All Classes and Interfaces
Class
Description
Base interface for extra methods required for handling associated data in AEAD ciphers.
Base class for the CMS recipient implementations, carrying the optional restrictions on which
content-encryption algorithms a recipient is willing to recover content for, and on the minimum
AEAD authentication tag size it will accept.
General finder for converting OIDs and AlgorithmIdentifiers into strings.
Exception thrown if an Archive TimeStamp according to RFC4998 fails to containsHashValue.
The Holder object.
Carrying class for an attribute certificate issuer.
Carrier for an authenticator control.
OCSP RFC 2560, RFC 6960
Generator for basic OCSP response objects.
Lightweight builder for the content encryptor used in CMS
EnvelopedData,
AuthEnvelopedData and EncryptedData structures — i.e. it
encrypts the actual transmitted (or stored) content.Lightweight CRMFOutputEncryptor builder.
Lightweight convenience class for EncryptedValueBuilder
An encrypted value padder that uses MGF1 as the basis of the padding.
Builder for creating content signers that use the HSS/LMS Hash-Based Signature Algorithm.
Builder for creating content verifier providers that support the HSS/LMS Hash-Based Signature Algorithm.
Lightweight implementation of
MTCCosigner for the MTC signature
algorithms enumerated in Section 6.1 of draft-ietf-plants-merkle-tree-certs:
"ECDSA-P256-SHA256", "ECDSA-P384-SHA384", "Ed25519",
"ML-DSA-44", "ML-DSA-65", "ML-DSA-87".Lightweight-side
MTCCosignerVerifierProvider that holds a table of
cosigner trust anchor IDs mapped to MTCSignatureVerifier instances.Builder for
BcMTCCosignerVerifierProvider.Lightweight implementation of
MTCSignatureVerifier.the RecipientInfo class for a recipient who has been sent a message
encrypted using a password.
Lightweight extension of
PKCS10CertificationRequest that exposes the request's
public key as an AsymmetricKeyParameter (no JCA dependency).Extension of the PKCS#10 builder to support AsymmetricKey objects.
Lightweight builder for the password-based MAC calculator used to protect the integrity of a
PKCS#12 PFX (RFC 7292).
Lightweight provider that resolves a
PKCS12MacCalculatorBuilder for the MAC algorithm
advertised by an incoming PFX's MacData.Lightweight builder for an
InputDecryptorProvider that handles the PKCS#12 password-based
encryption schemes from RFC 7292 Appendix C (e.g.Lightweight builder for an
OutputEncryptor that applies one of the PKCS#12
password-based encryption schemes from RFC 7292 Appendix C.Lightweight
PKCS12MacCalculatorBuilder that produces a PBMAC1 calculator
(RFC 8018 §7.1) for use as PKCS#12 PFX integrity protection per RFC 9579.Lightweight
PKCS12MacCalculatorBuilderProvider that returns PBMAC1
(RFC 8018 / RFC 9579) MAC calculator builders.Lightweight unwrapper for RSA PKCS#1 v1.5 (
rsaEncryption) key transport, used by the
BC CMS / PKIX recipient implementations.Lightweight SHA-256 implementation of
MerkleTreeHash.JCA helper class to allow BC lightweight objects to be used in the construction of a Version 1 certificate.
JCA helper class to allow BC lightweight objects to be used in the construction of a Version 3 certificate.
Calculator based on the use of a left weighted binary Merkle tree created
on top of the partial hash tree objects provided.
A class that explicitly buffers the data to be signed, sending it in one
block when ready for signing.
Holder class for a SimplePKIResponse containing the details making up /cacerts response.
Builder of CCPD requests (Certify Claim of Possession of Data).
Data piece of DVCRequest for CCPD service (Certify Claim of Possession of Data).
General checked Exception thrown in the cert package and its sub-packages.
Carrier class for a
CertConfirmContent message.Builder class for a
CertConfirmContent message.Builder for a CertificateRepMessage.
Carrier for a CRMF CertReqMsg.
Builder for high-level objects built on
CertReqMsg.High level wrapper for the CertResponse CRMF structure.
Builder for CertificateResponse objects (the CertResponse CRMF equivalent).
General IOException thrown in the cert package and its sub-packages.
Channel Binding Provider provides a method of extracting the
ChannelBinding that can be customised specifically for the provider.
a class representing null or absent content.
Exception thrown when a recipient is asked to recover content protected under a content-encryption
algorithm that is not in the recipient's configured allowed set (see
Jce*Recipient.setAllowedContentAlgorithms).Note: The SIGNATURE parameter is only available when generating unsigned attributes.
containing class for an CMS Authenticated Data object
General class for generating a CMS authenticated-data message.
Parsing class for an CMS Authenticated Data object from an input stream.
General class for generating a CMS authenticated-data message stream.
containing class for an CMS AuthEnveloped Data object
Parser for authenticated enveloped CMS data structures.
Generate authenticated enveloped CMS data with streaming support.
General class for generating a CMS enveloped-data message.
containing class for an CMS Compressed Data object
General class for generating a compressed CMS message.
Class for reading a CMS Compressed Data stream.
General class for generating a compressed CMS message stream.
containing class for an CMS Digested Data object
General class for generating a CMS encrypted-data message.
General class for generating a CMS encrypted-data message.
containing class for an CMS Enveloped Data object
General class for generating a CMS enveloped-data message.
Parsing class for an CMS Enveloped Data object from an input stream.
General class for generating a CMS enveloped-data message stream.
General class for generating a CMS enveloped-data message.
Toolkit methods for dealing with common errors in CMS
classes.
Use CMSTypedData instead of this.
a holding class for a byte array of data to be processed.
Carrier class for a CMPCertificate over CMS.
a holding class for a file of data to be processed.
Finder which is used to look up the algorithm identifiers representing the encryption algorithms that
are associated with a particular signature algorithm.
general class for handling a pkcs7-signature message.
general class for generating a pkcs7-signature message.
Parsing class for an CMS Signed Data object from an input stream.
General class for generating a pkcs7-signature message stream.
Exception thrown when a recipient is asked to recover AEAD-protected content whose authentication
tag is shorter than the recipient's configured minimum tag size (see
Jce*Recipient.setMinimumTagSize).General interface for an operator that is able to create a signature from
a stream of output.
General interface for an operator that is able to verify a signature based
on data in a stream of output.
General interface for providers of ContentVerifier objects.
Generic interface for a CertificateRequestMessage control value.
Builder of DVCSRequests to CPD service (Certify Possession of Data).
Data piece of DVCRequest for CPD service (Certify Possession of Data).
Wrapper class around a CsrAttrs structure.
Holder class for a response containing the details making up /csrattrs response.
A single shot fetcher for a certificate which will only request the specific DNS record if the
DANEEntryFetcher used on construction supports it.
Carrier class for a DANE entry.
Factory class for creating DANEEntry objects.
Factories for DANEEntryFetcher objects should implement this.
Factory for creating selector objects to use with the DANECertificateStore.
Class storing DANEEntry objects.
Builder for the DANECertificateStore.
General checked Exception thrown in the DANE package.
Default authenticated attributes generator.
Default implementation of
DigestAlgorithmIdentifierFinder, returning
the AlgorithmIdentifier that names a digest in the contexts where
this finder is used by CMS / S/MIME / PKIX operator builders.Look up provider for encapsulation lengths produced be KEM algorithms
Default implementation of
SignatureAlgorithmIdentifierFinder,
returning the AlgorithmIdentifier (algorithm OID plus any
algorithm-specific parameters) used to name a signature scheme in
X.509 certificates, CMS SignedData, OCSP responses and related PKIX
structures.Class for return signature names from OIDs or AlgorithmIdentifiers
Default signed attributes generator.
Helpers for working with the delta certificate request attribute carried by a paired
("chameleon") PKCS#10 request — see
draft-bonnell-lamps-chameleon-certs.
The delta certificate request attribute defined in
draft-bonnell-lamps-chameleon-certs.
Builder for the delta certificate request attribute defined in
draft-bonnell-lamps-chameleon-certs §5.
General tool for handling the extension described in: https://datatracker.ietf.org/doc/draft-bonnell-lamps-chameleon-certs/
General interface for an operator that is able to calculate a digest from
a stream of output.
The base interface for a provider of DigestCalculator implementations.
Exception thrown when failed to initialize some DVCS-related staff.
General DVCSException.
DVCS parsing exception - thrown when failed to parse DVCS message.
DVCRequest is general request to DVCS (RFC 3029).
Common base class for client DVCRequest builders.
Data piece of DVCRequest object (DVCS Data structure).
Information piece of DVCS requests.
DVCResponse is general response to DVCS (RFC 3029).
General checked Exception thrown in the cert package and its sub-packages.
General IOException thrown in the cert package and its sub-packages.
Builder for EncryptedValue structures.
An encrypted value padder is used to make sure that prior to a value been
encrypted the data is padded to a standard length.
Parser for EncryptedValue structures.
Holder class for a response containing the details making up a /simpleenroll response.
RFC 4998 ArchiveTimeStamp.
Generator for RFC 4998 Archive Time Stamps.
Generic class for holding byte[] data for RFC 4998 ERS.
An ERSData object that caches hash calculations.
General interface for an ERSData data group object.
Representation of data groups with more than 1 members according to the description provided in RFC4998.
Representation of a data group based on a directory.
RFC 4998 Evidence Record.
Exception thrown if an Archive TimeStamp according to RFC4998 fails to containsHashValue.
Generic class for holding a File of data for RFC 4998 ERS.
Generic class for processing an InputStream of data RFC 4998 ERS.
Base interface for an implementation that calculates the root hash
contained in the time-stamp from the Merkle tree based on the partial
hash-tree nodes.
Base interface for an object with adds HTTP Auth attributes to an ESTRequest
ESTClient implement connection to the server.
A client provider is responsible for creating an ESTClient instance.
ESTClientSourceProvider, implementations of this are expected to return a source.
Exception emitted by EST classes.
ESTHijacker can take control of the source after the initial http request
has been sent and a response received.
Implements a basic http request.
Builder for basic EST requests
A basic http response.
ESTService provides unified access to an EST server which is defined as implementing
RFC7030.
Build an RFC7030 (EST) service.
ESTSourceConnectionListener is called when the source is
is connected to the remote end point but no application
data has been sent.
A Content Signer which also provides details of the digest algorithm used internally.
Extension of
ContentSigner for signers whose signature encoding has
a fixed, predictable length — RSA (PKCS#1 v1.5 and PSS: the modulus size),
Ed25519/Ed448 and ML-DSA qualify; DER-encoded ECDSA/DSA do not (the
INTEGER components vary in length).General wrapper for a generic PKIMessage
HTML Filter
Provides stock implementations for basic auth and digest auth.
Base interface for an input consuming AEAD Decryptor supporting associated text.
General interface for an operator that is able to produce
an InputStream that will decrypt a stream of encrypted data.
General interface for an operator that is able to produce
an InputStream that will produce uncompressed data.
Thrown when a Merkle tree inclusion or consistency proof fails validation.
X509Certificate aware extension of
CertificateRepMessageBuilder.Class for storing Certificates for later lookup.
Builder to create a CertStore from certificate and CRL stores.
General builder class for ContentSigner operators based on the JCA.
Class for storing CRLs for later lookup.
JCA convenience class for EncryptedValueBuilder
Builder for HttpAuth operator that handles digest auth using a JCA provider.
General utility methods for building common objects for supporting the JCA/JCE/JSSE.
PEM generator for the original set of PEM objects used in Open SSL.
JCA-side implementation of
MTCCosigner for the MTC signature
algorithms enumerated in Section 6.1 of draft-ietf-plants-merkle-tree-certs:
"ECDSA-P256-SHA256", "ECDSA-P384-SHA384", "Ed25519",
"ML-DSA-44", "ML-DSA-65", "ML-DSA-87".Builder for
JcaMTCCosigner.JCA-side
MTCCosignerVerifierProvider that holds a table of cosigner
trust anchor IDs mapped to MTCSignatureVerifier instances.Builder for
JcaMTCCosignerVerifierProvider.JCA-side implementation of
MTCSignatureVerifier.Builder for
JcaMTCSignatureVerifier.General purpose writer for OpenSSL PEM objects based on JCA/JCE classes.
JCA-aware extension of
PKCS10CertificationRequest that returns the request's public
key as a JCA PublicKey.Extension of the PKCS#10 builder to support PublicKey and X500Principal objects.
JCA-aware extension of
PKCS12SafeBagBuilder that accepts standard JCA
X509Certificate and PrivateKey inputs.JCA-aware extension of
PKCS8EncryptedPrivateKeyInfoBuilder that accepts a standard
PrivateKey as input.Holder class for public/private key based identity information.
Builder for a private/public identity object representing a "user".
Reads a private key in any of the common OpenSSL on-disk forms and converts it
to a JCA
PrivateKey, transparently decrypting the password-protected variants.JCA-side SHA-256 implementation of
MerkleTreeHash, obtained via
MessageDigest.getInstance("SHA-256") through a JcaJceHelper.This is designed to parse the SignedPublicKeyAndChallenge created by the
KEYGEN tag included by Mozilla based browsers.
Use this class if you are using a provider that has all the facilities you
need.
Converter for producing X509Certificate objects tied to a specific provider from X509CertificateHolder objects.
JCA helper class for converting an X509Certificate into a X509CertificateHolder object.
Class for converting an X509CRLHolder into a corresponding X509CRL object tied to a
particular JCA provider.
JCA helper class for converting an X509CRL into a X509CRLHolder object.
JCA helper class to allow JCA objects to be used in the construction of a Version 1 certificate.
JCA helper class to allow JCA objects to be used in the construction of a Version 3 certificate.
Builder for the content encryptor used in CMS
EnvelopedData,
AuthEnvelopedData and EncryptedData structures — i.e. it
encrypts the actual transmitted (or stored) content.A generic decryptor provider for IETF style algorithms.
the KeyTransRecipientInformation class for a recipient who has been sent a secret
key encrypted using their public key that needs to be used to
extract the message.
A recipient for CMS authenticated enveloped data encrypted with a KEK (Key Encryption Key).
A recipient class for CMS authenticated enveloped data using key agreement (Key Agreement Recipient).
the KeyTransRecipientInformation class for a recipient who has been sent a secret
key encrypted using their public key that needs to be used to
extract the message.
the KeyTransRecipient class for a recipient who has been sent secret
key material encrypted using their public key that needs to be used to
derive a key and authenticate a message.
the KeyTransRecipient class for a recipient who has been sent secret
key material encrypted using their public key that needs to be used to
derive a key and extract a message.
DecryptorProviderBuilder for producing DecryptorProvider for use with PKCS8EncryptedPrivateKeyInfo.
the RecipientInfo class for a recipient who has been sent a message
encrypted using a password.
A builder for RFC 8018 PBE based MAC calculators.
Builder for a
PBEMacCalculatorProvider that vends PBMAC1 (RFC 8018 / RFC 9579)
verifier MAC calculators via the JCA.JCA-based builder for the password-based MAC calculator used to protect the integrity of a
PKCS#12 PFX (RFC 7292).
JCA-based
PKCS12MacCalculatorBuilderProvider that handles both the legacy PKCS#12
PBE-MAC (RFC 7292) and the RFC 9579 PBMAC1 protection schemes.JCA-based builder for an
InputDecryptorProvider that handles the password-based
decryption schemes encountered in PKCS#12 / PKCS#8: the legacy pkcs-12PbeIds family
(RFC 7292 Appendix C), PBES2 / PBKDF2 and PBES2 / scrypt (RFC 8018, RFC 7914), and the older
PBE1 schemes (pbeWithMD5AndDES-CBC, pbeWithSHA1AndDES-CBC).JCA-based builder for an
OutputEncryptor that applies one of the password-based
encryption schemes used to protect PKCS#8 / PKCS#12 payloads:
the legacy PKCS#12 pkcs-12PbeIds family (RFC 7292 Appendix C) — selected when
the constructor is passed one of those OIDs,
PBES2 (RFC 8018) — selected for any other key-encryption algorithm; the embedded
key-derivation function may be PBKDF2 or scrypt (RFC 7914) via an explicit
PBKDFConfig.
A DANE entry fetcher implemented using JNDI.
A typical hostname authorizer for verifying a hostname against the available certificates.
Build an RFC7030 (EST) service based on the JSSE.
Verify the host name is as expected after the SSL Handshake has been completed.
the RecipientInfo class for a recipient who has been sent a message
encrypted using a secret key known to the other side.
the RecipientInfo class for a recipient who has been sent a message
encrypted using key agreement.
the KeyTransRecipientInformation class for a recipient who has been sent a secret
key encrypted using their public key that needs to be used to
extract the message.
Extension of
OutputEncryptor for encryptors that can predict the
exact ciphertext length produced for a given plaintext length.Issuance- and relying-party-side helpers for landmark subtrees, per
Sections 6.3 and 7.4 of draft-ietf-plants-merkle-tree-certs.
A trusted subtree along with the reference checkpoint that proved its
consistency, per Section 7.4.
Maintains a relying-party-side list of trusted subtrees by accepting new
landmarks that come with a cosigned reference checkpoint and a subtree
consistency proof.
A snapshot of the log: tree size and root hash.
The published landmark sequence for a single issuance log, as defined by
Section 6.3 of draft-ietf-plants-merkle-tree-certs.
Interface for a Source which can only produce up to a certain number of bytes.
Base class for all Exceptions with localized messages.
General interface for a key initialized operator that is able to calculate a MAC from
a stream of output.
A generic class for capturing the mac data at the end of a encrypted data stream.
Parses (and encodes) a single log entry per Section 5.2.1 of
draft-ietf-plants-merkle-tree-certs:
A single Merkle Tree certificate log-entry extension, per Section 5.2.1 of
draft-ietf-plants-merkle-tree-certs:
Constants for the
MerkleTreeCertEntryType enum defined in
Section 5.2.1 of draft-ietf-plants-merkle-tree-certs:Validates a Merkle Tree Certificate (MTC) per Section 7.2 of
draft-ietf-plants-merkle-tree-certs.
A half-open range
[start, end) of revoked certificate serial
numbers, per Section 7.5 of the draft.Represents a trusted subtree (typically a landmark subtree predistributed
to the relying party).
Parameters supplied by the relying party for certificate validation.
Operator interface for the hash function used in the Merkle tree, as defined
by Section 4 of draft-ietf-plants-merkle-tree-certs.
Merkle Tree primitives for Merkle Tree Certificates (PLANTS).
Simple container for a subtree interval (start inclusive, end exclusive).
PEM generator for the original set of PEM objects used in Open SSL.
Identity-side helper for an MTC Certification Authority, per Section 5 of
draft-ietf-plants-merkle-tree-certs.
Helpers for the CA certificate representation defined by Section 5.5 of
draft-ietf-plants-merkle-tree-certs.
Issuer-side
ContentSigner that emits an MTC signatureValue
(an encoded MTCProof) for an EE Merkle Tree certificate per
Section 6.1 of draft-ietf-plants-merkle-tree-certs.Wire encoder for the CosignedMessage struct defined by Section 5.3.1 of
draft-ietf-plants-merkle-tree-certs:
Operator interface for producing a cosigner signature over the subtree
[start, end) of an MTC issuance log, per Section 5.3 of
draft-ietf-plants-merkle-tree-certs.Operator that verifies a single cosigner's signature over a CosignedMessage
as defined by Section 5.3.1 of
draft-ietf-plants-merkle-tree-certs.
Looks up an
MTCCosignerVerifier for a given cosigner trust anchor ID.Immutable identifier for an MTC issuance-log subtree window: the CA that
operates the log, the log number (the upper 16 bits of the cert serial per
Section 6.1 of draft-ietf-plants-merkle-tree-certs) and the subtree's
[start, end) index range (uint48).The MTCProof structure encoded in the X.509 certificate signatureValue per
draft-ietf-plants-merkle-tree-certs,
Section 6.1.
A single cosigner signature, as it appears inside the TLS-encoded MTCProof
defined by
draft-ietf-plants-merkle-tree-certs, Section 6.1:
String constants for the cosigner signature algorithms defined by Section
5.3.2 of draft-ietf-plants-merkle-tree-certs.
Operator interface for verifying a single cosigner signature over a
pre-encoded CosignedMessage, per Section 5.3.1 of
draft-ietf-plants-merkle-tree-certs.
Single-cosigner
ContentVerifierProvider adapter for MTC verification.ContentSigner for "Unsigned X.509 Certificates"
OCSPRequest ::= SEQUENCE {
tbsRequest TBSRequest,
optionalSignature [0] EXPLICIT Signature OPTIONAL }
TBSRequest ::= SEQUENCE {
version [0] EXPLICIT Version DEFAULT v1,
requestorName [1] EXPLICIT GeneralName OPTIONAL,
requestList SEQUENCE OF Request,
requestExtensions [2] EXPLICIT Extensions OPTIONAL }
Signature ::= SEQUENCE {
signatureAlgorithm AlgorithmIdentifier,
signature BIT STRING,
certs [0] EXPLICIT SEQUENCE OF Certificate OPTIONAL}
Version ::= INTEGER { v1(0) }
Request ::= SEQUENCE {
reqCert CertID,
singleRequestExtensions [0] EXPLICIT Extensions OPTIONAL }
CertID ::= SEQUENCE {
hashAlgorithm AlgorithmIdentifier,
issuerNameHash OCTET STRING, -- Hash of Issuer's DN
issuerKeyHash OCTET STRING, -- Hash of Issuers public key
serialNumber CertificateSerialNumber }
base generator for an OCSP response - at the moment this only supports the
generation of responses containing BasicOCSP responses.
Catalogue of content-encryption algorithm OIDs used where code only needs to
identify the parameter form or block size family for an algorithm.
Thrown by an operator builder when it cannot produce the requested operator.
Base checked exception for failures originating in the
org.bouncycastle.operator
abstraction layer — the bridge between BC's JCA-free high-level packages
(org.bouncycastle.cms, org.bouncycastle.cert, org.bouncycastle.pkcs,
etc.) and their underlying JCA / lightweight implementations
(org.bouncycastle.operator.jcajce / org.bouncycastle.operator.bc).Thrown from inside an operator's streaming method when an underlying cryptographic
failure occurs and the surrounding signature only permits an
IOException.General interface for an operator that is able to produce
an OutputStream that will output compressed data.
General interface for an operator that is able to produce
an OutputStream that will output encrypted data.
Deprecated.
no longer used.
the RecipientInfo class for a recipient who has been sent a message
encrypted using a password.
Base interface for decryption operations.
Class for parsing OpenSSL PEM encoded streams containing
X509 certificates, PKCS8 encoded keys and PKCS7 objects.
Deprecated.
use JcaPEMWriter
Holding class for a PKCS#10 certification request (RFC 2986).
A class for creating PKCS#10 Certification requests.
Holding class for a PKCS#12 PFX structure (RFC 7292).
A builder for the PKCS#12 Pfx key and certificate store.
Holding class for a PKCS#12 SafeBag (RFC 7292).
Builder for a
PKCS12SafeBag.Factory that materialises the
PKCS12SafeBags carried in one ContentInfo of a
PFX's AuthenticatedSafe.Wrapper around the RFC 7292
SecretBag ASN.1 structure used by the
PKCS#12 secretBag bag type.Builder for a
PKCS12SecretBag carrying an arbitrary secret value
identified by the supplied bag-type OID.Utility class for re-encoding PKCS#12 files to definite length.
Holding class for a PKCS#8 EncryptedPrivateKeyInfo structure (RFC 5958, originally RFC 5208).
A class for creating EncryptedPrivateKeyInfo structures.
General checked exception thrown by classes in
org.bouncycastle.pkcs and its
sub-packages.Specialised
IOException thrown by classes in org.bouncycastle.pkcs and its
sub-packages to signal malformed or corrupted PKCS encodings.Carrier for a PKIArchiveOptions structure.
Builder for a PKIArchiveControl structure.
PKIXCertPathReviewer
Validation of X.509 Certificate Paths.
Validation of X.509 Certificate Paths.
Holder class for public/private key based identity information.
POPODecKeyChallContent ::= SEQUENCE OF Challenge
-- One Challenge per encryption key certification request (in the
-- same order as these requests appear in CertReqMessages).
POPODecKeyChallContent ::= SEQUENCE OF Challenge
-- One Challenge per encryption key certification request (in the
-- same order as these requests appear in CertReqMessages).
Wrapper for a PKIMessage with protection attached to it.
Builder for creating a protected PKI message.
Interface for ContentVerifiers that also support raw signatures that can be
verified using the digest of the calculated data.
Carrier for a registration token control.
Fluent builder for the
RelatedCertificateDescriptor structure
defined by draft-ietf-lamps-certdiscovery, plus the wrapping required to
place it in a SubjectInfoAccess extension.Operator-style helpers for building and verifying the two wire-format
pieces defined by RFC 9763 ("Related Certificates for Use in Multiple
Authentications within a Protocol"):
the
RelatedCertificate certificate extension carried on an
end-entity certificate (OID
X509ObjectIdentifiers.id_pe_relatedCert
/ Extension.relatedCertificate), and
the RequesterCertificate CSR attribute value the requester
includes in the CSR to prove they hold the private key of the related
certificate (attribute OID
PKCSObjectIdentifiers.id_aa_relatedCertRequest).
OCSP RFC 2560, RFC 6960
Carrier for a ResponderID.
wrapper for the RevokedInfo object
Unchecked variant of
OperatorException used when an operator method has no
throws clause to declare a checked exception on.One
Extension entry inside the sct_extensions list of an
RFC 9162 (CT v2) SignedCertificateTimestampDataV2.A single Signed Certificate Timestamp (SCT) in the RFC 6962 (CT v1) wire
format.
The SCT body carried inside an RFC 9162 (CT v2)
TransItem whose
versioned_type is x509_sct_v2 (0x0102) or precert_sct_v2
(0x0103).RFC 6962 (CT v1)
SignedCertificateTimestampList: the TLS-encoded
structure carried inside the embedded-SCT certificate extension and the
OCSP SCT-list extension.This is designed to parse the SignedPublicKeyAndChallenge created by the
KEYGEN tag included by Mozilla based browsers.
a basic index for a signer.
Builder for SignerInfo generator objects.
an expanded SignerInfo block from a CMS Signed message
Basic generator that just returns a preconstructed attribute table
A sorting list - byte[] are sorted in ascending order.
A sorting list - byte[] are sorted in ascending order.
Used to Wrap a socket and to provide access to the underlying session.
Filter for strings to store in a SQL table.
Implementations provide SSL socket factories.
A checker for vetting subject public keys based on the direct checking of the ASN.1
Base class for an RFC 3161 Time Stamp Request.
Generator for RFC 3161 Time Stamp Request objects.
Base class for an RFC 3161 Time Stamp Response object.
Generator for RFC 3161 Time Stamp Responses.
Carrier class for a TimeStampToken.
Currently the class supports ESSCertID by if a digest calculator based on SHA1 is passed in, otherwise it uses
ESSCertIDv2.
Helper for emitting the EST transport-identity-linking attribute (RFC 7030 §3.5)
into a PKCS#10 certification request, with RFC 7894-aware selection of the
attribute type.
TLSUniqueProvider implementation of this can provide the TLS unique value.
One TLS-encoded item from an RFC 9162 (CT v2)
TransItemList.RFC 9162 (CT v2)
TransItemList: the TLS-encoded structure carried
inside the Transparency Information X.509v3 extension
(X509ObjectIdentifiers.id_ce_ct_transparencyInformation).A calculator which produces a truncated digest from a regular one, with the truncation
achieved by dropping off the right most octets.
Utilities for constructing and parsing the binary trust anchor IDs reserved
by Section 5.1 of draft-ietf-plants-merkle-tree-certs under each CA ID:
{caID 0 N} — issuance log N (Section 5.2)
{caID 1 N L} — landmark L of log N (Section 8.2)
{caID 2 N L} — landmark group containing landmark L
and earlier (Section 8.2.1)
Recognised hash algorithms for the time stamp protocol.
Exception thrown if a TSP request or response fails to validate.
wrapper for the UnknownInfo object
Wrapper class to mark untrusted input.
Wrapper class to mark an untrusted Url
Builder of DVC requests to VPKC service (Verify Public Key Certificates).
Data piece of DVCS request to VPKC service (Verify Public Key Certificates).
Builder of DVCS requests to VSD service (Verify Signed Document).
Data piece of DVCS request to VSD service (Verify Signed Document).
Holding class for an X.509 AttributeCertificate structure.
This class is an
Selector like implementation to select
attribute certificates from a given set of criteria.This class builds selectors according to the set criteria.
A general class for X.509 certificate "pretty printing".
Holding class for an X.509 Certificate structure.
a basic index for a X509CertificateHolder class
Collects the problems found while decoding an X.509 certificate, instead of throwing
on the first one, for diagnostic and reporting use (github #1508).
A single problem found during review.
The outcome of a review: the list of findings, plus the recovered certificate when
the structure decoded cleanly.
The severity of a
X509CertificateReviewer.Finding.Holding class for an X.509 CRL Entry structure.
Holding class for an X.509 CRL structure.
General utility class for creating calculated extensions using the standard methods.
X.509 Certificate Revocation Checker - still lacks OCSP support and support for delta CRLs.
Holder for an OpenSSL trusted certificate block.
class to produce an X.509 Version 1 certificate.
class to produce an X.509 Version 2 AttributeCertificate.
class to produce an X.509 Version 2 CRL.
class to produce an X.509 Version 3 certificate.