
¹«¾ùº¸´Ù ½Å·ÚÇÒ ¼ö ÀÖ´Â CA X500Principal·Î¼­ÀÇ À̸§À» ¸®ÅÏÇÕ´Ï´Ù.

¹Ýȯ°ª:
°¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA X. 500 ½Äº°¸í. Æ®·¯½ºÆ® ¿¨Ä¿¸¦ ½Å·ÚÇÒ ¼ö ÀÖ´Â °ø°³Å°¿Í À̸§ ¶Ç´Â X500Principal Æä¾î·Î¼­ ÁöÁ¤µÇ¾î ÀÖÁö ¾ÊÀº °æ¿ì´Â null
µµÀÔµÈ ¹öÀü :
1.5

getCAName

public final String  getCAName()
RFC 2253 String Çü½Ä¿¡ ÇÑ, °¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA À̸§À» ¸®ÅÏÇÕ´Ï´Ù.

¹Ýȯ°ª:
°¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA X. 500 ½Äº°¸í. Æ®·¯½ºÆ® ¿¨Ä¿¸¦ ½Å·ÚÇÒ ¼ö ÀÖ´Â °ø°³Å°¿Í À̸§ ¶Ç´Â X500Principal Æä¾î·Î¼­ ÁöÁ¤µÇ¾î ÀÖÁö ¾ÊÀº °æ¿ì´Â null

getCAPublicKey

public final PublicKey  getCAPublicKey()
¹«¾ùº¸´Ù ½Å·ÚÇÒ ¼ö ÀÖ´Â CA °ø°³Å°¸¦ ¸®ÅÏÇÕ´Ï´Ù.

¹Ýȯ°ª:
°¡Àå ½Å·ÚÇÒ ¼ö ÀÖ´Â CA °ø°³Å°. Æ®·¯½ºÆ® ¿¨Ä¿¸¦ ½Å·ÚÇÒ ¼ö ÀÖ´Â °ø°³Å°¿Í À̸§ ¶Ç´Â X500Principal Æä¾î·Î¼­ ÁöÁ¤µÇ¾î ÀÖÁö ¾ÊÀº °æ¿ì´Â null

getNameConstraints

public final byte[] getNameConstraints()
À̸§ Á¦¾àÀÇ ÆĶó¹ÌÅ͸¦ ¸®ÅÏÇÕ´Ï´Ù. ÁöÁ¤ÇÑ À̸§ Á¦¾àÀº ÀÌ Æ®·¯½ºÆ® ¿¨Ä¿¿Í °ü·ÃÁöÀ» ¼ö ÀÖ°í ÀÖ¾î X. 509 ÀÎÁõ¼­ ÆнºÀÇ Å¸´ç¼ºÀ» °Ë»çÇÒ ¶§ÀÇ Á¦¾àÀ» Ãß°¡Çϱâ À§Çؼ­ »ç¿ëµË´Ï´Ù.

À̸§ Á¦¾àÀº ¹ÙÀÌÆ® ¹è¿­·Î¼­ ¸®Åϵ˴ϴ٠. ÀÌ ¹ÙÀÌÆ® ¹è¿­¿¡´Â RFC 2459 ·Î X. 509 ·Î Á¤Àǵǰí ÀÖ´Â NameConstraints ±¸Á¶Ã¼¿¡ ÀÖ´Â °Í °°Àº À̸§ Á¦¾àÀÇ DER encode Çü½ÄÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. NameConstraints ±¸Á¶Ã¼ÀÇ ASN. 1 ÁöÁ¤Àº, TrustAnchor(X509Certificate trustedCert, byte[] nameConstraints) ·Î ¼³¸íÇÏ°í ÀÖ½À´Ï´Ù.

ÀÌÈÄÀÇ º¯°æÀ¸·ÎºÎÅÍ º¸È£Çϱâ À§Çؼ­ ¸®ÅÏµÈ ¹ÙÀÌÆ® ¹è¿­ÀÇ º¹Á¦°¡ ÀÛ¼ºµË´Ï´Ù.

¹Ýȯ°ª:
À̸§ Á¦¾àÀ» üũÇϱâ À§Çؼ­ »ç¿ëµÇ´Â NameConstraints È®Àå Á¤º¸¸¦ ASN. 1 DER ·Î encode ÇÑ °ªÀ» Æ÷ÇÔÇÑ ¹ÙÀÌÆ® ¹è¿­. ¼³Á¤µÇ¾î ÀÖÁö ¾ÊÀº °æ¿ì´Â null

toString

public String  toString()
TrustAnchor¸¦ ¼³¸íÇÏ´Â ¼­½Ä ÷ºÎ ij¸¯ÅÍ ¶óÀÎÀ» ¸®ÅÏÇÕ´Ï´Ù.

¿À¹ö¶óÀ̵å(override):
Ŭ·¡½º Object ³»ÀÇ toString
¹Ýȯ°ª:
TrustAnchor¸¦ ¼³¸íÇÏ´Â ¼­½Ä ÷ºÎ ij¸¯ÅÍ ¶óÀÎ

JavaTM 2 Platform
Standard Ed. 5.0

Copyright 2004 Sun Microsystems, Inc. All rights reserved. Use is subject to license terms . Documentation Redistribution Policy µµ ÂüÁ¶ÇϽʽÿÀ.