Class OpenSSHPrivateKeySpec

java.lang.Object
java.security.spec.EncodedKeySpec
org.bouncycastle.jcajce.spec.OpenSSHPrivateKeySpec
All Implemented Interfaces:
KeySpec

public class OpenSSHPrivateKeySpec extends EncodedKeySpec
OpenSSHPrivateKeySpec holds and encoded OpenSSH private key. The format of the key can be either ASN.1 or OpenSSH.
  • Constructor Details

    • OpenSSHPrivateKeySpec

      public OpenSSHPrivateKeySpec(byte[] encodedKey)
      Accept an encoded key and determine the format.

      The encoded key should be the Base64 decoded blob between the "---BEGIN and ---END" markers. This constructor will endeavour to find the OpenSSH format magic value. If it can not then it will default to ASN.1. It does not attempt to validate the ASN.1

      Example: OpenSSHPrivateKeySpec privSpec = new OpenSSHPrivateKeySpec(rawPriv);

      KeyFactory kpf = KeyFactory.getInstance("RSA", "BC"); PrivateKey prk = kpf.generatePrivate(privSpec);

      OpenSSHPrivateKeySpec rcPrivateSpec = kpf.getKeySpec(prk, OpenSSHPrivateKeySpec.class);

      Parameters:
      encodedKey - The encoded key.
    • OpenSSHPrivateKeySpec

      public OpenSSHPrivateKeySpec(byte[] encodedKey, char[] password)
      Accept an encoded key, determine the format, and carry the passphrase used to decrypt a passphrase-protected openssh-key-v1 key.

      Only the openssh-key-v1 format supports encryption; for an unencrypted key (or the ASN.1 format) the password is ignored and may be null. The password characters are used as their UTF-8 bytes, matching the OpenSSH client.

      Parameters:
      encodedKey - The encoded key.
      password - The passphrase, or null for an unencrypted key.
  • Method Details

    • getFormat

      public String getFormat()
      Return the format, either OpenSSH for the OpenSSH propriety format or ASN.1.
      Specified by:
      getFormat in class EncodedKeySpec
      Returns:
      the format OpenSSH or ASN.1
    • getPassword

      public char[] getPassword()
      Return the passphrase used to decrypt an encrypted openssh-key-v1 key, or null if none was supplied.
      Returns:
      the passphrase, or null.