public class PKCS12KeyStoreSpi extends KeyStoreSpi implements PKCSObjectIdentifiers, X509ObjectIdentifiers, BCKeyStore
| Modifier and Type | Class and Description |
|---|---|
static class |
PKCS12KeyStoreSpi.BCPKCS12KeyStore |
| Modifier and Type | Field and Description |
|---|---|
protected SecureRandom |
random |
bagtypes, canNotDecryptAny, certBag, certTypes, crlBag, crlTypes, data, des_EDE3_CBC, dhKeyAgreement, digestAlgorithm, digestedData, encryptedData, encryptionAlgorithm, envelopedData, id_aa, id_aa_commitmentType, id_aa_contentHint, id_aa_contentIdentifier, id_aa_contentReference, id_aa_encrypKeyPref, id_aa_ets_archiveTimestamp, id_aa_ets_certCRLTimestamp, id_aa_ets_certificateRefs, id_aa_ets_certValues, id_aa_ets_commitmentType, id_aa_ets_contentTimestamp, id_aa_ets_escTimeStamp, id_aa_ets_otherSigCert, id_aa_ets_revocationRefs, id_aa_ets_revocationValues, id_aa_ets_signerAttr, id_aa_ets_signerLocation, id_aa_ets_sigPolicyId, id_aa_msgSigDigest, id_aa_otherSigCert, id_aa_receiptRequest, id_aa_signatureTimeStampToken, id_aa_signerLocation, id_aa_signingCertificate, id_aa_signingCertificateV2, id_aa_sigPolicyId, id_alg, id_alg_CMS3DESwrap, id_alg_CMSRC2wrap, id_alg_PWRI_KEK, id_ct, id_ct_authData, id_ct_authEnvelopedData, id_ct_compressedData, id_ct_timestampedData, id_ct_TSTInfo, id_cti, id_cti_ets_proofOfApproval, id_cti_ets_proofOfCreation, id_cti_ets_proofOfDelivery, id_cti_ets_proofOfOrigin, id_cti_ets_proofOfReceipt, id_cti_ets_proofOfSender, id_hmacWithSHA1, id_hmacWithSHA224, id_hmacWithSHA256, id_hmacWithSHA384, id_hmacWithSHA512, id_mgf1, id_PBES2, id_PBKDF2, id_pSpecified, id_RSAES_OAEP, id_RSASSA_PSS, id_smime, id_spq, id_spq_ets_unotice, id_spq_ets_uri, keyBag, md5, md5WithRSAEncryption, pbeWithMD2AndDES_CBC, pbeWithMD2AndRC2_CBC, pbeWithMD5AndDES_CBC, pbeWithMD5AndRC2_CBC, pbeWithSHA1AndDES_CBC, pbeWithSHA1AndRC2_CBC, pbeWithSHAAnd128BitRC2_CBC, pbeWithSHAAnd128BitRC4, pbeWithSHAAnd2_KeyTripleDES_CBC, pbeWithSHAAnd3_KeyTripleDES_CBC, pbewithSHAAnd40BitRC2_CBC, pbeWithSHAAnd40BitRC2_CBC, pbeWithSHAAnd40BitRC4, pkcs_1, pkcs_12, pkcs_12PbeIds, pkcs_3, pkcs_5, pkcs_7, pkcs_9, pkcs_9_at_challengePassword, pkcs_9_at_contentType, pkcs_9_at_counterSignature, pkcs_9_at_emailAddress, pkcs_9_at_extendedCertificateAttributes, pkcs_9_at_extensionRequest, pkcs_9_at_friendlyName, pkcs_9_at_localKeyId, pkcs_9_at_messageDigest, pkcs_9_at_signingDescription, pkcs_9_at_signingTime, pkcs_9_at_smimeCapabilities, pkcs_9_at_unstructuredAddress, pkcs_9_at_unstructuredName, pkcs8ShroudedKeyBag, preferSignedData, RC2_CBC, rc4, rsaEncryption, safeContentsBag, sdsiCertificate, secretBag, sha1WithRSAEncryption, sha224WithRSAEncryption, sha256WithRSAEncryption, sha384WithRSAEncryption, sha512WithRSAEncryption, signedAndEnvelopedData, signedData, sMIMECapabilitiesVersions, srsaOAEPEncryptionSET, x509Certificate, x509certType, x509CrlcommonName, countryName, crlAccessMethod, id_ad, id_ad_caIssuers, id_ad_ocsp, id_at_name, id_at_telephoneNumber, id_ce, id_ea_rsa, id_pe, id_pkix, id_SHA1, localityName, ocspAccessMethod, organization, organizationalUnitName, ripemd160, ripemd160WithRSAEncryption, stateOrProvinceName| Constructor and Description |
|---|
PKCS12KeyStoreSpi(Provider provider,
ASN1ObjectIdentifier keyAlgorithm,
ASN1ObjectIdentifier certAlgorithm) |
| Modifier and Type | Method and Description |
|---|---|
protected byte[] |
cryptData(boolean forEncryption,
AlgorithmIdentifier algId,
char[] password,
boolean wrongPKCS12Zero,
byte[] data) |
Enumeration |
engineAliases()
Returns an
Enumeration over all alias names stored in this
KeyStoreSpi. |
boolean |
engineContainsAlias(String alias)
Indicates whether the given alias is present in this
KeyStoreSpi. |
void |
engineDeleteEntry(String alias)
this is not quite complete - we should follow up on the chain, a bit
tricky if a certificate appears in more than one chain...
|
Certificate |
engineGetCertificate(String alias)
simply return the cert for the private key
|
String |
engineGetCertificateAlias(Certificate cert)
Returns the alias associated with the first entry whose certificate
matches the specified certificate.
|
Certificate[] |
engineGetCertificateChain(String alias)
Returns the certificate chain for the entry with the given alias.
|
Date |
engineGetCreationDate(String alias)
Returns the creation date of the entry with the given alias.
|
Key |
engineGetKey(String alias,
char[] password)
Returns the key with the given alias, using the password to recover the
key from the store.
|
boolean |
engineIsCertificateEntry(String alias)
Indicates whether the specified alias is associated with a
KeyStore.TrustedCertificateEntry. |
boolean |
engineIsKeyEntry(String alias)
Indicates whether the specified alias is associated with either a
KeyStore.PrivateKeyEntry or a KeyStore.SecretKeyEntry. |
void |
engineLoad(InputStream stream,
char[] password)
Loads this
KeyStoreSpi from the given InputStream. |
void |
engineSetCertificateEntry(String alias,
Certificate cert)
Associates the given alias with a certificate.
|
void |
engineSetKeyEntry(String alias,
byte[] key,
Certificate[] chain)
Associates the given alias with a key and a certificate chain.
|
void |
engineSetKeyEntry(String alias,
Key key,
char[] password,
Certificate[] chain)
Associates the given alias with the key, password and certificate chain.
|
int |
engineSize()
Returns the number of entries stored in this
KeyStoreSpi. |
void |
engineStore(KeyStore.LoadStoreParameter param)
Stores this
KeyStoreSpi using the specified LoadStoreParameter. |
void |
engineStore(OutputStream stream,
char[] password)
Writes this
KeyStoreSpi to the specified OutputStream. |
void |
setRandom(SecureRandom rand)
set the random source for the key store
|
protected PrivateKey |
unwrapKey(AlgorithmIdentifier algId,
byte[] data,
char[] password,
boolean wrongPKCS12Zero) |
protected byte[] |
wrapKey(String algorithm,
Key key,
PKCS12PBEParams pbeParams,
char[] password) |
engineEntryInstanceOf, engineGetEntry, engineLoad, engineSetEntryprotected SecureRandom random
public PKCS12KeyStoreSpi(Provider provider, ASN1ObjectIdentifier keyAlgorithm, ASN1ObjectIdentifier certAlgorithm)
public void setRandom(SecureRandom rand)
BCKeyStoresetRandom in interface BCKeyStorepublic Enumeration engineAliases()
KeyStoreSpiEnumeration over all alias names stored in this
KeyStoreSpi.engineAliases in class KeyStoreSpiEnumeration over all alias names stored in this
KeyStoreSpi.public boolean engineContainsAlias(String alias)
KeyStoreSpiKeyStoreSpi.engineContainsAlias in class KeyStoreSpialias - the alias of an entry.true if the alias exists, false otherwise.public void engineDeleteEntry(String alias) throws KeyStoreException
engineDeleteEntry in class KeyStoreSpialias - the alias for the entry.KeyStoreException - if the entry can not be deleted.public Certificate engineGetCertificate(String alias)
engineGetCertificate in class KeyStoreSpialias - the alias for the entry.null if the specified alias is not bound to an entry.public String engineGetCertificateAlias(Certificate cert)
KeyStoreSpiengineGetCertificateAlias in class KeyStoreSpicert - the certificate to find the associated entry's alias for.null if no entry with the specified
certificate can be found.public Certificate[] engineGetCertificateChain(String alias)
KeyStoreSpiengineGetCertificateChain in class KeyStoreSpialias - the alias for the entrynull if the specified alias is not bound to an entry.public Date engineGetCreationDate(String alias)
KeyStoreSpiengineGetCreationDate in class KeyStoreSpialias - the alias for the entry.null if the specified alias is not
bound to an entry.public Key engineGetKey(String alias, char[] password) throws NoSuchAlgorithmException, UnrecoverableKeyException
KeyStoreSpiengineGetKey in class KeyStoreSpialias - the alias for the entry.password - the password used to recover the key.null if the
specified alias is not bound to an entry.NoSuchAlgorithmException - if the algorithm for recovering the key is not available.UnrecoverableKeyException - if the key can not be recovered.public boolean engineIsCertificateEntry(String alias)
KeyStoreSpiKeyStore.TrustedCertificateEntry.engineIsCertificateEntry in class KeyStoreSpialias - the alias of an entry.true if the given alias is associated with a certificate
entry.public boolean engineIsKeyEntry(String alias)
KeyStoreSpiKeyStore.PrivateKeyEntry or a KeyStore.SecretKeyEntry.engineIsKeyEntry in class KeyStoreSpialias - the alias of an entry.true if the given alias is associated with a key entry.public void engineSetCertificateEntry(String alias, Certificate cert) throws KeyStoreException
KeyStoreSpiIf the specified alias already exists, it will be reassigned.
engineSetCertificateEntry in class KeyStoreSpialias - the alias for the certificate.cert - the certificate.KeyStoreException - if an existing alias is not associated to an entry containing
a trusted certificate, or this method fails for any other
reason.public void engineSetKeyEntry(String alias, byte[] key, Certificate[] chain) throws KeyStoreException
KeyStoreSpiIf the specified alias already exists, it will be reassigned.
engineSetKeyEntry in class KeyStoreSpialias - the alias for the key.key - the key in an encoded format.chain - the certificate chain.KeyStoreException - if this operation fails.public void engineSetKeyEntry(String alias, Key key, char[] password, Certificate[] chain) throws KeyStoreException
KeyStoreSpiIf the specified alias already exists, it will be reassigned.
engineSetKeyEntry in class KeyStoreSpialias - the alias for the key.key - the key.password - the password.chain - the certificate chain.KeyStoreException - if the specified key can not be protected, or if this
operation fails for another reason.public int engineSize()
KeyStoreSpiKeyStoreSpi.engineSize in class KeyStoreSpiKeyStoreSpi.protected PrivateKey unwrapKey(AlgorithmIdentifier algId, byte[] data, char[] password, boolean wrongPKCS12Zero) throws IOException
IOExceptionprotected byte[] wrapKey(String algorithm, Key key, PKCS12PBEParams pbeParams, char[] password) throws IOException
IOExceptionprotected byte[] cryptData(boolean forEncryption,
AlgorithmIdentifier algId,
char[] password,
boolean wrongPKCS12Zero,
byte[] data)
throws IOException
IOExceptionpublic void engineLoad(InputStream stream, char[] password) throws IOException
KeyStoreSpiKeyStoreSpi from the given InputStream.
Utilizes the given password to verify the stored data.engineLoad in class KeyStoreSpistream - the InputStream to load this KeyStoreSpi's
data from.password - the password to verify the stored data, maybe null.IOException - if a problem occurred while reading from the stream.public void engineStore(KeyStore.LoadStoreParameter param) throws IOException, NoSuchAlgorithmException, CertificateException
KeyStoreSpiKeyStoreSpi using the specified LoadStoreParameter.engineStore in class KeyStoreSpiparam - the LoadStoreParameter that specifies how to store
this KeyStoreSpi, maybe null.IOException - if a problem occurred while writing to the stream.NoSuchAlgorithmException - if the required algorithm is not available.CertificateException - if the an exception occurred while storing the certificates
of this code KeyStoreSpi.public void engineStore(OutputStream stream, char[] password) throws IOException
KeyStoreSpiKeyStoreSpi to the specified OutputStream.
The data written to the OutputStream is protected by the
specified password.engineStore in class KeyStoreSpistream - the OutputStream to write the store's data to.password - the password to protect the data.IOException - if a problem occurred while writing to the stream.