public class MTCContentSigner extends java.lang.Object implements ContentSigner
ContentSigner that emits an MTC signatureValue
(an encoded MTCProof) for an EE Merkle Tree certificate per
Section 6.1 of draft-ietf-plants-merkle-tree-certs.
The signer is plugged into the standard
X509v3CertificateBuilder.build(ContentSigner) flow. As the TBSCertificate
DER bytes stream out of the builder into getOutputStream(), this
class captures them; when getSignature() is invoked it:
MerkleTreeCertEntry leaf hash and climbs one
Merkle level using the single-sibling inclusionProof via
MerkleTreeCertificateValidator.computeSubtreeHash(byte[], byte[], org.bouncycastle.cert.plants.MerkleTreeHash).MTCCosigner.cosignSubtree(org.bouncycastle.cert.plants.MTCLog, byte[]) to produce the
cosigner's MTCSignature.MTCProof and returns its TLS wire encoding.This is the simple-case binding used by the worked examples: a
standalone certificate (Section 6.2 of the draft) over the minimal
subtree [0, 2) — the EE's log entry at index 0, one sibling leaf at
index 1, and a single-node inclusion proof — carrying one cosigner
signature. Issuers with multi-level inclusion proofs or multiple cosigners
should compose the MTCCosigner, MTCProof and
MerkleTreeHash primitives directly; landmark-relative certificates
(Section 6.3, no signatures) are built via
LandmarkCertificateManager.buildLandmarkCertificate(long, long, org.bouncycastle.asn1.x509.TBSCertificateLogEntry, org.bouncycastle.asn1.x509.SubjectPublicKeyInfo, org.bouncycastle.cert.plants.MerkleTreePrimitives.SubtreeInfo, java.util.List<byte[]>, org.bouncycastle.cert.plants.MerkleTreeHash).
| Constructor and Description |
|---|
MTCContentSigner(MTCLog log,
byte[] inclusionProof,
MTCCosigner cosigner)
The cosigner's identity is taken from
MTCCosigner.getCosignerId()
— the CA-as-cosigner case is just a MTCCosigner constructed with
log.getCa().getCaId() as its cosigner ID (Section 5.3 of the
draft). |
| Modifier and Type | Method and Description |
|---|---|
org.bouncycastle.asn1.x509.AlgorithmIdentifier |
getAlgorithmIdentifier()
Return the algorithm identifier describing the signature
algorithm and parameters this signer generates.
|
java.io.OutputStream |
getOutputStream()
Returns a stream that will accept data for the purpose of calculating
a signature.
|
byte[] |
getSignature()
Returns a signature based on the current data written to the stream, since the
start or the last call to getSignature().
|
public MTCContentSigner(MTCLog log, byte[] inclusionProof, MTCCosigner cosigner)
MTCCosigner.getCosignerId()
— the CA-as-cosigner case is just a MTCCosigner constructed with
log.getCa().getCaId() as its cosigner ID (Section 5.3 of the
draft). Witnesses, regulators, federated peers or any other entity with
a distinct trust anchor ID work via the same constructor by constructing
the cosigner with their own ID.log - issuance log + subtree window
[log.getStart(), log.getEnd()) — also
supplies the CA (via MTCLog.getCa()) and
therefore the hash function and log IDinclusionProof - the single sibling leaf hash that, combined with
the EE's leaf hash, yields the subtree hash —
same bytes that land in the resulting MTCProofcosigner - cosigner driver bound to its trust anchor ID,
signature algorithm and keypublic org.bouncycastle.asn1.x509.AlgorithmIdentifier getAlgorithmIdentifier()
ContentSignergetAlgorithmIdentifier in interface ContentSignerpublic java.io.OutputStream getOutputStream()
ContentSignergetOutputStream in interface ContentSignerpublic byte[] getSignature()
ContentSignergetSignature in interface ContentSigner