X509CertificateValidator 類別
定義
重要
部分資訊涉及發行前產品,在發行之前可能會有大幅修改。 Microsoft 對此處提供的資訊,不做任何明確或隱含的瑕疵擔保。
驗證 X.509 憑證。
public ref class X509CertificateValidator abstract
public ref class X509CertificateValidator abstract : System::IdentityModel::Configuration::ICustomIdentityConfiguration
public abstract class X509CertificateValidator
public abstract class X509CertificateValidator : System.IdentityModel.Configuration.ICustomIdentityConfiguration
type X509CertificateValidator = class
type X509CertificateValidator = class
interface ICustomIdentityConfiguration
Public MustInherit Class X509CertificateValidator
Public MustInherit Class X509CertificateValidator
Implements ICustomIdentityConfiguration
- 繼承
-
X509CertificateValidator
- 衍生
- 實作
範例
public class MyX509CertificateValidator : X509CertificateValidator
{
string allowedIssuerName;
public MyX509CertificateValidator(string allowedIssuerName)
{
if (allowedIssuerName == null)
{
throw new ArgumentNullException("allowedIssuerName");
}
this.allowedIssuerName = allowedIssuerName;
}
public override void Validate(X509Certificate2 certificate)
{
// Check that there is a certificate.
if (certificate == null)
{
throw new ArgumentNullException("certificate");
}
// Check that the certificate issuer matches the configured issuer
if (allowedIssuerName != certificate.IssuerName.Name)
{
throw new SecurityTokenValidationException
("Certificate was not issued by a trusted issuer");
}
}
}
Public Class MyX509CertificateValidator
Inherits X509CertificateValidator
Private allowedIssuerName As String
Public Sub New(ByVal allowedIssuerName As String)
If allowedIssuerName Is Nothing Then
Throw New ArgumentNullException("allowedIssuerName")
End If
Me.allowedIssuerName = allowedIssuerName
End Sub
Public Overrides Sub Validate(ByVal certificate As X509Certificate2)
' Check that there is a certificate.
If certificate Is Nothing Then
Throw New ArgumentNullException("certificate")
End If
' Check that the certificate issuer matches the configured issuer
If allowedIssuerName <> certificate.IssuerName.Name Then
Throw New SecurityTokenValidationException("Certificate was not issued by a trusted issuer")
End If
End Sub
End Class
備註
使用該 X509CertificateValidator 類別來指定如何認定 X.509 證書的有效性。 這可以透過從 X509CertificateValidator 中推導出類別並覆寫該 Validate 方法來完成。
建構函式
| 名稱 | Description |
|---|---|
| X509CertificateValidator() |
初始化 X509CertificateValidator 類別的新執行個體。 |
屬性
| 名稱 | Description |
|---|---|
| ChainTrust |
會有一個驗證器,用信任鏈驗證 X.509 憑證。 |
| None |
得到一個驗證器,但對 X.509 憑證沒有任何驗證。 因此,X.509 憑證始終被視為有效。 |
| PeerOrChainTrust |
會有一個驗證者來驗證憑證是否在 |
| PeerTrust |
會有一個驗證器來驗證憑證是否在 |
方法
| 名稱 | Description |
|---|---|
| CreateChainTrustValidator(Boolean, X509ChainPolicy) |
取得一個驗證者,透過指定用於建立與驗證信任鏈的上下文與鏈政策來驗證 X.509 憑證。 |
| CreatePeerOrChainTrustValidator(Boolean, X509ChainPolicy) |
取得驗證器來驗證憑證是否在憑證儲存中 |
| Equals(Object) |
判斷指定的物件是否等於目前的物件。 (繼承來源 Object) |
| GetHashCode() |
做為預設哈希函式。 (繼承來源 Object) |
| GetType() |
取得目前實例的 Type。 (繼承來源 Object) |
| LoadCustomConfiguration(XmlNodeList) |
在衍生類別中覆寫時,從 XML 載入自定義組態。 |
| MemberwiseClone() |
建立目前 Object的淺層複本。 (繼承來源 Object) |
| ToString() |
傳回表示目前 物件的字串。 (繼承來源 Object) |
| Validate(X509Certificate2) |
當在衍生類別中覆寫時,會驗證 X.509 憑證。 |