IdentityCredential.AuthKeysNeedingCertification Property
Definition
Important
Some information relates to prerelease product that may be substantially modified before it’s released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
Gets a collection of dynamic authentication keys that need certification.
public abstract System.Collections.Generic.ICollection<Java.Security.Cert.X509Certificate> AuthKeysNeedingCertification { [Android.Runtime.Register("getAuthKeysNeedingCertification", "()Ljava/util/Collection;", "GetGetAuthKeysNeedingCertificationHandler", ApiSince=30)] get; }
[<get: Android.Runtime.Register("getAuthKeysNeedingCertification", "()Ljava/util/Collection;", "GetGetAuthKeysNeedingCertificationHandler", ApiSince=30)>]
member this.AuthKeysNeedingCertification : System.Collections.Generic.ICollection<Java.Security.Cert.X509Certificate>
Property Value
A collection of X.509 certificates for dynamic authentication keys that need issuer certification. This value cannot be null.
- Attributes
Remarks
This method is deprecated. Use java.security.KeyStore with the Android hardware-backed keystore instead.
Gets a collection of dynamic authentication keys that need certification.
When there aren't enough certified dynamic authentication keys, either because the key count has been increased or because one or more keys have reached their usage count or it if a key is too close to its expiration date, this method will generate replacement keys and certificates and return them for issuer certification. The issuer certificates and associated static authentication data must then be provided back to the Identity Credential using storeStaticAuthenticationData(X509Certificate,byte[]). The private part of each authentication key never leaves secure hardware.
Each X.509 certificate is signed by CredentialKey. The certificate chain for CredentialKey can be obtained using the getCredentialKeyCertificateChain() method.
If the implementation is feature version 202101 or later, each X.509 certificate contains an X.509 extension at OID 1.3.6.1.4.1.11129.2.1.26 which contains a DER encoded OCTET STRING with the bytes of the CBOR with the following CDDL:
ProofOfBinding = [
"ProofOfBinding",
bstr, // Contains SHA-256(ProofOfProvisioning)
]
This CBOR enables an issuer to determine the exact state of the credential it returns issuer-signed data for.
See PackageManager.FEATURE_IDENTITY_CREDENTIAL_HARDWARE for known feature versions.
Android reference for android.security.identity.IdentityCredential.getAuthKeysNeedingCertification.
Portions of this page are modifications based on work created and shared by the Android Open Source Project and used according to terms described in the Creative Commons 2.5 Attribution License.