Språk

HttpEngine.Builder.AddPublicKeyPins Method

Definition

Pins a set of public keys for a given host.

[Android.Runtime.Register("addPublicKeyPins", "(Ljava/lang/String;Ljava/util/Set;ZLjava/time/Instant;)Landroid/net/http/HttpEngine$Builder;", "GetAddPublicKeyPins_Ljava_lang_String_Ljava_util_Set_ZLjava_time_Instant_Handler", ApiSince=34)]
public virtual Android.Net.Http.HttpEngine.Builder AddPublicKeyPins(string hostName, System.Collections.Generic.ICollection<byte[]> pinsSha256, bool includeSubdomains, Java.Time.Instant expirationInstant);
[<Android.Runtime.Register("addPublicKeyPins", "(Ljava/lang/String;Ljava/util/Set;ZLjava/time/Instant;)Landroid/net/http/HttpEngine$Builder;", "GetAddPublicKeyPins_Ljava_lang_String_Ljava_util_Set_ZLjava_time_Instant_Handler", ApiSince=34)>]
abstract member AddPublicKeyPins : string * System.Collections.Generic.ICollection<byte[]> * bool * Java.Time.Instant -> Android.Net.Http.HttpEngine.Builder
override this.AddPublicKeyPins : string * System.Collections.Generic.ICollection<byte[]> * bool * Java.Time.Instant -> Android.Net.Http.HttpEngine.Builder

Parameters

hostName
String

name of the host to which the public keys should be pinned. A host that consists only of digits and the dot character is treated as invalid. This value cannot be null.

pinsSha256
ICollection<Byte[]>

a set of pins. Each pin is the SHA-256 cryptographic hash of the DER-encoded ASN.1 representation of the Subject Public Key Info (SPKI) of the host's X.509 certificate. Use Certificate.getPublicKey() and Key.getEncoded() to obtain DER-encoded ASN.1 representation of the SPKI. Although, the method does not mandate the presence of the backup pin that can be used if the control of the primary private key has been lost, it is highly recommended to supply one. This value cannot be null.

includeSubdomains
Boolean

indicates whether the pinning policy should be applied to subdomains of hostName.

expirationInstant
Instant

specifies the expiration instant for the pins. This value cannot be null.

Returns

the builder to facilitate chaining. This value cannot be null.

Attributes

Remarks

Pins a set of public keys for a given host. By pinning a set of public keys, pinsSha256, communication with hostName is required to authenticate with a certificate with a public key from the set of pinned ones. An app can pin the public key of the root certificate, any of the intermediate certificates or the end-entry certificate. Authentication will fail and secure communication will not be established if none of the public keys is present in the host's certificate chain, even if the host attempts to authenticate with a certificate allowed by the device's trusted store of certificates.

Calling this method multiple times with the same host name overrides the previously set pins for the host.

More information about the public key pinning can be found in RFC 7469.

Android reference for android.net.http.HttpEngine.Builder.addPublicKeyPins.

Portions of this page are modifications based on work created and shared by the Android Open Source Project and used according to terms described in the Creative Commons 2.5 Attribution License.

Applies to