Class Der
The little ASN.1 DER a server needs to move keys and signatures between the
shapes they travel in: a JSON Web Key's numbers and the SubjectPublicKeyInfo
that Crypto.verify(String, byte[], byte[], byte[]) takes; a PKCS#1 or SEC 1 private
key out of an older PEM file and the PKCS#8 that
Crypto.sign(String, byte[], byte[]) takes; an ECDSA signature as OpenSSL and
the JDK write it and as a JSON Web Signature carries it.
byte[] publicKey = Der.rsaPublicKey(modulus, exponent); // from a JWK's n and e
byte[] jose = Der.ecdsaDerToJose(Crypto.sign(Crypto.ES256, key, data), 32);
Nothing here computes with a key. It reads and writes the envelope, and
refuses one that is not exactly what it expects with an IOException.
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final StringThe key type of an elliptic curve key, as a JSON Web Key names it.static final StringThe curve of ES256, as a JSON Web Key names it.static final StringThe curve of ES384, as a JSON Web Key names it.static final StringThe key type of an RSA key, as a JSON Web Key names it. -
Method Summary
Modifier and TypeMethodDescriptionstatic intecCoordinateLength(String curve) static StringecCurve(byte[] publicKey) static byte[]ecdsaDerToJose(byte[] der, int partLength) An ECDSA signature as a JSON Web Signature carries it -- r and s side by side, each padded to the curve's size -- from the ASN.1 DER thatCrypto.sign(String, byte[], byte[])returns.static byte[]ecdsaJoseToDer(byte[] jose) The ASN.1 DERCrypto.verify(String, byte[], byte[], byte[])takes, from an ECDSA signature as a JSON Web Signature carries it.static byte[]ecPublicKey(String curve, byte[] x, byte[] y) static byte[][]ecPublicKeyParts(byte[] publicKey) The two coordinates of an EC SubjectPublicKeyInfo's point, each as long asecCoordinateLength(String)says.static byte[]pkcs1ToPkcs8(byte[] rsaPrivateKey) Wraps a PKCS#1RSAPrivateKey-- the content of a PEM file that saysRSA PRIVATE KEY-- as PKCS#8.static StringprivateKeyType(byte[] privateKey) static byte[]publicKeyOf(byte[] privateKey) The public half of a PKCS#8 private key, as a SubjectPublicKeyInfo.static StringpublicKeyType(byte[] publicKey) static intrsaModulusBits(byte[] publicKey) The size of an RSA public key: the bits of its modulus.static byte[]rsaPublicKey(byte[] modulus, byte[] exponent) The SubjectPublicKeyInfo of an RSA public key.static byte[][]rsaPublicKeyParts(byte[] publicKey) The modulus and the public exponent of an RSA SubjectPublicKeyInfo, each an unsigned big-endian number without leading zeros.static byte[]sec1ToPkcs8(byte[] ecPrivateKey) Wraps a SEC 1ECPrivateKey-- the content of a PEM file that saysEC PRIVATE KEY-- as PKCS#8.
-
Field Details
-
RSA
-
EC
The key type of an elliptic curve key, as a JSON Web Key names it.- See Also:
-
P256
-
P384
-
-
Method Details
-
rsaPublicKey
The SubjectPublicKeyInfo of an RSA public key.- Parameters:
modulus- the modulus as an unsigned big-endian number, as a JWK'sndecodesexponent- the public exponent, likewise: a JWK'se- Throws:
IOException
-
rsaPublicKeyParts
The modulus and the public exponent of an RSA SubjectPublicKeyInfo, each an unsigned big-endian number without leading zeros.- Throws:
IOException
-
rsaModulusBits
The size of an RSA public key: the bits of its modulus.- Throws:
IOException
-
ecPublicKey
- Parameters:
curve- the curve as a JWK'scrvnames itx- the point's first coordinate, big-endian: a JWK'sxy- its second: a JWK'sy- Throws:
IOException
-
ecCurve
- Throws:
IOException
-
ecPublicKeyParts
The two coordinates of an EC SubjectPublicKeyInfo's point, each as long asecCoordinateLength(String)says.- Throws:
IOException
-
ecCoordinateLength
The bytes one coordinate -- and each half of a JOSE signature -- takes on a curve: 32 onP256, 48 onP384.- Throws:
IOException
-
publicKeyType
- Throws:
IOException
-
privateKeyType
- Throws:
IOException
-
publicKeyOf
The public half of a PKCS#8 private key, as a SubjectPublicKeyInfo.
An RSA private key always holds its public numbers. An EC private key holds its public point only when whatever wrote it put it there, which openssl does; one that does not is refused, and its public key has to be given beside it.
- Throws:
IOException
-
pkcs1ToPkcs8
Wraps a PKCS#1RSAPrivateKey-- the content of a PEM file that saysRSA PRIVATE KEY-- as PKCS#8.- Throws:
IOException
-
sec1ToPkcs8
Wraps a SEC 1ECPrivateKey-- the content of a PEM file that saysEC PRIVATE KEY-- as PKCS#8. The key has to name its curve, as one openssl wrote does.- Throws:
IOException
-
ecdsaDerToJose
An ECDSA signature as a JSON Web Signature carries it -- r and s side by side, each padded to the curve's size -- from the ASN.1 DER thatCrypto.sign(String, byte[], byte[])returns.- Parameters:
partLength-ecCoordinateLength(String)of the key's curve- Throws:
IOException
-
ecdsaJoseToDer
The ASN.1 DERCrypto.verify(String, byte[], byte[], byte[])takes, from an ECDSA signature as a JSON Web Signature carries it.- Throws:
IOException
-