FileDocCategorySizeDatePackage
JDKX509CertificateFactory.javaAPI DocAndroid 1.5 API13912Wed May 06 22:41:06 BST 2009org.bouncycastle.jce.provider

JDKX509CertificateFactory

public class JDKX509CertificateFactory extends CertificateFactorySpi
class for dealing with X509 certificates.

At the moment this will deal with "-----BEGIN CERTIFICATE-----" to "-----END CERTIFICATE-----" base 64 encoded certs, as well as the BER binaries of certificates and some classes of PKCS#7 objects.

Fields Summary
private static final long
MAX_MEMORY
private org.bouncycastle.asn1.pkcs.SignedData
sData
private int
sDataObjectCount
private InputStream
currentStream
private org.bouncycastle.asn1.pkcs.SignedData
sCrlData
private int
sCrlDataObjectCount
private InputStream
currentCrlStream
Constructors Summary
Methods Summary
public java.security.cert.CRLengineGenerateCRL(java.io.InputStream inStream)
Generates a certificate revocation list (CRL) object and initializes it with the data read from the input stream inStream.

        if (currentCrlStream == null)
        {
            currentCrlStream = inStream;
            sCrlData = null;
            sCrlDataObjectCount = 0;
        }
        else if (currentCrlStream != inStream) // reset if input stream has changed
        {
            currentCrlStream = inStream;
            sCrlData = null;
            sCrlDataObjectCount = 0;
        }

        try
        {
            if (sCrlData != null)
            {
                if (sCrlDataObjectCount != sCrlData.getCertificates().size())
                {
                    return new X509CRLObject(
                                CertificateList.getInstance(
                                        sCrlData.getCRLs().getObjectAt(sCrlDataObjectCount++)));
                }
                else
                {
                    sCrlData = null;
                    sCrlDataObjectCount = 0;
                    return null;
                }
            }
            
            if (!inStream.markSupported())
            {
                // BEGIN android-modified
                inStream = new BufferedInputStream(inStream, 8192);
                // END android-modified
            }
            
            inStream.mark(10);
            if (inStream.read() != 0x30)  // assume ascii PEM encoded.
            {
                inStream.reset();
                return readPEMCRL(inStream);
            }
            else if (inStream.read() == 0x80)    // assume BER encoded.
            {
                inStream.reset();
                return readPKCS7CRL(inStream);
            }
            else
            {
                inStream.reset();
                return readDERCRL(new ASN1InputStream(inStream, getLimit(inStream)));
            }
        }
        catch (CRLException e)
        {
            throw e;
        }
        catch (Exception e)
        {
            throw new CRLException(e.toString());
        }
    
public java.util.CollectionengineGenerateCRLs(java.io.InputStream inStream)
Returns a (possibly empty) collection view of the CRLs read from the given input stream inStream. The inStream may contain a sequence of DER-encoded CRLs, or a PKCS#7 CRL set. This is a PKCS#7 SignedData object, with the only signficant field being crls. In particular the signature and the contents are ignored.

        CRL     crl;
        List    crls = new ArrayList();

        while ((crl = engineGenerateCRL(inStream)) != null)
        {
            crls.add(crl);
        }

        return crls;
    
public java.security.cert.CertPathengineGenerateCertPath(java.io.InputStream inStream)

        return engineGenerateCertPath(inStream, "PkiPath");
    
public java.security.cert.CertPathengineGenerateCertPath(java.io.InputStream inStream, java.lang.String encoding)

        return new PKIXCertPath(inStream, encoding);
    
public java.security.cert.CertPathengineGenerateCertPath(java.util.List certificates)

        Iterator iter = certificates.iterator();
        Object obj;
        while (iter.hasNext())
        {
            obj = iter.next();
            if (obj != null)
            {
                if (!(obj instanceof X509Certificate))
                {
                    throw new CertificateException("list contains none X509Certificate object while creating CertPath\n" + obj.toString());
                }
            }
        }
        return new PKIXCertPath(certificates);
    
public java.security.cert.CertificateengineGenerateCertificate(java.io.InputStream in)
Generates a certificate object and initializes it with the data read from the input stream inStream.

        if (currentStream == null)
        {
            currentStream = in;
            sData = null;
            sDataObjectCount = 0;
        }
        else if (currentStream != in) // reset if input stream has changed
        {
            currentStream = in;
            sData = null;
            sDataObjectCount = 0;
        }

        try
        {
            if (sData != null)
            {
                if (sDataObjectCount != sData.getCertificates().size())
                {
                    return new X509CertificateObject(
                                X509CertificateStructure.getInstance(
                                        sData.getCertificates().getObjectAt(sDataObjectCount++)));
                }
                else
                {
                    sData = null;
                    sDataObjectCount = 0;
                    return null;
                }
            }
            
            if (!in.markSupported())
            {
                // BEGIN android-modified
                in = new BufferedInputStream(in, 8192);
                // END android-modified
            }
            
            in.mark(10);
            int    tag = in.read();
            
            if (tag == -1)
            {
                return null;
            }
            
            if (tag != 0x30)  // assume ascii PEM encoded.
            {
                in.reset();
                return readPEMCertificate(in);
            }
            else if (in.read() == 0x80)    // assume BER encoded.
            {
                in.reset();
                return readPKCS7Certificate(new ASN1InputStream(in, getLimit(in)));
            }
            else
            {
                in.reset();
                return readDERCertificate(new ASN1InputStream(in, getLimit(in)));
            }
        }
        catch (Exception e)
        {
            throw new CertificateException(e.toString());
        }
    
public java.util.CollectionengineGenerateCertificates(java.io.InputStream inStream)
Returns a (possibly empty) collection view of the certificates read from the given input stream inStream.

        Certificate     cert;
        List            certs = new ArrayList();

        while ((cert = engineGenerateCertificate(inStream)) != null)
        {
            certs.add(cert);
        }

        return certs;
    
public java.util.IteratorengineGetCertPathEncodings()

        return PKIXCertPath.certPathEncodings.iterator();
    
private intgetLimit(java.io.InputStream in)


       
         
    
        if (in instanceof ByteArrayInputStream)
        {
            return in.available();
        }
        
        if (MAX_MEMORY > Integer.MAX_VALUE)
        {
            return Integer.MAX_VALUE;
        }
        
        return (int)MAX_MEMORY;
    
private java.security.cert.CRLreadDERCRL(org.bouncycastle.asn1.ASN1InputStream dIn)

        return new X509CRLObject(new CertificateList((ASN1Sequence)dIn.readObject()));
    
private java.security.cert.CertificatereadDERCertificate(org.bouncycastle.asn1.ASN1InputStream dIn)

        ASN1Sequence    seq = (ASN1Sequence)dIn.readObject();

        if (seq.size() > 1
                && seq.getObjectAt(0) instanceof DERObjectIdentifier)
        {
            if (seq.getObjectAt(0).equals(PKCSObjectIdentifiers.signedData))
            {
                sData = new SignedData(ASN1Sequence.getInstance(
                                (ASN1TaggedObject)seq.getObjectAt(1), true));

                return new X509CertificateObject(
                            X509CertificateStructure.getInstance(
                                    sData.getCertificates().getObjectAt(sDataObjectCount++)));
            }
        }

        return new X509CertificateObject(
                            X509CertificateStructure.getInstance(seq));
    
private java.lang.StringreadLine(java.io.InputStream in)

        int             c;
        StringBuffer    l = new StringBuffer();

        while (((c = in.read()) != '\n") && (c >= 0))
        {
            if (c == '\r")
            {
                continue;
            }

            l.append((char)c);
        }

        if (c < 0)
        {
            return null;
        }

        return l.toString();
    
private java.security.cert.CRLreadPEMCRL(java.io.InputStream in)

        String          line;
        StringBuffer    pemBuf = new StringBuffer();

        while ((line = readLine(in)) != null)
        {
            if (line.equals("-----BEGIN CRL-----")
                || line.equals("-----BEGIN X509 CRL-----"))
            {
                break;
            }
        }

        while ((line = readLine(in)) != null)
        {
            if (line.equals("-----END CRL-----")
                || line.equals("-----END X509 CRL-----"))
            {
                break;
            }

            pemBuf.append(line);
        }

        if (pemBuf.length() != 0)
        {
            return readDERCRL(new ASN1InputStream(Base64.decode(pemBuf.toString())));
        }

        return null;
    
private java.security.cert.CertificatereadPEMCertificate(java.io.InputStream in)

        String          line;
        StringBuffer    pemBuf = new StringBuffer();

        while ((line = readLine(in)) != null)
        {
            if (line.equals("-----BEGIN CERTIFICATE-----")
                || line.equals("-----BEGIN X509 CERTIFICATE-----"))
            {
                break;
            }
        }

        while ((line = readLine(in)) != null)
        {
            if (line.equals("-----END CERTIFICATE-----")
                || line.equals("-----END X509 CERTIFICATE-----"))
            {
                break;
            }

            pemBuf.append(line);
        }

        if (pemBuf.length() != 0)
        {
            return readDERCertificate(new ASN1InputStream(Base64.decode(pemBuf.toString())));
        }

        return null;
    
private java.security.cert.CRLreadPKCS7CRL(java.io.InputStream in)

        ASN1InputStream  dIn = new ASN1InputStream(in, getLimit(in));
        ASN1Sequence     seq = (ASN1Sequence)dIn.readObject();

        if (seq.size() > 1
                && seq.getObjectAt(0) instanceof DERObjectIdentifier)
        {
            if (seq.getObjectAt(0).equals(PKCSObjectIdentifiers.signedData))
            {
                sCrlData = new SignedData(ASN1Sequence.getInstance(
                                (ASN1TaggedObject)seq.getObjectAt(1), true));
    
                return new X509CRLObject(
                            CertificateList.getInstance(
                                    sCrlData.getCRLs().getObjectAt(sCrlDataObjectCount++)));
            }
        }

        return new X509CRLObject(
                     CertificateList.getInstance(seq));
    
private java.security.cert.CertificatereadPKCS7Certificate(java.io.InputStream in)
read in a BER encoded PKCS7 certificate.

        ASN1InputStream  dIn = new ASN1InputStream(in, getLimit(in));
        ASN1Sequence     seq = (ASN1Sequence)dIn.readObject();

        if (seq.size() > 1
                && seq.getObjectAt(0) instanceof DERObjectIdentifier)
        {
            if (seq.getObjectAt(0).equals(PKCSObjectIdentifiers.signedData))
            {
                sData = new SignedData(ASN1Sequence.getInstance(
                                (ASN1TaggedObject)seq.getObjectAt(1), true));
    
                return new X509CertificateObject(
                            X509CertificateStructure.getInstance(
                                    sData.getCertificates().getObjectAt(sDataObjectCount++)));
            }
        }

        return new X509CertificateObject(
                     X509CertificateStructure.getInstance(seq));