Get the App
SLTechnology News&Howtos  ›  Development  › 

How to obtain TLS client Certificate in Spring Integration

Shulou Source: shulou.com Published: 2022-06-01 11:47:25 10月02日 Update

Editor to share with you how to obtain TLS client certificate in Spring Integration, I believe most people do not know much about it, so share this article for your reference, I hope you can learn a lot after reading this article, let's go to know it!

Spring Integration is a very powerful and extensible inheritance framework. But sometimes it's not easy to get some of the information you need. As far as I'm concerned-certificates that can be used to authenticate each other in TLS (TLS-based Syslog) connections. You have a Java method to receive messages, and ideally you want to get the certificate chain used by the client to authenticate it (for example, you may need to extract CN).

Fortunately, Spring Integration is flexible. It can do it, but it's a little confusing. I'll use the XML notation, but it can also be done through Java configuration.

SslContextSupport is usually org.springframework.integration.ip.tcp.connection.DefaultTcpSSLContextSupport or a custom implementation (for example, if you want to use the "blind" trust store)

Then you need these two classes. You can view them in their respective registries: TLSSyslogInterceptorFactory and TLSMUTAUALNIOCONNECTIONSUPPORT.

What are these classes for? The SSL engine "wantClientAuth" option set by the TLSMutualNioConnectionSupport class. There is another option-- "needClientAuth", which is used for client-side authentication, not just supporting it. Depending on the use case, you can use one or the other.

You can then obtain the certificate in the handler method in the following ways:

Certificate [] certificates = (Certificate []) message.getHeaders (). Get (TLSSyslogInterceptorFactory.TLS_CLIENT_CERTIFICATES); this is all the content of the article "how to obtain a TLS client Certificate in Spring Integration". Thank you for reading! I believe we all have a certain understanding, hope to share the content to help you, if you want to learn more knowledge, welcome to follow the industry information channel!

Tags: Certificates clients clients articles identity authentication content can be passed methods powerful inexplicable lucky not easy not only not much two information most engines situations Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Huawei OPPO Reno Xiaomi NVidia MySQL