Class CMSAuthEnvelopedDataStreamGenerator


  • public class CMSAuthEnvelopedDataStreamGenerator
    extends CMSAuthEnvelopedGenerator
    Generate authenticated enveloped CMS data with streaming support.

    When using this generator, note:

    • The returned OutputStream must be closed to finalize encryption and authentication
    • Closing the returned stream does not close the underlying OutputStream passed to open()
    • Callers are responsible for closing the underlying OutputStream separately
    • Constructor Detail

      • CMSAuthEnvelopedDataStreamGenerator

        public CMSAuthEnvelopedDataStreamGenerator()
    • Method Detail

      • setBufferSize

        public void setBufferSize​(int bufferSize)
        Set the underlying string size for encapsulated data
        Parameters:
        bufferSize - length of octet strings to buffer the data.
      • setBEREncodeRecipients

        public void setBEREncodeRecipients​(boolean berEncodeRecipientSet)
        Use a BER Set to store the recipient information
      • open

        protected java.io.OutputStream open​(org.bouncycastle.asn1.ASN1ObjectIdentifier dataType,
                                            java.io.OutputStream out,
                                            org.bouncycastle.asn1.ASN1EncodableVector recipientInfos,
                                            OutputAEADEncryptor encryptor)
                                     throws java.io.IOException
        Throws:
        java.io.IOException
      • open

        public java.io.OutputStream open​(java.io.OutputStream out,
                                         OutputAEADEncryptor encryptor)
                                  throws CMSException,
                                         java.io.IOException
        Generate authenticated-enveloped-data using the given encryptor, and marking the encapsulated bytes as being of type DATA.

        Stream handling note: Closing the returned stream finalizes the CMS structure but does not close the underlying output stream. The caller remains responsible for managing the lifecycle of out.

        Parameters:
        out - the output stream to write the CMS structure to
        encryptor - the cipher to use for encryption
        Returns:
        an output stream that writes encrypted and authenticated content
        Throws:
        CMSException
        java.io.IOException
      • open

        public java.io.OutputStream open​(org.bouncycastle.asn1.ASN1ObjectIdentifier dataType,
                                         java.io.OutputStream out,
                                         OutputAEADEncryptor encryptor)
                                  throws CMSException,
                                         java.io.IOException
        Generate authenticated-enveloped-data using the given encryptor, and marking the encapsulated bytes as being of the passed in type.

        Stream handling note: Closing the returned stream finalizes the CMS structure but does not close the underlying output stream. The caller remains responsible for managing the lifecycle of out.

        Parameters:
        dataType - the type of the data being written to the object.
        out - the output stream to write the CMS structure to
        encryptor - the cipher to use for encryption
        Returns:
        an output stream that writes encrypted and authenticated content
        Throws:
        CMSException
        java.io.IOException
      • open

        public java.io.OutputStream open​(java.io.OutputStream out,
                                         long inputLength,
                                         OutputAEADEncryptor encryptor)
                                  throws CMSException,
                                         java.io.IOException
        Generate an authenticated-enveloped object for inputLength content octets, using the given encryptor. In definite-length mode (see CMSEnvelopedGenerator.setEncoding(String)) the length is used to pre-compute every enclosing header, so exactly that many content octets must then be written to the returned stream - a mismatch fails with an IOException, by which point the output is unusable and must be discarded. In BER mode the length is ignored.

        In definite-length mode the buffer size and BER recipient set settings are ignored (an indefinite-length encoding may not appear inside a definite-length one). Nothing is buffered, so content larger than a Java array can carry is supported. Note that in this mode any authenticated attributes are generated and fed to the encryptor's AAD stream at open() time, ahead of the content - the order AEAD modes require.

        Throws:
        CMSException
        java.io.IOException