語言

X509CertificateValidator 類別

定義

驗證 X.509 憑證。

public ref class X509CertificateValidator abstract
public ref class X509CertificateValidator abstract : System::IdentityModel::Configuration::ICustomIdentityConfiguration
public abstract class X509CertificateValidator
public abstract class X509CertificateValidator : System.IdentityModel.Configuration.ICustomIdentityConfiguration
type X509CertificateValidator = class
type X509CertificateValidator = class
    interface ICustomIdentityConfiguration
Public MustInherit Class X509CertificateValidator
Public MustInherit Class X509CertificateValidator
Implements ICustomIdentityConfiguration
繼承
X509CertificateValidator
衍生
實作

範例

public class MyX509CertificateValidator : X509CertificateValidator
{
    string allowedIssuerName;
    public MyX509CertificateValidator(string allowedIssuerName)
    {
        if (allowedIssuerName == null)
        {
            throw new ArgumentNullException("allowedIssuerName");
        }

        this.allowedIssuerName = allowedIssuerName;
    }
    public override void Validate(X509Certificate2 certificate)
    {
        // Check that there is a certificate.
        if (certificate == null)
        {
            throw new ArgumentNullException("certificate");
        }

        // Check that the certificate issuer matches the configured issuer
        if (allowedIssuerName != certificate.IssuerName.Name)
        {
            throw new SecurityTokenValidationException
              ("Certificate was not issued by a trusted issuer");
        }
    }
}

Public Class MyX509CertificateValidator
    Inherits X509CertificateValidator
    Private allowedIssuerName As String

    Public Sub New(ByVal allowedIssuerName As String)
        If allowedIssuerName Is Nothing Then
            Throw New ArgumentNullException("allowedIssuerName")
        End If

        Me.allowedIssuerName = allowedIssuerName

    End Sub

    Public Overrides Sub Validate(ByVal certificate As X509Certificate2)
        ' Check that there is a certificate.
        If certificate Is Nothing Then
            Throw New ArgumentNullException("certificate")
        End If

        ' Check that the certificate issuer matches the configured issuer
        If allowedIssuerName <> certificate.IssuerName.Name Then
            Throw New SecurityTokenValidationException("Certificate was not issued by a trusted issuer")
        End If

    End Sub
End Class

備註

使用該 X509CertificateValidator 類別來指定如何認定 X.509 證書的有效性。 這可以透過從 X509CertificateValidator 中推導出類別並覆寫該 Validate 方法來完成。

建構函式

名稱 Description
X509CertificateValidator()

初始化 X509CertificateValidator 類別的新執行個體。

屬性

名稱 Description
ChainTrust

會有一個驗證器,用信任鏈驗證 X.509 憑證。

None

得到一個驗證器,但對 X.509 憑證沒有任何驗證。 因此,X.509 憑證始終被視為有效。

PeerOrChainTrust

會有一個驗證者來驗證憑證是否在 TrustedPeople 憑證庫裡,或是建立憑證信任鏈。 只要通過任一驗證方法,證書即被視為可信。

PeerTrust

會有一個驗證器來驗證憑證是否在 TrustedPeople 憑證庫裡。

方法

名稱 Description
CreateChainTrustValidator(Boolean, X509ChainPolicy)

取得一個驗證者,透過指定用於建立與驗證信任鏈的上下文與鏈政策來驗證 X.509 憑證。

CreatePeerOrChainTrustValidator(Boolean, X509ChainPolicy)

取得驗證器來驗證憑證是否在憑證儲存中 TrustedPeople ,或指定用於建立憑證信任鏈的上下文與鏈策略。 只要通過任一驗證方法,證書即被視為可信。

Equals(Object)

判斷指定的物件是否等於目前的物件。

(繼承來源 Object)
GetHashCode()

做為預設哈希函式。

(繼承來源 Object)
GetType()

取得目前實例的 Type。

(繼承來源 Object)
LoadCustomConfiguration(XmlNodeList)

在衍生類別中覆寫時,從 XML 載入自定義組態。

MemberwiseClone()

建立目前 Object的淺層複本。

(繼承來源 Object)
ToString()

傳回表示目前 物件的字串。

(繼承來源 Object)
Validate(X509Certificate2)

當在衍生類別中覆寫時,會驗證 X.509 憑證。

適用於