Class UnboundIDCertificatePlusPasswordBindRequest
java.lang.Object
com.unboundid.ldap.sdk.LDAPRequest
com.unboundid.ldap.sdk.BindRequest
com.unboundid.ldap.sdk.SASLBindRequest
com.unboundid.ldap.sdk.unboundidds.UnboundIDCertificatePlusPasswordBindRequest
- All Implemented Interfaces:
ReadOnlyLDAPRequest,Serializable
@ThreadSafety(level=NOT_THREADSAFE)
public final class UnboundIDCertificatePlusPasswordBindRequest
extends SASLBindRequest
This class provides support for an UnboundID-proprietary SASL mechanism that
provides multifactor authentication using the combination of a client
certificate (presented during SSL/TLS negotiation) and a static password.
The name for this SASL mechanism is "UNBOUNDID-CERTIFICATE-PLUS-PASSWORD". The SASL credentials consist simply of the static password for the user identified by the certificate, to make the SASL mechanism as easy as possible to use from other client APIs.
NOTE: This class, and other classes within the
com.unboundid.ldap.sdk.unboundidds package structure, are only
supported for use against Ping Identity, UnboundID, and
Nokia/Alcatel-Lucent 8661 server products. These classes provide support
for proprietary functionality or for external specifications that are not
considered stable or mature enough to be guaranteed to work in an
interoperable way with other types of LDAP servers.
The name for this SASL mechanism is "UNBOUNDID-CERTIFICATE-PLUS-PASSWORD". The SASL credentials consist simply of the static password for the user identified by the certificate, to make the SASL mechanism as easy as possible to use from other client APIs.
- See Also:
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringThe name for the UnboundID certificate plus password SASL mechanism.Fields inherited from class com.unboundid.ldap.sdk.SASLBindRequest
CRED_TYPE_SASLFields inherited from class com.unboundid.ldap.sdk.BindRequest
VERSION_ELEMENT -
Constructor Summary
ConstructorsConstructorDescriptionUnboundIDCertificatePlusPasswordBindRequest(byte[] password, Control... controls) Creates a new certificate plus password bind request with the provided information.UnboundIDCertificatePlusPasswordBindRequest(String password, Control... controls) Creates a new certificate plus password bind request with the provided information. -
Method Summary
Modifier and TypeMethodDescriptionCreates a new instance of this LDAP request that may be modified without impacting this request.Creates a new instance of this LDAP request that may be modified without impacting this request.intRetrieves the message ID for the last LDAP message sent using this request.Retrieves the password to use to authenticate as the user identified by the certificate.getRebindRequest(String host, int port) Retrieves a bind request that may be used to re-bind using the same credentials authentication type and credentials as previously used to perform the initial bind.Retrieves the name of the SASL mechanism used in this SASL bind request.protected BindResultprocess(LDAPConnection connection, int depth) Sends this bind request to the target server over the provided connection and returns the corresponding response.voidAppends a number of lines comprising the Java source code that can be used to recreate this request to the given list.voidtoString(StringBuilder buffer) Appends a string representation of this request to the provided buffer.Methods inherited from class com.unboundid.ldap.sdk.SASLBindRequest
getBindType, responseReceived, sendBindRequest, sendMessageMethods inherited from class com.unboundid.ldap.sdk.BindRequest
getOperationTypeMethods inherited from class com.unboundid.ldap.sdk.LDAPRequest
followReferrals, getControl, getControlList, getControls, getIntermediateResponseListener, getReferralConnector, getReferralConnectorInternal, getReferralDepth, getResponseTimeoutMillis, hasControl, hasControl, setFollowReferrals, setIntermediateResponseListener, setReferralConnector, setReferralDepth, setResponseTimeoutMillis, toString
-
Field Details
-
UNBOUNDID_CERT_PLUS_PW_MECHANISM_NAME
The name for the UnboundID certificate plus password SASL mechanism.- See Also:
-
-
Constructor Details
-
UnboundIDCertificatePlusPasswordBindRequest
public UnboundIDCertificatePlusPasswordBindRequest(@NotNull String password, @Nullable Control... controls) Creates a new certificate plus password bind request with the provided information.- Parameters:
password- The password to use to authenticate as user identified by the certificate. It must not benullor empty.controls- The set of controls to include in the bind request. It may benullor empty if no request controls are needed.
-
UnboundIDCertificatePlusPasswordBindRequest
public UnboundIDCertificatePlusPasswordBindRequest(@NotNull byte[] password, @Nullable Control... controls) Creates a new certificate plus password bind request with the provided information.- Parameters:
password- The password to use to authenticate as user identified by the certificate. It must not benullor empty.controls- The set of controls to include in the bind request. It may benullor empty if no request controls are needed.
-
-
Method Details
-
getPassword
Retrieves the password to use to authenticate as the user identified by the certificate.- Returns:
- The password to use to authenticate as the user identified by the certificate.
-
getSASLMechanismName
Retrieves the name of the SASL mechanism used in this SASL bind request.- Specified by:
getSASLMechanismNamein classSASLBindRequest- Returns:
- The name of the SASL mechanism used in this SASL bind request.
-
process
@NotNull protected BindResult process(@NotNull LDAPConnection connection, int depth) throws LDAPException Sends this bind request to the target server over the provided connection and returns the corresponding response.- Specified by:
processin classBindRequest- Parameters:
connection- The connection to use to send this bind request to the server and read the associated response.depth- The current referral depth for this request. It should always be one for the initial request, and should only be incremented when following referrals.- Returns:
- The bind response read from the server.
- Throws:
LDAPException- If a problem occurs while sending the request or reading the response.
-
getLastMessageID
Retrieves the message ID for the last LDAP message sent using this request.- Overrides:
getLastMessageIDin classSASLBindRequest- Returns:
- The message ID for the last LDAP message sent using this request, or -1 if it no LDAP messages have yet been sent using this request.
-
duplicate
Creates a new instance of this LDAP request that may be modified without impacting this request.- Specified by:
duplicatein interfaceReadOnlyLDAPRequest- Specified by:
duplicatein classBindRequest- Returns:
- A new instance of this LDAP request that may be modified without impacting this request.
-
duplicate
Creates a new instance of this LDAP request that may be modified without impacting this request. The provided controls will be used for the new request instead of duplicating the controls from this request.- Specified by:
duplicatein interfaceReadOnlyLDAPRequest- Specified by:
duplicatein classBindRequest- Parameters:
controls- The set of controls to include in the duplicate request.- Returns:
- A new instance of this LDAP request that may be modified without impacting this request.
-
getRebindRequest
@NotNull public UnboundIDCertificatePlusPasswordBindRequest getRebindRequest(@NotNull String host, int port) Retrieves a bind request that may be used to re-bind using the same credentials authentication type and credentials as previously used to perform the initial bind. This may be used in an attempt to automatically re-establish a connection that is lost, or potentially when following a referral to another directory instance.
It is recommended that all bind request types which implement this capability be implemented so that the elements needed to create a new request are immutable. If this is not done, then changes made to a bind request object may alter the authentication/authorization identity and/or credentials associated with that request so that a rebind request created from it will not match the original request used to authenticate on a connection.- Overrides:
getRebindRequestin classBindRequest- Parameters:
host- The address of the directory server to which the connection is established.port- The port of the directory server to which the connection is established.- Returns:
- A bind request that may be used to re-bind using the same
authentication type and credentials as previously used to perform
the initial bind, or
nullto indicate that automatic re-binding is not supported for this type of bind request.
-
toString
Appends a string representation of this request to the provided buffer.- Specified by:
toStringin interfaceReadOnlyLDAPRequest- Specified by:
toStringin classLDAPRequest- Parameters:
buffer- The buffer to which to append a string representation of this request.
-
toCode
public void toCode(@NotNull List<String> lineList, @NotNull String requestID, int indentSpaces, boolean includeProcessing) Appends a number of lines comprising the Java source code that can be used to recreate this request to the given list.- Specified by:
toCodein interfaceReadOnlyLDAPRequest- Overrides:
toCodein classSASLBindRequest- Parameters:
lineList- The list to which the source code lines should be added.requestID- The name that should be used as an identifier for the request. If this isnullor empty, then a generic ID will be used.indentSpaces- The number of spaces that should be used to indent the generated code. It must not be negative.includeProcessing- Indicates whether the generated code should include code required to actually process the request and handle the result (iftrue), or just to generate the request (iffalse).
-