2 * Copyright 2001-2007 Internet2
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
8 * http://www.apache.org/licenses/LICENSE-2.0
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
18 * @file xmltooling/security/X509Credential.h
20 * Wraps an X.509-based Credential.
23 #if !defined(__xmltooling_x509cred_h__) && !defined(XMLTOOLING_NO_XMLSEC)
24 #define __xmltooling_x509cred_h__
26 #include <xmltooling/security/Credential.h>
27 #include <xmltooling/security/XSECCryptoX509CRL.h>
29 #include <xsec/enc/XSECCryptoX509.hpp>
31 namespace xmltooling {
34 * Wraps an X.509-based Credential.
36 class XMLTOOL_API X509Credential : public virtual Credential
42 virtual ~X509Credential() {}
45 * Bitmask constants for limiting resolution process inside a CredentialResolver.
53 * Gets an immutable collection of certificates in the entity's trust chain. The entity certificate is contained
54 * within this list. No specific ordering of the certificates is guaranteed.
56 * @return a certificate chain
58 virtual const std::vector<XSECCryptoX509*>& getEntityCertificateChain() const=0;
61 * Gets a CRL associated with the credential.
63 * @return CRL associated with the credential
65 virtual XSECCryptoX509CRL* getCRL() const=0;
68 * Extracts Subject CN and DNS/URI subjectAltNames from a certificate.
70 * @param x509 certificate to extract
71 * @param names a set to insert names into
73 static void extractNames(XSECCryptoX509* x509, std::set<std::string>& names);
77 #endif /* __xmltooling_x509cred_h__ */