Class JcaMTCCosigner

  • All Implemented Interfaces:
    MTCCosigner

    public class JcaMTCCosigner
    extends java.lang.Object
    implements MTCCosigner
    JCA-side implementation of MTCCosigner for the MTC signature algorithms enumerated in Section 6.1 of draft-ietf-plants-merkle-tree-certs: "ECDSA-P256-SHA256", "ECDSA-P384-SHA384", "Ed25519", "ML-DSA-44", "ML-DSA-65", "ML-DSA-87".

    Symmetric counterpart of JcaMTCSignatureVerifier — encapsulates the MTCCosignedMessage encode plus the underlying JCA Signature ceremony. The draft identifiers are mapped to JCA Signature names internally; the plain (r||s) ECDSA encoding used by MTCProof requires SHA256WITHPLAIN-ECDSA / SHA384WITHPLAIN-ECDSA, which BC's JCE provider registers (DER-encoded SHA256withECDSA is wire-incompatible with the MTCProof signature byte format).

    Instances are created via JcaMTCCosigner.Builder.

    • Method Detail

      • getCosignerId

        public byte[] getCosignerId()
        Specified by:
        getCosignerId in interface MTCCosigner
        Returns:
        the binary trust anchor ID of this cosigner — the value that appears in MTCSignature.getCosignerId() on every signature produced by this instance. Per Section 5.3 of the draft, when the CA itself is acting as a cosigner this is the CA's own trust anchor ID.
      • cosignSubtree

        public MTCSignature cosignSubtree​(MTCLog log,
                                          byte[] subtreeHash)
                                   throws java.io.IOException
        Description copied from interface: MTCCosigner
        Cosigns the subtree [log.getStart(), log.getEnd()) of the issuance log identified by log.getLogId().
        Specified by:
        cosignSubtree in interface MTCCosigner
        Throws:
        java.io.IOException - if the CosignedMessage cannot be encoded or the underlying signing operation fails