Class TransItem

java.lang.Object
org.bouncycastle.cert.ct.TransItem

public class TransItem extends Object
One TLS-encoded item from an RFC 9162 (CT v2) TransItemList. The structure is a 2-byte VersionedTransType followed by the type-specific data payload; this class retains the payload as opaque bytes and provides a typed decoder for the only payload kind the certificate-side decoder needs to interpret in practice: getSignedCertificateTimestampDataV2(). Other payload kinds (log entries, signed tree heads, consistency / inclusion proofs) are still recoverable through getRawData(); layering structured decoders on top is intentionally left to consumers that need them.
    enum {
        x509_entry_v2(0x0100), precert_entry_v2(0x0101),
        x509_sct_v2(0x0102),   precert_sct_v2(0x0103),
        signed_tree_head_v2(0x0104),
        consistency_proof_v2(0x0105),
        inclusion_proof_v2(0x0106),
        reserved_rfc6962(0x0000..0x00FF),
        reserved_experimentaluse(0xE000..0xEFFF),
        reserved_privateuse(0xF000..0xFFFF),
        (0xFFFF)
    } VersionedTransType;

    struct {
        VersionedTransType versioned_type;
        select (versioned_type) {
            case x509_sct_v2:    SignedCertificateTimestampDataV2;
            case precert_sct_v2: SignedCertificateTimestampDataV2;
            ...
        } data;
    } TransItem;
  • Field Details

  • Constructor Details

    • TransItem

      public TransItem(int versionedType, byte[] data)
  • Method Details

    • getInstance

      public static TransItem getInstance(byte[] encoded)
      Decode a TransItem from its serialized form (the bytes that appear as one SerializedTransItem entry inside a TransItemList).
    • getVersionedType

      public int getVersionedType()
    • getRawData

      public byte[] getRawData()
      The raw data payload bytes — i.e. the SerializedTransItem minus the 2-byte versioned_type prefix. The caller is responsible for parsing them according to getVersionedType().
    • getSignedCertificateTimestampDataV2

      public SignedCertificateTimestampDataV2 getSignedCertificateTimestampDataV2()
      When this item is a v2 SCT (x509_sct_v2 or precert_sct_v2), return the decoded payload; otherwise return null.
    • getEncoded

      public byte[] getEncoded()
      Serialize this TransItem to its TLS wire form.