Class JcePasswordRecipient
java.lang.Object
org.bouncycastle.cms.AbstractRecipient
org.bouncycastle.cms.jcajce.JcePasswordRecipient
- All Implemented Interfaces:
PasswordRecipient, Recipient
- Direct Known Subclasses:
JcePasswordAuthenticatedRecipient, JcePasswordAuthEnvelopedRecipient, JcePasswordEnvelopedRecipient
the RecipientInfo class for a recipient who has been sent a message
encrypted using a password.
-
Nested Class Summary
Nested classes/interfaces inherited from interface PasswordRecipient
PasswordRecipient.PRF -
Field Summary
FieldsFields inherited from interface PasswordRecipient
PKCS5_SCHEME2, PKCS5_SCHEME2_UTF8 -
Method Summary
Modifier and TypeMethodDescriptionbyte[]calculateDerivedKey(int schemeID, org.bouncycastle.asn1.x509.AlgorithmIdentifier derivationAlgorithm, int keySize) protected KeyextractSecretKey(org.bouncycastle.asn1.x509.AlgorithmIdentifier keyEncryptionAlgorithm, org.bouncycastle.asn1.x509.AlgorithmIdentifier contentEncryptionAlgorithm, byte[] derivedKey, byte[] encryptedContentEncryptionKey) char[]intsetAllowedContentAlgorithms(Set<org.bouncycastle.asn1.ASN1ObjectIdentifier> allowedContentAlgorithms) Set the content-encryption algorithms this recipient is willing to unwrap a key for.setMinimumTagSize(int tagSizeInBits) Set the minimum AEAD authentication tag size (in bits) this recipient will accept.setPasswordConversionScheme(int schemeID) setProvider(String providerName) setProvider(Provider provider) Methods inherited from class AbstractRecipient
checkTagSize, isContentAlgorithmAllowed, setAllowedContentAlgorithmSet, setMinimumTagSizeInBitsMethods inherited from class Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, waitMethods inherited from interface PasswordRecipient
getRecipientOperator
-
Field Details
-
helper
-
-
Method Details
-
setPasswordConversionScheme
-
setProvider
-
setProvider
-
setAllowedContentAlgorithms
public JcePasswordRecipient setAllowedContentAlgorithms(Set<org.bouncycastle.asn1.ASN1ObjectIdentifier> allowedContentAlgorithms) Set the content-encryption algorithms this recipient is willing to unwrap a key for. When set, an attempt to recover content protected under any other algorithm is rejected, mitigating an attacker substituting a weaker content-encryption algorithm into the recipient info.- Parameters:
allowedContentAlgorithms- the set of permitted content-encryption algorithm OIDs.- Returns:
- this recipient.
-
setMinimumTagSize
Set the minimum AEAD authentication tag size (in bits) this recipient will accept. When set, an attempt to recover AuthEnvelopedData whose content algorithm carries a shorter tag is rejected, mitigating an attacker downgrading the tag to a weaker length.- Parameters:
tagSizeInBits- the minimum acceptable AEAD tag size, in bits.- Returns:
- this recipient.
-
extractSecretKey
protected Key extractSecretKey(org.bouncycastle.asn1.x509.AlgorithmIdentifier keyEncryptionAlgorithm, org.bouncycastle.asn1.x509.AlgorithmIdentifier contentEncryptionAlgorithm, byte[] derivedKey, byte[] encryptedContentEncryptionKey) throws CMSException - Throws:
CMSException
-
calculateDerivedKey
public byte[] calculateDerivedKey(int schemeID, org.bouncycastle.asn1.x509.AlgorithmIdentifier derivationAlgorithm, int keySize) throws CMSException - Specified by:
calculateDerivedKeyin interfacePasswordRecipient- Throws:
CMSException
-
getPasswordConversionScheme
public int getPasswordConversionScheme()- Specified by:
getPasswordConversionSchemein interfacePasswordRecipient
-
getPassword
public char[] getPassword()- Specified by:
getPasswordin interfacePasswordRecipient
-