2 * Copyright 2001-2007 Internet2
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
8 * http://www.apache.org/licenses/LICENSE-2.0
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
18 * @file xmltooling/security/X509Credential.h
20 * Wraps an X.509-based Credential.
23 #if !defined(__xmltooling_x509cred_h__) && !defined(XMLTOOLING_NO_XMLSEC)
24 #define __xmltooling_x509cred_h__
26 #include <xmltooling/security/Credential.h>
27 #include <xmltooling/security/XSECCryptoX509CRL.h>
29 #include <xsec/enc/XSECCryptoX509.hpp>
31 namespace xmltooling {
34 * Wraps an X.509-based Credential.
36 class XMLTOOL_API X509Credential : public virtual Credential
42 virtual ~X509Credential() {}
45 * Bitmask constants for limiting resolution process inside a CredentialResolver.
53 * Bitmask of supported KeyInfo content to generate.
56 KEYINFO_X509_CERTIFICATE = 4,
57 KEYINFO_X509_SUBJECTNAME = 8,
58 KEYINFO_X509_ISSUERSERIAL = 16
62 * Gets an immutable collection of certificates in the entity's trust chain. The entity certificate is contained
63 * within this list. No specific ordering of the certificates is guaranteed.
65 * @return a certificate chain
67 virtual const std::vector<XSECCryptoX509*>& getEntityCertificateChain() const=0;
72 * Gets a CRL associated with the credential.
74 * @return CRL associated with the credential
76 virtual XSECCryptoX509CRL* getCRL() const=0;
79 * Gets an immutable collection of all CRLs associated with the credential.
81 * @return CRLs associated with the credential
83 virtual const std::vector<XSECCryptoX509CRL*>& getCRLs() const=0;
87 * Gets the subject name of the first certificate in the chain.
89 * @return the Subject DN
91 virtual const char* getSubjectName() const=0;
94 * Gets the issuer name of the first certificate in the chain.
96 * @return the Issuer DN
98 virtual const char* getIssuerName() const=0;
101 * Gets the serial number of the first certificate in the chain.
103 * @return the serial number
105 virtual const char* getSerialNumber() const=0;
108 * Extracts properties like issuer and subject from the first certificate in the chain.
110 virtual void extract()=0;
114 #endif /* __xmltooling_x509cred_h__ */