Class BcKEKRecipient
java.lang.Object
org.bouncycastle.cms.AbstractRecipient
org.bouncycastle.cms.bc.BcKEKRecipient
- All Implemented Interfaces:
KEKRecipient, Recipient
- Direct Known Subclasses:
BcKEKEnvelopedRecipient
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected org.bouncycastle.crypto.CipherParametersextractSecretKey(org.bouncycastle.asn1.x509.AlgorithmIdentifier keyEncryptionAlgorithm, org.bouncycastle.asn1.x509.AlgorithmIdentifier contentEncryptionAlgorithm, byte[] encryptedContentEncryptionKey) setAllowedContentAlgorithms(Set<org.bouncycastle.asn1.ASN1ObjectIdentifier> allowedContentAlgorithms) Set the content-encryption algorithms this recipient is willing to unwrap a key for.Methods inherited from class AbstractRecipient
checkTagSize, isContentAlgorithmAllowed, setAllowedContentAlgorithmSet, setMinimumTagSizeInBitsMethods inherited from class Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface KEKRecipient
getRecipientOperator
-
Constructor Details
-
BcKEKRecipient
-
-
Method Details
-
setAllowedContentAlgorithms
public BcKEKRecipient setAllowedContentAlgorithms(Set<org.bouncycastle.asn1.ASN1ObjectIdentifier> allowedContentAlgorithms) Set the content-encryption algorithms this recipient is willing to unwrap a key for. When set, an attempt to recover content protected under any other algorithm is rejected, mitigating an attacker substituting a weaker content-encryption algorithm into the recipient info.- Parameters:
allowedContentAlgorithms- the set of permitted content-encryption algorithm OIDs.- Returns:
- this recipient.
-
extractSecretKey
protected org.bouncycastle.crypto.CipherParameters extractSecretKey(org.bouncycastle.asn1.x509.AlgorithmIdentifier keyEncryptionAlgorithm, org.bouncycastle.asn1.x509.AlgorithmIdentifier contentEncryptionAlgorithm, byte[] encryptedContentEncryptionKey) throws CMSException - Throws:
CMSException
-