Class JcaMTCCosigner

java.lang.Object
org.bouncycastle.cert.plants.jcajce.JcaMTCCosigner
All Implemented Interfaces:
MTCCosigner

public class JcaMTCCosigner extends Object implements MTCCosigner
JCA-side implementation of MTCCosigner for the MTC signature algorithms enumerated in Section 6.1 of draft-ietf-plants-merkle-tree-certs: "ECDSA-P256-SHA256", "ECDSA-P384-SHA384", "Ed25519", "ML-DSA-44", "ML-DSA-65", "ML-DSA-87".

Symmetric counterpart of JcaMTCSignatureVerifier — encapsulates the MTCCosignedMessage encode plus the underlying JCA Signature ceremony. The draft identifiers are mapped to JCA Signature names internally; the plain (r||s) ECDSA encoding used by MTCProof requires SHA256WITHPLAIN-ECDSA / SHA384WITHPLAIN-ECDSA, which BC's JCE provider registers (DER-encoded SHA256withECDSA is wire-incompatible with the MTCProof signature byte format).

Instances are created via JcaMTCCosigner.Builder.

  • Method Details

    • getCosignerId

      public byte[] getCosignerId()
      Specified by:
      getCosignerId in interface MTCCosigner
      Returns:
      the binary trust anchor ID of this cosigner — the value that appears in MTCSignature.getCosignerId() on every signature produced by this instance. Per Section 5.3 of the draft, when the CA itself is acting as a cosigner this is the CA's own trust anchor ID.
    • cosignSubtree

      public MTCSignature cosignSubtree(MTCLog log, byte[] subtreeHash) throws IOException
      Description copied from interface: MTCCosigner
      Cosigns the subtree [log.getStart(), log.getEnd()) of the issuance log identified by log.getLogId().
      Specified by:
      cosignSubtree in interface MTCCosigner
      Throws:
      IOException - if the CosignedMessage cannot be encoded or the underlying signing operation fails