1.1 --- /dev/null Thu Jan 01 00:00:00 1970 +0000 1.2 +++ b/mobile/android/thirdparty/ch/boye/httpclientandroidlib/conn/ssl/TrustStrategy.java Wed Dec 31 06:09:35 2014 +0100 1.3 @@ -0,0 +1,57 @@ 1.4 +/* 1.5 + * ==================================================================== 1.6 + * Licensed to the Apache Software Foundation (ASF) under one 1.7 + * or more contributor license agreements. See the NOTICE file 1.8 + * distributed with this work for additional information 1.9 + * regarding copyright ownership. The ASF licenses this file 1.10 + * to you under the Apache License, Version 2.0 (the 1.11 + * "License"); you may not use this file except in compliance 1.12 + * with the License. You may obtain a copy of the License at 1.13 + * 1.14 + * http://www.apache.org/licenses/LICENSE-2.0 1.15 + * 1.16 + * Unless required by applicable law or agreed to in writing, 1.17 + * software distributed under the License is distributed on an 1.18 + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY 1.19 + * KIND, either express or implied. See the License for the 1.20 + * specific language governing permissions and limitations 1.21 + * under the License. 1.22 + * ==================================================================== 1.23 + * 1.24 + * This software consists of voluntary contributions made by many 1.25 + * individuals on behalf of the Apache Software Foundation. For more 1.26 + * information on the Apache Software Foundation, please see 1.27 + * <http://www.apache.org/>. 1.28 + * 1.29 + */ 1.30 +package ch.boye.httpclientandroidlib.conn.ssl; 1.31 + 1.32 +import java.security.cert.CertificateException; 1.33 +import java.security.cert.X509Certificate; 1.34 + 1.35 +/** 1.36 + * A strategy to establish trustworthiness of certificates without consulting the trust manager 1.37 + * configured in the actual SSL context. This interface can be used to override the standard 1.38 + * JSSE certificate verification process. 1.39 + * 1.40 + * @since 4.1 1.41 + */ 1.42 +public interface TrustStrategy { 1.43 + 1.44 + /** 1.45 + * Determines whether the certificate chain can be trusted without consulting the trust manager 1.46 + * configured in the actual SSL context. This method can be used to override the standard JSSE 1.47 + * certificate verification process. 1.48 + * <p> 1.49 + * Please note that, if this method returns <code>false</code>, the trust manager configured 1.50 + * in the actual SSL context can still clear the certificate as trusted. 1.51 + * 1.52 + * @param chain the peer certificate chain 1.53 + * @param authType the authentication type based on the client certificate 1.54 + * @return <code>true</code> if the certificate can be trusted without verification by 1.55 + * the trust manager, <code>false</code> otherwise. 1.56 + * @throws CertificateException thrown if the certificate is not trusted or invalid. 1.57 + */ 1.58 + boolean isTrusted(X509Certificate[] chain, String authType) throws CertificateException; 1.59 + 1.60 +}