Speak now
Please Wait Image Converting Into Text...
Embark on a journey of knowledge! Take the quiz and earn valuable credits.
Challenge yourself and boost your learning! Start the quiz now to earn credits.
Unlock your potential! Begin the quiz, answer questions, and accumulate credits along the way.
General Tech QA/Testing 2 years ago
Posted on 16 Aug 2022, this text provides information on QA/Testing related to General Tech. Please note that while accuracy is prioritized, the data presented might not be entirely correct or up-to-date. This information is offered for general knowledge and informational purposes only, and should not be considered as a substitute for professional advice.
Turn Your Knowledge into Earnings.
I implement a SAML SP in Java.In order to to validate the certificate of the SAML response,I extract the X509Certificate element from the SAML response and validate it against a Java keystore file which I uploaded the IDP certificate to in advance.I use the following code to validate the certificate:
X509Certificate certFromResponse = //extract from SAML response KeyStore keyStore = getKS(); PKIXParameters params = new PKIXParameters(keyStore); params.setRevocationEnabled(false); CertPath certPath = certificateFactory.generateCertPath(Arrays.asList(certFromResponse)); CertPathValidator certPathValidator = CertPathValidator.getInstance(CertPathValidator.getDefaultType()); CertPathValidatorResult result = certPathValidator.validate(certPath, params);
This works fine for certificates which are root CA.When the certificate has a certification path, the validation fails.A possible way to handle it is to manually upload all the certificates from the path into the JKS filewith different aliases, and then extract them into a list like this:
List<Certificate> certs = new ArrayList<Certificate>(); certs.add(certFromResponse); if (keyStore.getCertificate("ALIAS_CA_1") != null) { certs.add(keyStore.getCertificate("ALIAS_CA_1")); } if (keyStore.getCertificate("ALIAS_CA_2") != null) { certs.add(keyStore.getCertificate("ALIAS_CA_2"); } ... CertPath certPath = certificateFactory.generateCertPath(certs);
Is there a more straightforward way to do it? Is it possible to extract the certification path from the certificate Itself?
Thanks!
It seems that the PKIXParameters extracts the certification path automatically, so no need to do it manually.All we have to do is uploading all certificates to the keystore.
No matter what stage you're at in your education or career, TuteeHub will help you reach the next level that you're aiming for. Simply,Choose a subject/topic and get started in self-paced practice sessions to improve your knowledge and scores.
General Tech 9 Answers
General Tech 7 Answers
General Tech 3 Answers
General Tech 2 Answers
Ready to take your education and career to the next level? Register today and join our growing community of learners and professionals.