Class CMSSignedDataStreamGenerator

java.lang.Object
org.bouncycastle.cms.CMSSignedGenerator
org.bouncycastle.cms.CMSSignedDataStreamGenerator

public class CMSSignedDataStreamGenerator extends CMSSignedGenerator
General class for generating a pkcs7-signature message stream.

A simple example of usage.

     X509Certificate signCert = ...
     certList.add(signCert);

     Store           certs = new JcaCertStore(certList);
     ContentSigner sha1Signer = new JcaContentSignerBuilder("SHA1withRSA").setProvider("BC").build(signKP.getPrivate());

     CMSSignedDataStreamGenerator gen = new CMSSignedDataStreamGenerator();

     gen.addSignerInfoGenerator(
               new JcaSignerInfoGeneratorBuilder(
                    new JcaDigestCalculatorProviderBuilder().setProvider("BC").build())
                    .build(sha1Signer, signCert));

     gen.addCertificates(certs);

     OutputStream sigOut = gen.open(bOut);

     sigOut.write("Hello World!".getBytes());

     sigOut.close();

Stream handling note:

  • The returned OutputStream must be closed to finalize the CMS structure (write certificates, CRLs, signer infos).
  • Closing the returned stream does not close the underlying OutputStream passed to open().
  • Callers are responsible for closing the underlying OutputStream separately.
  • Constructor Details

    • CMSSignedDataStreamGenerator

      public CMSSignedDataStreamGenerator()
      base constructor
    • CMSSignedDataStreamGenerator

      public CMSSignedDataStreamGenerator(DigestAlgorithmIdentifierFinder digestAlgIdFinder)
      base constructor with a custom DigestAlgorithmIdentifierFinder
  • Method Details

    • setBufferSize

      public void setBufferSize(int bufferSize)
      Set the underlying string size for encapsulated data
      Parameters:
      bufferSize - length of octet strings to buffer the data.
    • open

      public OutputStream open(OutputStream out) throws IOException
      generate a signed object that for a CMS Signed Data object using the given provider.
      Throws:
      IOException
    • open

      public OutputStream open(OutputStream out, boolean encapsulate) throws IOException
      generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature with the default content type "data".
      Throws:
      IOException
    • open

      public OutputStream open(OutputStream out, boolean encapsulate, OutputStream dataOutputStream) throws IOException
      generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature with the default content type "data". If dataOutputStream is non null the data being signed will be written to the stream as it is processed.
      Parameters:
      out - stream the CMS object is to be written to.
      encapsulate - true if data should be encapsulated.
      dataOutputStream - output stream to copy the data being signed to.
      Throws:
      IOException
    • open

      public OutputStream open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, boolean encapsulate) throws IOException
      generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature. The content type is set according to the OID represented by the string signedContentType.
      Throws:
      IOException
    • open

      public OutputStream open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, boolean encapsulate, OutputStream dataOutputStream) throws IOException
      Open an OutputStream that in closing will generate a signed object for a CMS Signed Data object - if encapsulate is true a copy of the message will be included in the signature. The content type is set according to the OID represented by the string signedContentType.
      Parameters:
      eContentType - OID for data to be signed.
      out - stream the CMS object is to be written to.
      encapsulate - true if data should be encapsulated.
      dataOutputStream - output stream to copy the data being signed to.
      Throws:
      IOException
    • open

      public OutputStream open(OutputStream out, long contentLength) throws CMSException, IOException
      Generate a definite-length signed object with encapsulated content of exactly contentLength octets, the content type marked as DATA. See open(ASN1ObjectIdentifier, OutputStream, long, OutputStream).
      Throws:
      CMSException
      IOException
    • open

      public OutputStream open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, long contentLength) throws CMSException, IOException
      Generate a definite-length signed object with encapsulated content of exactly contentLength octets. See open(ASN1ObjectIdentifier, OutputStream, long, OutputStream).
      Throws:
      CMSException
      IOException
    • open

      public OutputStream open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, long contentLength, OutputStream dataOutputStream) throws CMSException, IOException
      Generate a definite-length (DL or DER, per CMSSignedGenerator.setEncoding(String)) signed object with encapsulated content of exactly contentLength octets, in a single pass with nothing buffered - so the content may exceed the size of a Java array.

      The SignerInfos trail the content in the encoding but their length feeds the enclosing headers, which are written before any content flows. Every SignerInfoGenerator must therefore be able to pre-commit its encoded SignerInfo length (see SignerInfoGenerator.getPredictedEncodedLength(ASN1ObjectIdentifier)): the underlying signer has to implement FixedLengthContentSigner - RSA, Ed25519/Ed448 and ML-DSA qualify; DER-encoded ECDSA/DSA do not - and any attribute generators must be length-stable. Exactly contentLength octets must then be written to the returned stream; any mismatch, including a SignerInfo coming out at other than its predicted length, fails with an IOException, by which point the output is unusable and must be discarded.

      Parameters:
      eContentType - the type of the data being written to the object.
      out - stream the CMS object is to be written to.
      contentLength - the exact number of content octets that will be written.
      dataOutputStream - output stream to copy the content to as it is processed (may be null).
      Throws:
      CMSException
      IOException
    • generate

      public void generate(CMSTypedData content, OutputStream out) throws CMSException, IOException
      Write a definite-length (DL or DER, per CMSSignedGenerator.setEncoding(String)) signed object with encapsulated content in two passes over the supplied content, with nothing buffered - so the content may exceed the size of a Java array, and no length needs to be known in advance.

      Pass one streams the content through the signers' digest calculators and computes every signature, so all lengths are exact - unlike the single-pass open(OutputStream, long) this works with variable-length signature algorithms such as DER-encoded ECDSA. Pass two writes the structure, re-reading the content from content - which must therefore be re-readable (e.g. file-backed) and stable: the second pass is re-digested and compared against the first, so a source that changed between passes fails with an IOException rather than producing a structure whose signatures don't verify.

      Parameters:
      content - the content to sign and encapsulate; write is invoked twice.
      out - stream the CMS object is to be written to.
      Throws:
      CMSException
      IOException
    • getDigestAlgorithms

      public List<org.bouncycastle.asn1.x509.AlgorithmIdentifier> getDigestAlgorithms()
      Return a list of the current Digest AlgorithmIdentifiers applying to the next signature.
      Returns:
      a list of the Digest AlgorithmIdentifiers