Class Jwk
java.lang.Object
com.codename1.backend.security.crypto.Jwk
One key, as a JSON Web Key describes it (RFC 7517): an RSA key, an EC key on P-256 or P-384, or a shared secret.
Jwk signing = Jwk.ofPrivateKey(KeyFiles.readPrivateKey("/etc/app/signing.pem"));
Map<String, Object> published = signing.toPublicJson(); // n and e, never d
Jwk theirs = Jwk.parse(Json.parseObject(text));
Inside, a key is held in the form the runtime computes with -- PKCS#8 and SubjectPublicKeyInfo -- and the JSON form is made and read at the edges.
A key has an id. Unless one is given it is the base64url SHA-256 of the SubjectPublicKeyInfo, so the same key has the same id wherever it is loaded and a rotated key has a new one without anybody naming it.
-
Field Summary
Fields -
Method Summary
Modifier and TypeMethodDescriptionThe one algorithm the key is for, or null when it is for any its type allows.getCurve()P-256orP-384for an EC key; null otherwise.getKeyId()The id given, or else the base64url SHA-256 of the SubjectPublicKeyInfo; null for a shared secret that was given none.RSA,ECoroct.byte[]The PKCS#8 private key, or the bytes of a shared secret; null for a key that only verifies.byte[]The SubjectPublicKeyInfo; null for a shared secret.getUse()The declared use, or null.booleanWhether the key can sign.static JwkofKeyPair(byte[] privateKey, byte[] publicKey) A key that signs and verifies, from a PKCS#8 private key and its SubjectPublicKeyInfo.static JwkThe key in a PEM text: a private key of any of the formsKeyFilesreads, or a public key.static JwkofPrivateKey(byte[] privateKey) A key that signs and verifies, from a PKCS#8 private key that holds its public half; seeDer.publicKeyOf(byte[]).static JwkofPublicKey(byte[] publicKey) A key that verifies, from a SubjectPublicKeyInfo.static JwkofSecret(byte[] secret) A shared secret, for the HMAC algorithms.static JwkThe public key a JSON Web Key describes.The key as the JSON a key set publishes: its type, id and public numbers, withalgandusewhen it has them.toString()Returns a string representation of the object.withAlgorithm(String algorithm) This key for one algorithm alone:RS256.This key under another id.This key with a declared use:sig.
-
Field Details
-
OCT
-
-
Method Details
-
ofPublicKey
A key that verifies, from a SubjectPublicKeyInfo.- Throws:
IOException
-
ofPrivateKey
A key that signs and verifies, from a PKCS#8 private key that holds its public half; seeDer.publicKeyOf(byte[]).- Throws:
IOException
-
ofKeyPair
A key that signs and verifies, from a PKCS#8 private key and its SubjectPublicKeyInfo.- Throws:
IOException
-
ofSecret
A shared secret, for the HMAC algorithms. It has no id unless given one, and is never written to JSON. -
ofPem
The key in a PEM text: a private key of any of the formsKeyFilesreads, or a public key.- Throws:
IOException
-
parse
The public key a JSON Web Key describes. Only what verifies is read: adin the JSON is ignored, and a shared secret is refused.- Throws:
IOException- when the JSON is not an RSA key or an EC key on P-256 or P-384, with what is wrong
-
withKeyId
-
withAlgorithm
-
withUse
-
getKeyType
RSA,ECoroct. -
getCurve
P-256orP-384for an EC key; null otherwise. -
getKeyId
The id given, or else the base64url SHA-256 of the SubjectPublicKeyInfo; null for a shared secret that was given none. -
getAlgorithm
The one algorithm the key is for, or null when it is for any its type allows. -
getUse
The declared use, or null. -
getPublicKey
public byte[] getPublicKey()The SubjectPublicKeyInfo; null for a shared secret. -
getPrivateKey
public byte[] getPrivateKey()The PKCS#8 private key, or the bytes of a shared secret; null for a key that only verifies. -
isPrivate
public boolean isPrivate()Whether the key can sign. -
toPublicJson
The key as the JSON a key set publishes: its type, id and public numbers, withalgandusewhen it has them. Nothing private is ever in it.- Throws:
IllegalStateException- for a shared secret, which has no public form
-
toString
Description copied from class:ObjectReturns a string representation of the object. In general, the toString method returns a string that "textually represents" this object. The result should be a concise but informative representation that is easy for a person to read. It is recommended that all subclasses override this method. The toString method for class Object returns a string consisting of the name of the class of which the object is an instance, the at-sign character `@', and the unsigned hexadecimal representation of the hash code of the object. In other words, this method returns a string equal to the value of: getClass().getName() + '@' + Integer.toHexString(hashCode())
-