public class JcaTlsRawKeyCertificate extends java.lang.Object implements TlsCertificate
This is the base class for JcaTlsCertificate (an X.509 certificate is a SubjectPublicKeyInfo
plus X.509 metadata); subclasses override getPublicKey(),
getSubjectPublicKeyInfo(), supportsKeyUsageBit(int) and the X.509 accessors
(getEncoded(), getExtension(ASN1ObjectIdentifier), getSerialNumber(),
getSigAlgOID(), getSigAlgParams()) to source them from the certificate. This
mirrors the lightweight BcTlsCertificate extends BcTlsRawKeyCertificate structure.
| Modifier and Type | Field and Description |
|---|---|
protected JcaTlsCrypto |
crypto |
protected org.bouncycastle.asn1.x509.SubjectPublicKeyInfo |
keyInfo |
protected static int |
KU_CRL_SIGN |
protected static int |
KU_DATA_ENCIPHERMENT |
protected static int |
KU_DECIPHER_ONLY |
protected static int |
KU_DIGITAL_SIGNATURE |
protected static int |
KU_ENCIPHER_ONLY |
protected static int |
KU_KEY_AGREEMENT |
protected static int |
KU_KEY_CERT_SIGN |
protected static int |
KU_KEY_ENCIPHERMENT |
protected static int |
KU_NON_REPUDIATION |
protected javax.crypto.interfaces.DHPublicKey |
pubKeyDH |
protected java.security.interfaces.ECPublicKey |
pubKeyEC |
protected java.security.PublicKey |
pubKeyRSA |
| Modifier | Constructor and Description |
|---|---|
protected |
JcaTlsRawKeyCertificate(JcaTlsCrypto crypto)
For subclasses (e.g.
|
|
JcaTlsRawKeyCertificate(JcaTlsCrypto crypto,
byte[] keyInfo) |
|
JcaTlsRawKeyCertificate(JcaTlsCrypto crypto,
org.bouncycastle.asn1.x509.SubjectPublicKeyInfo keyInfo) |
| Modifier and Type | Method and Description |
|---|---|
TlsCertificate |
checkUsageInRole(int tlsCertificateRole) |
TlsEncryptor |
createEncryptor(int tlsCertificateRole)
Return an encryptor based on the public key in this certificate.
|
Tls13Verifier |
createVerifier(int signatureScheme) |
TlsVerifier |
createVerifier(short signatureAlgorithm) |
byte[] |
getEncoded() |
byte[] |
getExtension(org.bouncycastle.asn1.ASN1ObjectIdentifier extensionOID) |
short |
getLegacySignatureAlgorithm() |
protected java.security.PublicKey |
getPublicKey() |
java.math.BigInteger |
getSerialNumber() |
java.lang.String |
getSigAlgOID() |
org.bouncycastle.asn1.ASN1Encodable |
getSigAlgParams() |
protected org.bouncycastle.asn1.x509.SubjectPublicKeyInfo |
getSubjectPublicKeyInfo() |
protected boolean |
implSupportsSignatureAlgorithm(short signatureAlgorithm) |
protected boolean |
supportsKeyUsageBit(int keyUsageBit) |
protected boolean |
supportsMLDSA(org.bouncycastle.asn1.ASN1ObjectIdentifier mlDsaAlgOid) |
protected boolean |
supportsRSA_PKCS1() |
protected boolean |
supportsRSA_PSS_PSS(short signatureAlgorithm) |
protected boolean |
supportsRSA_PSS_RSAE() |
boolean |
supportsSignatureAlgorithm(short signatureAlgorithm) |
boolean |
supportsSignatureAlgorithmCA(short signatureAlgorithm) |
protected boolean |
supportsSLHDSA(org.bouncycastle.asn1.ASN1ObjectIdentifier slhDsaAlgOid) |
protected void |
validateKeyUsageBit(int keyUsageBit) |
protected void |
validateMLDSA(org.bouncycastle.asn1.ASN1ObjectIdentifier mlDsaAlgOid) |
protected void |
validateRSA_PKCS1() |
protected void |
validateRSA_PSS_PSS(short signatureAlgorithm) |
protected void |
validateRSA_PSS_RSAE() |
protected void |
validateSLHDSA(org.bouncycastle.asn1.ASN1ObjectIdentifier slhDsaAlgOid) |
protected static final int KU_DIGITAL_SIGNATURE
protected static final int KU_NON_REPUDIATION
protected static final int KU_KEY_ENCIPHERMENT
protected static final int KU_DATA_ENCIPHERMENT
protected static final int KU_KEY_AGREEMENT
protected static final int KU_KEY_CERT_SIGN
protected static final int KU_CRL_SIGN
protected static final int KU_ENCIPHER_ONLY
protected static final int KU_DECIPHER_ONLY
protected final JcaTlsCrypto crypto
protected final org.bouncycastle.asn1.x509.SubjectPublicKeyInfo keyInfo
protected javax.crypto.interfaces.DHPublicKey pubKeyDH
protected java.security.interfaces.ECPublicKey pubKeyEC
protected java.security.PublicKey pubKeyRSA
public JcaTlsRawKeyCertificate(JcaTlsCrypto crypto, byte[] keyInfo)
public JcaTlsRawKeyCertificate(JcaTlsCrypto crypto, org.bouncycastle.asn1.x509.SubjectPublicKeyInfo keyInfo)
protected JcaTlsRawKeyCertificate(JcaTlsCrypto crypto)
JcaTlsCertificate) that source the public key from elsewhere and
override getPublicKey() / getSubjectPublicKeyInfo().public TlsEncryptor createEncryptor(int tlsCertificateRole) throws java.io.IOException
TlsCertificatecreateEncryptor in interface TlsCertificatetlsCertificateRole - TlsCertificateRolejava.io.IOExceptionpublic TlsVerifier createVerifier(short signatureAlgorithm) throws java.io.IOException
createVerifier in interface TlsCertificatesignatureAlgorithm - SignatureAlgorithmjava.io.IOExceptionpublic Tls13Verifier createVerifier(int signatureScheme) throws java.io.IOException
createVerifier in interface TlsCertificatesignatureScheme - SignatureSchemejava.io.IOExceptionpublic byte[] getEncoded()
throws java.io.IOException
getEncoded in interface TlsCertificatejava.io.IOExceptionpublic byte[] getExtension(org.bouncycastle.asn1.ASN1ObjectIdentifier extensionOID)
throws java.io.IOException
getExtension in interface TlsCertificatejava.io.IOExceptionpublic java.math.BigInteger getSerialNumber()
getSerialNumber in interface TlsCertificatepublic java.lang.String getSigAlgOID()
getSigAlgOID in interface TlsCertificatepublic org.bouncycastle.asn1.ASN1Encodable getSigAlgParams()
throws java.io.IOException
getSigAlgParams in interface TlsCertificatejava.io.IOExceptionpublic short getLegacySignatureAlgorithm()
throws java.io.IOException
getLegacySignatureAlgorithm in interface TlsCertificateSignatureAlgorithmjava.io.IOExceptionpublic boolean supportsSignatureAlgorithm(short signatureAlgorithm)
throws java.io.IOException
supportsSignatureAlgorithm in interface TlsCertificatesignatureAlgorithm - SignatureAlgorithmjava.io.IOExceptionpublic boolean supportsSignatureAlgorithmCA(short signatureAlgorithm)
throws java.io.IOException
supportsSignatureAlgorithmCA in interface TlsCertificatejava.io.IOExceptionpublic TlsCertificate checkUsageInRole(int tlsCertificateRole) throws java.io.IOException
checkUsageInRole in interface TlsCertificatetlsCertificateRole - TlsCertificateRolejava.io.IOExceptionprotected boolean implSupportsSignatureAlgorithm(short signatureAlgorithm)
throws java.io.IOException
java.io.IOExceptionprotected java.security.PublicKey getPublicKey()
throws java.io.IOException
java.io.IOExceptionprotected org.bouncycastle.asn1.x509.SubjectPublicKeyInfo getSubjectPublicKeyInfo()
throws java.io.IOException
java.io.IOExceptionprotected boolean supportsKeyUsageBit(int keyUsageBit)
protected boolean supportsMLDSA(org.bouncycastle.asn1.ASN1ObjectIdentifier mlDsaAlgOid)
throws java.io.IOException
java.io.IOExceptionprotected boolean supportsRSA_PKCS1()
throws java.io.IOException
java.io.IOExceptionprotected boolean supportsRSA_PSS_PSS(short signatureAlgorithm)
throws java.io.IOException
java.io.IOExceptionprotected boolean supportsRSA_PSS_RSAE()
throws java.io.IOException
java.io.IOExceptionprotected boolean supportsSLHDSA(org.bouncycastle.asn1.ASN1ObjectIdentifier slhDsaAlgOid)
throws java.io.IOException
java.io.IOExceptionprotected void validateKeyUsageBit(int keyUsageBit)
throws java.io.IOException
java.io.IOExceptionprotected void validateMLDSA(org.bouncycastle.asn1.ASN1ObjectIdentifier mlDsaAlgOid)
throws java.io.IOException
java.io.IOExceptionprotected void validateRSA_PKCS1()
throws java.io.IOException
java.io.IOExceptionprotected void validateRSA_PSS_PSS(short signatureAlgorithm)
throws java.io.IOException
java.io.IOExceptionprotected void validateRSA_PSS_RSAE()
throws java.io.IOException
java.io.IOExceptionprotected void validateSLHDSA(org.bouncycastle.asn1.ASN1ObjectIdentifier slhDsaAlgOid)
throws java.io.IOException
java.io.IOException