Class BcPasswordRecipient

    • Method Detail

      • setPasswordConversionScheme

        public BcPasswordRecipient setPasswordConversionScheme​(int schemeID)
      • setAllowedContentAlgorithms

        public BcPasswordRecipient setAllowedContentAlgorithms​(java.util.Set<org.bouncycastle.asn1.ASN1ObjectIdentifier> allowedContentAlgorithms)
        Set the content-encryption algorithms this recipient is willing to unwrap a key for. When set, an attempt to recover content protected under any other algorithm is rejected, mitigating an attacker substituting a weaker content-encryption algorithm into the recipient info.
        Parameters:
        allowedContentAlgorithms - the set of permitted content-encryption algorithm OIDs.
        Returns:
        this recipient.
      • extractSecretKey

        protected org.bouncycastle.crypto.params.KeyParameter extractSecretKey​(org.bouncycastle.asn1.x509.AlgorithmIdentifier keyEncryptionAlgorithm,
                                                                               org.bouncycastle.asn1.x509.AlgorithmIdentifier contentEncryptionAlgorithm,
                                                                               byte[] derivedKey,
                                                                               byte[] encryptedContentEncryptionKey)
                                                                        throws CMSException
        Throws:
        CMSException