public class DefaultDigestAlgorithmIdentifierFinder extends java.lang.Object implements DigestAlgorithmIdentifierFinder
DigestAlgorithmIdentifierFinder, returning
the AlgorithmIdentifier that names a digest in the contexts where
this finder is used by CMS / S/MIME / PKIX operator builders.
Parameter-field convention: SHA-2 and SHA-3 digest identifiers are
produced with the parameters field absent, per
RFC 5754 §2:
"Implementations MUST generate SHA2 AlgorithmIdentifiers with absent
parameters." SHA-1 keeps NULL parameters (RFC 3370). Old
algorithms with historic NULL-parameter conventions (MD2 / MD4 / MD5,
GOST R 34.11-94) follow their own RFCs.
This is a different convention from
DefaultSignatureAlgorithmIdentifierFinder, which when building
RSASSA-PSS-params emits the SHA-2 / SHA-3 hash sub-identifier with
NULL parameters per
RFC 4055 §2.1 (sha256Identifier ::= { id-sha256, NULL } etc.).
Both forms are standards-compliant in their respective slots; a single CMS
SignedData carrying an RSA-PSS SignerInfo will validly contain the same
SHA-2 OID twice, once with absent parameters (in digestAlgorithm)
and once with NULL parameters (inside the PSS parameter structure).
Receiver-side AlgorithmIdentifier.equals() on the two encodings
returns false but both are accepted by RFC 5754 §2 and by other
mainstream verifiers (OpenSSL, the JDK providers, GnuTLS).
| Modifier and Type | Field and Description |
|---|---|
static DigestAlgorithmIdentifierFinder |
INSTANCE |
| Constructor and Description |
|---|
DefaultDigestAlgorithmIdentifierFinder() |
| Modifier and Type | Method and Description |
|---|---|
org.bouncycastle.asn1.x509.AlgorithmIdentifier |
find(org.bouncycastle.asn1.x509.AlgorithmIdentifier sigAlgId)
Find the digest algorithm identifier that matches with
the passed in signature algorithm identifier.
|
org.bouncycastle.asn1.x509.AlgorithmIdentifier |
find(org.bouncycastle.asn1.ASN1ObjectIdentifier digAlgOid)
Find the algorithm identifier that matches with
the passed in digest OID.
|
org.bouncycastle.asn1.x509.AlgorithmIdentifier |
find(java.lang.String digAlgName)
Find the algorithm identifier that matches with
the passed in digest name.
|
public static DigestAlgorithmIdentifierFinder INSTANCE
public DefaultDigestAlgorithmIdentifierFinder()
public org.bouncycastle.asn1.x509.AlgorithmIdentifier find(org.bouncycastle.asn1.x509.AlgorithmIdentifier sigAlgId)
DigestAlgorithmIdentifierFinderfind in interface DigestAlgorithmIdentifierFindersigAlgId - the signature algorithm of interest.public org.bouncycastle.asn1.x509.AlgorithmIdentifier find(org.bouncycastle.asn1.ASN1ObjectIdentifier digAlgOid)
DigestAlgorithmIdentifierFinderfind in interface DigestAlgorithmIdentifierFinderdigAlgOid - the OID of the digest algorithm of interest.public org.bouncycastle.asn1.x509.AlgorithmIdentifier find(java.lang.String digAlgName)
DigestAlgorithmIdentifierFinderfind in interface DigestAlgorithmIdentifierFinderdigAlgName - the name of the digest algorithm of interest.