Class Der

java.lang.Object
com.codename1.backend.security.crypto.Der

public final class Der extends Object

The little ASN.1 DER a server needs to move keys and signatures between the shapes they travel in: a JSON Web Key's numbers and the SubjectPublicKeyInfo that Crypto.verify(String, byte[], byte[], byte[]) takes; a PKCS#1 or SEC 1 private key out of an older PEM file and the PKCS#8 that Crypto.sign(String, byte[], byte[]) takes; an ECDSA signature as OpenSSL and the JDK write it and as a JSON Web Signature carries it.

byte[] publicKey = Der.rsaPublicKey(modulus, exponent);      // from a JWK's n and e
byte[] jose = Der.ecdsaDerToJose(Crypto.sign(Crypto.ES256, key, data), 32);

Nothing here computes with a key. It reads and writes the envelope, and refuses one that is not exactly what it expects with an IOException.

  • Field Summary

    Fields
    Modifier and Type
    Field
    Description
    static final String
    The key type of an elliptic curve key, as a JSON Web Key names it.
    static final String
    The curve of ES256, as a JSON Web Key names it.
    static final String
    The curve of ES384, as a JSON Web Key names it.
    static final String
    The key type of an RSA key, as a JSON Web Key names it.
  • Method Summary

    Modifier and Type
    Method
    Description
    static int
    The bytes one coordinate -- and each half of a JOSE signature -- takes on a curve: 32 on P256, 48 on P384.
    static String
    ecCurve(byte[] publicKey)
    The curve of an EC SubjectPublicKeyInfo: P256 or P384.
    static byte[]
    ecdsaDerToJose(byte[] der, int partLength)
    An ECDSA signature as a JSON Web Signature carries it -- r and s side by side, each padded to the curve's size -- from the ASN.1 DER that Crypto.sign(String, byte[], byte[]) returns.
    static byte[]
    ecdsaJoseToDer(byte[] jose)
    The ASN.1 DER Crypto.verify(String, byte[], byte[], byte[]) takes, from an ECDSA signature as a JSON Web Signature carries it.
    static byte[]
    ecPublicKey(String curve, byte[] x, byte[] y)
    The SubjectPublicKeyInfo of a public key on P256 or P384.
    static byte[][]
    ecPublicKeyParts(byte[] publicKey)
    The two coordinates of an EC SubjectPublicKeyInfo's point, each as long as ecCoordinateLength(String) says.
    static byte[]
    pkcs1ToPkcs8(byte[] rsaPrivateKey)
    Wraps a PKCS#1 RSAPrivateKey -- the content of a PEM file that says RSA PRIVATE KEY -- as PKCS#8.
    static String
    privateKeyType(byte[] privateKey)
    RSA or EC: what a PKCS#8 private key is the key of.
    static byte[]
    publicKeyOf(byte[] privateKey)
    The public half of a PKCS#8 private key, as a SubjectPublicKeyInfo.
    static String
    publicKeyType(byte[] publicKey)
    RSA or EC: what a SubjectPublicKeyInfo is the key of.
    static int
    rsaModulusBits(byte[] publicKey)
    The size of an RSA public key: the bits of its modulus.
    static byte[]
    rsaPublicKey(byte[] modulus, byte[] exponent)
    The SubjectPublicKeyInfo of an RSA public key.
    static byte[][]
    rsaPublicKeyParts(byte[] publicKey)
    The modulus and the public exponent of an RSA SubjectPublicKeyInfo, each an unsigned big-endian number without leading zeros.
    static byte[]
    sec1ToPkcs8(byte[] ecPrivateKey)
    Wraps a SEC 1 ECPrivateKey -- the content of a PEM file that says EC PRIVATE KEY -- as PKCS#8.

    Methods inherited from class Object

    clone, equals, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Field Details

  • Method Details

    • rsaPublicKey

      public static byte[] rsaPublicKey(byte[] modulus, byte[] exponent) throws IOException
      The SubjectPublicKeyInfo of an RSA public key.
      Parameters:
      modulus - the modulus as an unsigned big-endian number, as a JWK's n decodes
      exponent - the public exponent, likewise: a JWK's e
      Throws:
      IOException
    • rsaPublicKeyParts

      public static byte[][] rsaPublicKeyParts(byte[] publicKey) throws IOException
      The modulus and the public exponent of an RSA SubjectPublicKeyInfo, each an unsigned big-endian number without leading zeros.
      Throws:
      IOException
    • rsaModulusBits

      public static int rsaModulusBits(byte[] publicKey) throws IOException
      The size of an RSA public key: the bits of its modulus.
      Throws:
      IOException
    • ecPublicKey

      public static byte[] ecPublicKey(String curve, byte[] x, byte[] y) throws IOException
      The SubjectPublicKeyInfo of a public key on P256 or P384.
      Parameters:
      curve - the curve as a JWK's crv names it
      x - the point's first coordinate, big-endian: a JWK's x
      y - its second: a JWK's y
      Throws:
      IOException
    • ecCurve

      public static String ecCurve(byte[] publicKey) throws IOException
      The curve of an EC SubjectPublicKeyInfo: P256 or P384.
      Throws:
      IOException
    • ecPublicKeyParts

      public static byte[][] ecPublicKeyParts(byte[] publicKey) throws IOException
      The two coordinates of an EC SubjectPublicKeyInfo's point, each as long as ecCoordinateLength(String) says.
      Throws:
      IOException
    • ecCoordinateLength

      public static int ecCoordinateLength(String curve) throws IOException
      The bytes one coordinate -- and each half of a JOSE signature -- takes on a curve: 32 on P256, 48 on P384.
      Throws:
      IOException
    • publicKeyType

      public static String publicKeyType(byte[] publicKey) throws IOException
      RSA or EC: what a SubjectPublicKeyInfo is the key of.
      Throws:
      IOException
    • privateKeyType

      public static String privateKeyType(byte[] privateKey) throws IOException
      RSA or EC: what a PKCS#8 private key is the key of.
      Throws:
      IOException
    • publicKeyOf

      public static byte[] publicKeyOf(byte[] privateKey) throws IOException

      The public half of a PKCS#8 private key, as a SubjectPublicKeyInfo.

      An RSA private key always holds its public numbers. An EC private key holds its public point only when whatever wrote it put it there, which openssl does; one that does not is refused, and its public key has to be given beside it.

      Throws:
      IOException
    • pkcs1ToPkcs8

      public static byte[] pkcs1ToPkcs8(byte[] rsaPrivateKey) throws IOException
      Wraps a PKCS#1 RSAPrivateKey -- the content of a PEM file that says RSA PRIVATE KEY -- as PKCS#8.
      Throws:
      IOException
    • sec1ToPkcs8

      public static byte[] sec1ToPkcs8(byte[] ecPrivateKey) throws IOException
      Wraps a SEC 1 ECPrivateKey -- the content of a PEM file that says EC PRIVATE KEY -- as PKCS#8. The key has to name its curve, as one openssl wrote does.
      Throws:
      IOException
    • ecdsaDerToJose

      public static byte[] ecdsaDerToJose(byte[] der, int partLength) throws IOException
      An ECDSA signature as a JSON Web Signature carries it -- r and s side by side, each padded to the curve's size -- from the ASN.1 DER that Crypto.sign(String, byte[], byte[]) returns.
      Parameters:
      partLength - ecCoordinateLength(String) of the key's curve
      Throws:
      IOException
    • ecdsaJoseToDer

      public static byte[] ecdsaJoseToDer(byte[] jose) throws IOException
      The ASN.1 DER Crypto.verify(String, byte[], byte[], byte[]) takes, from an ECDSA signature as a JSON Web Signature carries it.
      Throws:
      IOException