Class JcePKCSPBEOutputEncryptorBuilder
java.lang.Object
org.bouncycastle.pkcs.jcajce.JcePKCSPBEOutputEncryptorBuilder
JCA-based builder for an
OutputEncryptor that applies one of the password-based
encryption schemes used to protect PKCS#8 / PKCS#12 payloads:
- the legacy PKCS#12
pkcs-12PbeIdsfamily (RFC 7292 Appendix C) — selected when the constructor is passed one of those OIDs, - PBES2 (RFC 8018) — selected for any other key-encryption algorithm; the embedded
key-derivation function may be PBKDF2 or scrypt (RFC 7914) via an explicit
PBKDFConfig.
-
Constructor Summary
ConstructorsConstructorDescriptionJcePKCSPBEOutputEncryptorBuilder(org.bouncycastle.asn1.ASN1ObjectIdentifier keyEncryptionAlg) Construct a builder for a single algorithm.JcePKCSPBEOutputEncryptorBuilder(org.bouncycastle.crypto.util.PBKDFConfig pbkdfAlgorithm, org.bouncycastle.asn1.ASN1ObjectIdentifier keyEncryptionAlg) Constructor allowing different derivation functions such as PBKDF2 and scrypt. -
Method Summary
Modifier and TypeMethodDescriptionbuild(char[] password) Bind the builder to a password and return a configuredOutputEncryptor.setIterationCount(int iterationCount) Set the iteration count for the PBE calculation.setKeySizeProvider(SecretKeySizeProvider keySizeProvider) Set the lookup provider of AlgorithmIdentifier returning key_size_in_bits used to handle PKCS5 decryption.setPRF(org.bouncycastle.asn1.x509.AlgorithmIdentifier prf) Set the PRF to use for key generation.setProvider(String providerName) setProvider(Provider provider) setRandom(SecureRandom random)
-
Constructor Details
-
JcePKCSPBEOutputEncryptorBuilder
public JcePKCSPBEOutputEncryptorBuilder(org.bouncycastle.asn1.ASN1ObjectIdentifier keyEncryptionAlg) Construct a builder for a single algorithm. IfkeyEncryptionAlgis a PKCS#12 PBE OID, the resulting encryptor uses the PKCS#12 wire profile; otherwise the encryptor uses PBES2 with the default PBKDF2 configuration andkeyEncryptionAlgas the underlying encryption scheme.- Parameters:
keyEncryptionAlg- the algorithm identifier the encryptor should apply.
-
JcePKCSPBEOutputEncryptorBuilder
public JcePKCSPBEOutputEncryptorBuilder(org.bouncycastle.crypto.util.PBKDFConfig pbkdfAlgorithm, org.bouncycastle.asn1.ASN1ObjectIdentifier keyEncryptionAlg) Constructor allowing different derivation functions such as PBKDF2 and scrypt.- Parameters:
pbkdfAlgorithm- key derivation algorithm definition to use.keyEncryptionAlg- encryption algorithm to apply the derived key with.
-
-
Method Details
-
setProvider
-
setProvider
-
setRandom
-
setKeySizeProvider
Set the lookup provider of AlgorithmIdentifier returning key_size_in_bits used to handle PKCS5 decryption.- Parameters:
keySizeProvider- a provider of integer secret key sizes.- Returns:
- the current builder.
-
setPRF
Set the PRF to use for key generation. By default this is HmacSHA1.- Parameters:
prf- algorithm id for PRF.- Returns:
- the current builder.
- Throws:
IllegalStateException- if this builder was intialised with a PBKDFDef
-
setIterationCount
Set the iteration count for the PBE calculation.- Parameters:
iterationCount- the iteration count to apply to the key creation.- Returns:
- the current builder.
- Throws:
IllegalStateException- if this builder was intialised with a PBKDFDef
-
build
Bind the builder to a password and return a configuredOutputEncryptor. Its algorithm identifier carries the freshly generated salt / iteration count / IV in the wire format appropriate to the chosen scheme.- Parameters:
password- the password used to derive the encryption key.- Returns:
- a configured output encryptor.
- Throws:
OperatorCreationException- if a JCECipherorSecretKeyFactorycannot be created for the requested scheme.
-