Interface ConnectionSettings.TlsSettings<T>
- Type Parameters:
T-
- Enclosing interface:
ConnectionSettings<T>
public static interface ConnectionSettings.TlsSettings<T>
TLS settings.
-
Method Summary
Modifier and TypeMethodDescriptionThe cipher suites to enable, in order of preference.The connection builder.Activate hostname verification.hostnameVerification(boolean hostnameVerification) Whether to activate hostname verification or not.namedGroups(String... namedGroups) The named groups to enable, in order of preference.sslContext(SSLContext sslContext) SSLContextto use.sslEngineCustomizer(Consumer<SSLEngine> customizer) Callback to customize theSSLEngineused for the connection.Convenience method to set aSSLContextthat trusts all servers.
-
Method Details
-
hostnameVerification
ConnectionSettings.TlsSettings<T> hostnameVerification()Activate hostname verification.Activated by default.
- Returns:
- TLS settings
-
hostnameVerification
Whether to activate hostname verification or not.Activated by default.
- Parameters:
hostnameVerification- activation flag- Returns:
- TLS settings
-
sslContext
SSLContextto use.- Parameters:
sslContext- the SSL context to use- Returns:
- TLS settings
-
ciphers
The cipher suites to enable, in order of preference.- Parameters:
ciphers- cipher suites to enable- Returns:
- TLS settings
-
namedGroups
The named groups to enable, in order of preference.This will be applied only for Java 20 and more.
- Parameters:
namedGroups- named groups to enable- Returns:
- TLS settings
- See Also:
-
sslEngineCustomizer
Callback to customize theSSLEngineused for the connection.The callback is called after the library has applied its own initialization of the engine, so it can be used to override the settings the library sets by default.
This is an advanced extension point, most applications should not need it.
- Parameters:
customizer- the customizer- Returns:
- TLS settings
-
trustEverything
ConnectionSettings.TlsSettings<T> trustEverything()Convenience method to set aSSLContextthat trusts all servers.When this feature is enabled, no peer verification is performed, which provides no protection against Man-in-the-Middle (MITM) attacks.
Use this only in development and QA environments.
- Returns:
- TLS settings
-
connection
-