|
8 | 8 | import java.security.Security; |
9 | 9 | import java.security.cert.X509Certificate; |
10 | 10 | import java.util.Date; |
| 11 | +import java.util.Iterator; |
11 | 12 |
|
12 | 13 | import junit.framework.TestCase; |
13 | 14 | import org.bouncycastle.asn1.ASN1ObjectIdentifier; |
|
23 | 24 | import org.bouncycastle.cert.jcajce.JcaX509v3CertificateBuilder; |
24 | 25 | import org.bouncycastle.cms.jcajce.JcaSignerInfoGeneratorBuilder; |
25 | 26 | import org.bouncycastle.cms.jcajce.JcaSignerInfoVerifierBuilder; |
| 27 | +import org.bouncycastle.jcajce.provider.asymmetric.compositesignatures.CompositeIndex; |
26 | 28 | import org.bouncycastle.jce.provider.BouncyCastleProvider; |
27 | 29 | import org.bouncycastle.operator.ContentSigner; |
28 | 30 | import org.bouncycastle.operator.jcajce.JcaContentSignerBuilder; |
@@ -344,4 +346,88 @@ public void testMLDSA() |
344 | 346 |
|
345 | 347 | assertNotNull("no signingCertificate attribute found", table.get(PKCSObjectIdentifiers.id_aa_signingCertificate)); |
346 | 348 | } |
| 349 | + |
| 350 | + public void testComposite() |
| 351 | + throws Exception |
| 352 | + { |
| 353 | + for (Iterator it = CompositeIndex.getSupportedIdentifiers().iterator(); it.hasNext(); ) |
| 354 | + { |
| 355 | + String name = CompositeIndex.getAlgorithmName((ASN1ObjectIdentifier)it.next()); |
| 356 | + doTestComposite(name); |
| 357 | + } |
| 358 | + } |
| 359 | + |
| 360 | + private void doTestComposite(String algorithmName) |
| 361 | + throws Exception |
| 362 | + { |
| 363 | + // |
| 364 | + // set up the keys |
| 365 | + // |
| 366 | + PrivateKey privKey; |
| 367 | + PublicKey pubKey; |
| 368 | + |
| 369 | + try |
| 370 | + { |
| 371 | + KeyPairGenerator g = KeyPairGenerator.getInstance(algorithmName, BC); |
| 372 | + |
| 373 | + KeyPair p = g.generateKeyPair(); |
| 374 | + |
| 375 | + privKey = p.getPrivate(); |
| 376 | + pubKey = p.getPublic(); |
| 377 | + } |
| 378 | + catch (Exception e) |
| 379 | + { |
| 380 | + fail("error setting up keys - " + e); |
| 381 | + return; |
| 382 | + } |
| 383 | + |
| 384 | + // |
| 385 | + // extensions |
| 386 | + // |
| 387 | + |
| 388 | + // |
| 389 | + // create the certificate - version 1 |
| 390 | + // |
| 391 | + |
| 392 | + ContentSigner sigGen = new JcaContentSignerBuilder(algorithmName) |
| 393 | + .setProvider(BC).build(privKey); |
| 394 | + JcaX509v3CertificateBuilder certGen = new JcaX509v3CertificateBuilder( |
| 395 | + new X500Name("CN=Test"), |
| 396 | + BigInteger.valueOf(1), |
| 397 | + new Date(System.currentTimeMillis() - 50000), |
| 398 | + new Date(System.currentTimeMillis() + 50000), |
| 399 | + new X500Name("CN=Test"), |
| 400 | + pubKey); |
| 401 | + |
| 402 | + certGen.addExtension(Extension.extendedKeyUsage, true, new ExtendedKeyUsage(KeyPurposeId.id_kp_timeStamping)); |
| 403 | + |
| 404 | + X509Certificate cert = new JcaX509CertificateConverter() |
| 405 | + .setProvider("BC").getCertificate(certGen.build(sigGen)); |
| 406 | + |
| 407 | + ContentSigner signer = new JcaContentSignerBuilder(algorithmName).setProvider(BC).build(privKey); |
| 408 | + |
| 409 | + TimeStampTokenGenerator tsTokenGen = new TimeStampTokenGenerator( |
| 410 | + new JcaSignerInfoGeneratorBuilder(new JcaDigestCalculatorProviderBuilder().build()) |
| 411 | + .build(signer, cert), new SHA1DigestCalculator(), new ASN1ObjectIdentifier("1.2")); |
| 412 | + |
| 413 | + // tsTokenGen.addCertificates(certs); |
| 414 | + |
| 415 | + TimeStampRequestGenerator reqGen = new TimeStampRequestGenerator(); |
| 416 | + TimeStampRequest request = reqGen.generate(TSPAlgorithms.SHA3_256, new byte[32], BigInteger.valueOf(100)); |
| 417 | + |
| 418 | + TimeStampResponseGenerator tsRespGen = new TimeStampResponseGenerator(tsTokenGen, TSPAlgorithms.ALLOWED); |
| 419 | + |
| 420 | + TimeStampResponse tsResp = tsRespGen.generate(request, new BigInteger("23"), new Date()); |
| 421 | + |
| 422 | + tsResp = new TimeStampResponse(tsResp.getEncoded()); |
| 423 | + |
| 424 | + TimeStampToken tsToken = tsResp.getTimeStampToken(); |
| 425 | + |
| 426 | + tsToken.validate(new JcaSignerInfoVerifierBuilder(new JcaDigestCalculatorProviderBuilder().build()) |
| 427 | + .setProvider(BC).build(cert)); |
| 428 | + |
| 429 | + AttributeTable table = tsToken.getSignedAttributes(); |
| 430 | + |
| 431 | + assertNotNull("no signingCertificate attribute found", table.get(PKCSObjectIdentifiers.id_aa_signingCertificate)); |
| 432 | + } |
347 | 433 | } |
0 commit comments