public final class SslUtils extends Object
| Modifier and Type | Method and Description |
|---|---|
static KeyManagerFactory |
getDefaultKeyManagerFactory()
Returns the default key manager factory.
|
static KeyManagerFactory |
getDefaultKeyManagerFactory(Provider provider)
Returns the default key manager factory using the specified provider.
|
static TrustManagerFactory |
getDefaultTrustManagerFactory()
Returns the default trust manager factory.
|
static TrustManagerFactory |
getDefaultTrustManagerFactory(Provider provider)
Returns the default trust manager factory using the specified provider.
|
static KeyManagerFactory |
getPkixKeyManagerFactory()
Returns the PKIX key manager factory.
|
static TrustManagerFactory |
getPkixTrustManagerFactory()
Returns the PKIX trust manager factory.
|
static TrustManagerFactory |
getPkixTrustManagerFactory(Provider provider)
Returns the PKIX trust manager factory using the specified provider.
|
static SSLContext |
getSslContext()
Returns the SSL context for "SSL" algorithm.
|
static SSLContext |
getTlsSslContext()
Returns the SSL context for "TLS" algorithm.
|
static SSLContext |
getTlsSslContext(Provider provider)
Returns the SSL context for "TLS" algorithm using the specified provider.
|
static SSLContext |
initSslContext(SSLContext sslContext,
KeyStore trustStore,
TrustManagerFactory trustManagerFactory)
Initializes the SSL context to the trust managers supplied by the trust manager factory for the
given trust store.
|
static SSLContext |
initSslContext(SSLContext sslContext,
KeyStore trustStore,
TrustManagerFactory trustManagerFactory,
KeyStore mtlsKeyStore,
String mtlsKeyStorePassword,
KeyManagerFactory keyManagerFactory)
Beta Initializes the SSL context to the trust managers supplied by the trust manager factory for the given trust store, and to the key managers supplied by the key manager factory for the given key store. |
static HostnameVerifier |
trustAllHostnameVerifier()
Beta Returns a verifier that trusts all host names. |
static SSLContext |
trustAllSSLContext()
Beta Returns an SSL context in which all X.509 certificates are trusted. |
public static SSLContext getSslContext() throws NoSuchAlgorithmException
NoSuchAlgorithmExceptionpublic static SSLContext getTlsSslContext() throws NoSuchAlgorithmException
NoSuchAlgorithmExceptionpublic static SSLContext getTlsSslContext(Provider provider) throws NoSuchAlgorithmException
If a custom provider (e.g., Conscrypt) is configured, the context must be loaded from it to enable the provider's specific TLS parameters and curve groups (such as PQC).
provider - the security provider, or null to use the default JRE providerNoSuchAlgorithmExceptionpublic static TrustManagerFactory getDefaultTrustManagerFactory(Provider provider) throws NoSuchAlgorithmException
Aligning the trust manager factory's provider with the SSLContext's provider is necessary to prevent handshake failures. For example, if Conscrypt is used for the SSLContext but the default SunJSSE TrustManager is used, TLS 1.3 handshakes will fail with "Unknown authType: GENERIC" because SunJSSE does not recognize Conscrypt's "GENERIC" authentication type string.
provider - the security provider, or null to use the default JRE providerNoSuchAlgorithmExceptionpublic static TrustManagerFactory getPkixTrustManagerFactory(Provider provider) throws NoSuchAlgorithmException
Aligning the trust manager factory's provider with the SSLContext's provider is necessary to prevent handshake failures. For example, if Conscrypt is used for the SSLContext but the default SunJSSE TrustManager is used, TLS 1.3 handshakes will fail with "Unknown authType: GENERIC" because SunJSSE does not recognize Conscrypt's "GENERIC" authentication type string.
provider - the security provider, or null to use the default JRE providerNoSuchAlgorithmExceptionpublic static KeyManagerFactory getDefaultKeyManagerFactory(Provider provider) throws NoSuchAlgorithmException
provider - the security provider, or null to use the default JRE providerNoSuchAlgorithmExceptionpublic static TrustManagerFactory getDefaultTrustManagerFactory() throws NoSuchAlgorithmException
NoSuchAlgorithmExceptionpublic static TrustManagerFactory getPkixTrustManagerFactory() throws NoSuchAlgorithmException
NoSuchAlgorithmExceptionpublic static KeyManagerFactory getDefaultKeyManagerFactory() throws NoSuchAlgorithmException
NoSuchAlgorithmExceptionpublic static KeyManagerFactory getPkixKeyManagerFactory() throws NoSuchAlgorithmException
NoSuchAlgorithmException@CanIgnoreReturnValue public static SSLContext initSslContext(SSLContext sslContext, KeyStore trustStore, TrustManagerFactory trustManagerFactory) throws GeneralSecurityException
sslContext - SSL context (for example SSLContext.getInstance(java.lang.String))trustStore - key store for certificates to trust (for example SecurityUtils.getJavaKeyStore())trustManagerFactory - trust manager factory (for example getPkixTrustManagerFactory())GeneralSecurityException@Beta public static SSLContext initSslContext(SSLContext sslContext, KeyStore trustStore, TrustManagerFactory trustManagerFactory, KeyStore mtlsKeyStore, String mtlsKeyStorePassword, KeyManagerFactory keyManagerFactory) throws GeneralSecurityException
Beta sslContext - SSL context (for example SSLContext.getInstance(java.lang.String))trustStore - key store for certificates to trust (for example SecurityUtils.getJavaKeyStore())trustManagerFactory - trust manager factory (for example getPkixTrustManagerFactory())mtlsKeyStore - key store for client certificate and key to establish mutual TLSmtlsKeyStorePassword - password for mtlsKeyStore parameterkeyManagerFactory - key manager factory (for example getDefaultKeyManagerFactory())GeneralSecurityException@Beta public static SSLContext trustAllSSLContext() throws GeneralSecurityException
Beta Be careful! Disabling SSL certificate validation is dangerous and should only be done in testing environments.
GeneralSecurityException@Beta public static HostnameVerifier trustAllHostnameVerifier()
Beta Be careful! Disabling host name verification is dangerous and should only be done in testing environments.
Copyright © 2011–2026 Google. All rights reserved.