IdentityCredential.AuthKeysNeedingCertification 屬性
定義
重要
部分資訊涉及發行前產品,在發行之前可能會有大幅修改。 Microsoft 對此處提供的資訊,不做任何明確或隱含的瑕疵擔保。
會收到一組需要認證的動態驗證金鑰。
public abstract System.Collections.Generic.ICollection<Java.Security.Cert.X509Certificate> AuthKeysNeedingCertification { [Android.Runtime.Register("getAuthKeysNeedingCertification", "()Ljava/util/Collection;", "GetGetAuthKeysNeedingCertificationHandler", ApiSince=30)] get; }
[<get: Android.Runtime.Register("getAuthKeysNeedingCertification", "()Ljava/util/Collection;", "GetGetAuthKeysNeedingCertificationHandler", ApiSince=30)>]
member this.AuthKeysNeedingCertification : System.Collections.Generic.ICollection<Java.Security.Cert.X509Certificate>
屬性值
一組用於動態認證金鑰且需要發行者認證的 X.509 憑證。 這個值不可能為零值。
- 屬性
備註
此方法已被取代。 改用 java.security.KeyStore 搭配 Android 硬體支援的 keystore。
會收到一組需要認證的動態驗證金鑰。
當認證的動態驗證金鑰數量不足時,無論是因為金鑰數量增加、一把或多把金鑰已達使用量,或金鑰接近到期日,此方法會產生替換金鑰與憑證並退回給發行者認證。 發行憑證及相關的靜態認證資料必須透過 storeStaticAuthenticationData(X509Certificate,byte[])回傳給身份憑證。 每個認證金鑰的私密部分從未離開過安全的硬體。
每張 X.509 憑證皆由 CredentialKey 簽署。 CredentialKey 的憑證鏈可透過 getCredentialKeyCertificateChain() 方法取得。
若實作為功能版本 202101 或更新,每個 X.509 憑證包含一個 X.509 擴充檔名,OID 為 1.3.6.1.4.1.1129.2.1.26,該擴充包含一個以 DER 編碼的八位元組字串,包含包含 CBOR 位元組,並包含以下 CDDL:
ProofOfBinding = [
"ProofOfBinding",
bstr, // Contains SHA-256(ProofOfProvisioning)
]
此 CBOR 使發行者能確定其回傳發行者簽署資料的憑證的確切狀態。
詳見PackageManager.FEATURE_IDENTITY_CREDENTIAL_HARDWARE已知的功能版本。
Android 參考資料。android.security.identity.IdentityCredential.getAuthKeysNeedingCertification
本頁部分內容為基於 Open Source Project 所創建與分享的作品,並依授權條款所描述的使用進行修改。