Class StrictSSLProtocolSocketFactory
- java.lang.Object
-
- org.apache.commons.httpclient.contrib.ssl.StrictSSLProtocolSocketFactory
-
- All Implemented Interfaces:
org.apache.commons.httpclient.protocol.ProtocolSocketFactory
,org.apache.commons.httpclient.protocol.SecureProtocolSocketFactory
public class StrictSSLProtocolSocketFactory extends Object implements org.apache.commons.httpclient.protocol.SecureProtocolSocketFactory
ASecureProtocolSocketFactory
that uses JSSE to create SSL sockets. It will also support host name verification to help preventing man-in-the-middle attacks. Host name verification is turned on by default but one will be able to turn it off, which might be a useful feature during development. Host name verification will make sure the SSL sessions server host name matches with the the host name returned in the server certificates "Common Name" field of the "SubjectDN" entry.- Author:
- Sebastian Hauer
DISCLAIMER: HttpClient developers DO NOT actively support this component. The component is provided as a reference material, which may be inappropriate for use without additional customization.
-
-
Constructor Summary
Constructors Constructor Description StrictSSLProtocolSocketFactory()
Constructor for StrictSSLProtocolSocketFactory.StrictSSLProtocolSocketFactory(boolean verifyHostname)
Constructor for StrictSSLProtocolSocketFactory.
-
Method Summary
All Methods Instance Methods Concrete Methods Modifier and Type Method Description Socket
createSocket(String host, int port)
Socket
createSocket(String host, int port, InetAddress clientHost, int clientPort)
Socket
createSocket(String host, int port, InetAddress localAddress, int localPort, org.apache.commons.httpclient.params.HttpConnectionParams params)
Attempts to get a new socket connection to the given host within the given time limit.Socket
createSocket(Socket socket, String host, int port, boolean autoClose)
boolean
equals(Object obj)
boolean
getHostnameVerification()
Gets the status of the host name verification flag.int
hashCode()
void
setHostnameVerification(boolean verifyHostname)
Set the host name verification flag.
-
-
-
Constructor Detail
-
StrictSSLProtocolSocketFactory
public StrictSSLProtocolSocketFactory(boolean verifyHostname)
Constructor for StrictSSLProtocolSocketFactory.- Parameters:
verifyHostname
- The host name verification flag. If set totrue
the SSL sessions server host name will be compared to the host name returned in the server certificates "Common Name" field of the "SubjectDN" entry. If these names do not match a Exception is thrown to indicate this. Enabling host name verification will help to prevent from man-in-the-middle attacks. If set tofalse
host name verification is turned off. Code sample:Protocol stricthttps = new Protocol( "https", new StrictSSLProtocolSocketFactory(true), 443); HttpClient client = new HttpClient(); client.getHostConfiguration().setHost("localhost", 443, stricthttps);
-
StrictSSLProtocolSocketFactory
public StrictSSLProtocolSocketFactory()
Constructor for StrictSSLProtocolSocketFactory. Host name verification will be enabled by default.
-
-
Method Detail
-
setHostnameVerification
public void setHostnameVerification(boolean verifyHostname)
Set the host name verification flag.- Parameters:
verifyHostname
- The host name verification flag. If set totrue
the SSL sessions server host name will be compared to the host name returned in the server certificates "Common Name" field of the "SubjectDN" entry. If these names do not match a Exception is thrown to indicate this. Enabling host name verification will help to prevent from man-in-the-middle attacks. If set tofalse
host name verification is turned off.
-
getHostnameVerification
public boolean getHostnameVerification()
Gets the status of the host name verification flag.- Returns:
- Host name verification flag. Either
true
if host name verification is turned on, orfalse
if host name verification is turned off.
-
createSocket
public Socket createSocket(String host, int port, InetAddress clientHost, int clientPort) throws IOException, UnknownHostException
- Specified by:
createSocket
in interfaceorg.apache.commons.httpclient.protocol.ProtocolSocketFactory
- Throws:
IOException
UnknownHostException
- See Also:
ProtocolSocketFactory.createSocket(java.lang.String,int,java.net.InetAddress,int)
-
createSocket
public Socket createSocket(String host, int port, InetAddress localAddress, int localPort, org.apache.commons.httpclient.params.HttpConnectionParams params) throws IOException, UnknownHostException, org.apache.commons.httpclient.ConnectTimeoutException
Attempts to get a new socket connection to the given host within the given time limit.This method employs several techniques to circumvent the limitations of older JREs that do not support connect timeout. When running in JRE 1.4 or above reflection is used to call Socket#connect(SocketAddress endpoint, int timeout) method. When executing in older JREs a controller thread is executed. The controller thread attempts to create a new socket within the given limit of time. If socket constructor does not return until the timeout expires, the controller terminates and throws an
ConnectTimeoutException
- Specified by:
createSocket
in interfaceorg.apache.commons.httpclient.protocol.ProtocolSocketFactory
- Parameters:
host
- the host name/IPport
- the port on the hostclientHost
- the local host name/IP to bind the socket toclientPort
- the port on the local machineparams
-Http connection parameters
- Returns:
- Socket a new socket
- Throws:
IOException
- if an I/O error occurs while creating the socketUnknownHostException
- if the IP address of the host cannot be determinedorg.apache.commons.httpclient.ConnectTimeoutException
-
createSocket
public Socket createSocket(String host, int port) throws IOException, UnknownHostException
- Specified by:
createSocket
in interfaceorg.apache.commons.httpclient.protocol.ProtocolSocketFactory
- Throws:
IOException
UnknownHostException
- See Also:
ProtocolSocketFactory.createSocket(java.lang.String,int)
-
createSocket
public Socket createSocket(Socket socket, String host, int port, boolean autoClose) throws IOException, UnknownHostException
- Specified by:
createSocket
in interfaceorg.apache.commons.httpclient.protocol.SecureProtocolSocketFactory
- Throws:
IOException
UnknownHostException
- See Also:
SecureProtocolSocketFactory.createSocket(java.net.Socket,java.lang.String,int,boolean)
-
-