Class CoseKey
A credential's public key as an authenticator sends it -- a COSE_Key, RFC
9052 -- turned into what Crypto.verify(String, byte[], byte[], byte[]) takes: an algorithm name and a
SubjectPublicKeyInfo.
Two kinds of key are read, the two every platform authenticator offers:
| COSE algorithm | Key | Verified as |
|---|---|---|
| -7, ES256 | EC2 on P-256, uncompressed | Crypto.ES256 |
| -257, RS256 | RSA of 2048 bits or more | Crypto.RS256 |
Any other algorithm is refused with
WebAuthnException.UNSUPPORTED_ALGORITHM -- EdDSA (-8) among them, which
the server's cryptography does not verify -- and a key that names one of
the two and is not such a key with WebAuthnException.INVALID_KEY. The
registration options offer only these two, so a conforming authenticator
answers with nothing else.
-
Field Summary
Fields -
Method Summary
Modifier and TypeMethodDescriptionlongbyte[]The key as a SubjectPublicKeyInfo, in DER.static CoseKeyof(long algorithm, byte[] publicKey) The key read from stored bytes: whatgetPublicKey()returned.booleanverify(byte[] data, byte[] signature) Whethersignatureis this key's signature ofdata.
-
Field Details
-
ES256
public static final long ES256The COSE identifier of ES256: ECDSA on P-256 with SHA-256.- See Also:
-
RS256
public static final long RS256The COSE identifier of RS256: RSASSA-PKCS1-v1_5 with SHA-256.- See Also:
-
-
Method Details
-
of
The key read from stored bytes: what
getPublicKey()returned.WebAuthnException: whenalgorithmis not one this server verifies
-
getAlgorithm
-
getPublicKey
public byte[] getPublicKey()The key as a SubjectPublicKeyInfo, in DER. -
verify
public boolean verify(byte[] data, byte[] signature) Whether
signatureis this key's signature ofdata. An ES256 signature is ASN.1 DER, as an authenticator sends it.WebAuthnException:WebAuthnException.INVALID_KEYwhen the key cannot be used at all, which is not the same as a signature that is wrong
-