Class CMSSignedDataStreamGenerator
A simple example of usage.
X509Certificate signCert = ...
certList.add(signCert);
Store certs = new JcaCertStore(certList);
ContentSigner sha1Signer = new JcaContentSignerBuilder("SHA1withRSA").setProvider("BC").build(signKP.getPrivate());
CMSSignedDataStreamGenerator gen = new CMSSignedDataStreamGenerator();
gen.addSignerInfoGenerator(
new JcaSignerInfoGeneratorBuilder(
new JcaDigestCalculatorProviderBuilder().setProvider("BC").build())
.build(sha1Signer, signCert));
gen.addCertificates(certs);
OutputStream sigOut = gen.open(bOut);
sigOut.write("Hello World!".getBytes());
sigOut.close();
Stream handling note:
- The returned OutputStream must be closed to finalize the CMS structure (write certificates, CRLs, signer infos).
- Closing the returned stream does not close the underlying OutputStream
passed to
open(). - Callers are responsible for closing the underlying OutputStream separately.
-
Field Summary
Fields inherited from class CMSSignedGenerator
_signers, certs, crls, DATA, DIGEST_GOST3411, DIGEST_MD5, DIGEST_RIPEMD128, DIGEST_RIPEMD160, DIGEST_RIPEMD256, DIGEST_SHA1, DIGEST_SHA224, DIGEST_SHA256, DIGEST_SHA384, DIGEST_SHA512, digestAlgIdFinder, digests, encoding, ENCRYPTION_DSA, ENCRYPTION_ECDSA, ENCRYPTION_ECGOST3410, ENCRYPTION_ECGOST3410_2012_256, ENCRYPTION_ECGOST3410_2012_512, ENCRYPTION_GOST3410, ENCRYPTION_RSA, ENCRYPTION_RSA_PSS, extraDigestAlgorithms, signerGens -
Constructor Summary
ConstructorsConstructorDescriptionbase constructorCMSSignedDataStreamGenerator(DigestAlgorithmIdentifierFinder digestAlgIdFinder) base constructor with a custom DigestAlgorithmIdentifierFinder -
Method Summary
Modifier and TypeMethodDescriptionvoidgenerate(CMSTypedData content, OutputStream out) Write a definite-length (DL or DER, perCMSSignedGenerator.setEncoding(String)) signed object with encapsulated content in two passes over the supplied content, with nothing buffered - so the content may exceed the size of a Java array, and no length needs to be known in advance.List<org.bouncycastle.asn1.x509.AlgorithmIdentifier> Return a list of the current Digest AlgorithmIdentifiers applying to the next signature.open(OutputStream out) generate a signed object that for a CMS Signed Data object using the given provider.open(OutputStream out, boolean encapsulate) generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature with the default content type "data".open(OutputStream out, boolean encapsulate, OutputStream dataOutputStream) generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature with the default content type "data".open(OutputStream out, long contentLength) Generate a definite-length signed object with encapsulated content of exactlycontentLengthoctets, the content type marked as DATA.open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, boolean encapsulate) generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature.open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, boolean encapsulate, OutputStream dataOutputStream) Open an OutputStream that in closing will generate a signed object for a CMS Signed Data object - if encapsulate is true a copy of the message will be included in the signature.open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, long contentLength) Generate a definite-length signed object with encapsulated content of exactlycontentLengthoctets.open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, long contentLength, OutputStream dataOutputStream) Generate a definite-length (DL or DER, perCMSSignedGenerator.setEncoding(String)) signed object with encapsulated content of exactlycontentLengthoctets, in a single pass with nothing buffered - so the content may exceed the size of a Java array.voidsetBufferSize(int bufferSize) Set the underlying string size for encapsulated dataMethods inherited from class CMSSignedGenerator
addAttributeCertificate, addAttributeCertificates, addCertificate, addCertificates, addCRL, addCRLs, addDigestAlgorithms, addOtherRevocationInfo, addOtherRevocationInfo, addSignerInfoGenerator, addSigners, getBaseParameters, getGeneratedDigests, setEncoding
-
Constructor Details
-
CMSSignedDataStreamGenerator
public CMSSignedDataStreamGenerator()base constructor -
CMSSignedDataStreamGenerator
base constructor with a custom DigestAlgorithmIdentifierFinder
-
-
Method Details
-
setBufferSize
public void setBufferSize(int bufferSize) Set the underlying string size for encapsulated data- Parameters:
bufferSize- length of octet strings to buffer the data.
-
open
generate a signed object that for a CMS Signed Data object using the given provider.- Throws:
IOException
-
open
generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature with the default content type "data".- Throws:
IOException
-
open
public OutputStream open(OutputStream out, boolean encapsulate, OutputStream dataOutputStream) throws IOException generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature with the default content type "data". If dataOutputStream is non null the data being signed will be written to the stream as it is processed.- Parameters:
out- stream the CMS object is to be written to.encapsulate- true if data should be encapsulated.dataOutputStream- output stream to copy the data being signed to.- Throws:
IOException
-
open
public OutputStream open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, boolean encapsulate) throws IOException generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature. The content type is set according to the OID represented by the string signedContentType.- Throws:
IOException
-
open
public OutputStream open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, boolean encapsulate, OutputStream dataOutputStream) throws IOException Open an OutputStream that in closing will generate a signed object for a CMS Signed Data object - if encapsulate is true a copy of the message will be included in the signature. The content type is set according to the OID represented by the string signedContentType.- Parameters:
eContentType- OID for data to be signed.out- stream the CMS object is to be written to.encapsulate- true if data should be encapsulated.dataOutputStream- output stream to copy the data being signed to.- Throws:
IOException
-
open
Generate a definite-length signed object with encapsulated content of exactlycontentLengthoctets, the content type marked as DATA. Seeopen(ASN1ObjectIdentifier, OutputStream, long, OutputStream).- Throws:
CMSExceptionIOException
-
open
public OutputStream open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, long contentLength) throws CMSException, IOException Generate a definite-length signed object with encapsulated content of exactlycontentLengthoctets. Seeopen(ASN1ObjectIdentifier, OutputStream, long, OutputStream).- Throws:
CMSExceptionIOException
-
open
public OutputStream open(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType, OutputStream out, long contentLength, OutputStream dataOutputStream) throws CMSException, IOException Generate a definite-length (DL or DER, perCMSSignedGenerator.setEncoding(String)) signed object with encapsulated content of exactlycontentLengthoctets, in a single pass with nothing buffered - so the content may exceed the size of a Java array.The SignerInfos trail the content in the encoding but their length feeds the enclosing headers, which are written before any content flows. Every
SignerInfoGeneratormust therefore be able to pre-commit its encoded SignerInfo length (seeSignerInfoGenerator.getPredictedEncodedLength(ASN1ObjectIdentifier)): the underlying signer has to implementFixedLengthContentSigner- RSA, Ed25519/Ed448 and ML-DSA qualify; DER-encoded ECDSA/DSA do not - and any attribute generators must be length-stable. ExactlycontentLengthoctets must then be written to the returned stream; any mismatch, including a SignerInfo coming out at other than its predicted length, fails with an IOException, by which point the output is unusable and must be discarded.- Parameters:
eContentType- the type of the data being written to the object.out- stream the CMS object is to be written to.contentLength- the exact number of content octets that will be written.dataOutputStream- output stream to copy the content to as it is processed (may be null).- Throws:
CMSExceptionIOException
-
generate
Write a definite-length (DL or DER, perCMSSignedGenerator.setEncoding(String)) signed object with encapsulated content in two passes over the supplied content, with nothing buffered - so the content may exceed the size of a Java array, and no length needs to be known in advance.Pass one streams the content through the signers' digest calculators and computes every signature, so all lengths are exact - unlike the single-pass
open(OutputStream, long)this works with variable-length signature algorithms such as DER-encoded ECDSA. Pass two writes the structure, re-reading the content fromcontent- which must therefore be re-readable (e.g. file-backed) and stable: the second pass is re-digested and compared against the first, so a source that changed between passes fails with an IOException rather than producing a structure whose signatures don't verify.- Parameters:
content- the content to sign and encapsulate;writeis invoked twice.out- stream the CMS object is to be written to.- Throws:
CMSExceptionIOException
-
getDigestAlgorithms
Return a list of the current Digest AlgorithmIdentifiers applying to the next signature.- Returns:
- a list of the Digest AlgorithmIdentifiers
-