Class CMSSignedDataStreamGenerator


  • public class CMSSignedDataStreamGenerator
    extends CMSSignedGenerator
    General class for generating a pkcs7-signature message stream.

    A simple example of usage.

          X509Certificate signCert = ...
          certList.add(signCert);
    
          Store           certs = new JcaCertStore(certList);
          ContentSigner sha1Signer = new JcaContentSignerBuilder("SHA1withRSA").setProvider("BC").build(signKP.getPrivate());
    
          CMSSignedDataStreamGenerator gen = new CMSSignedDataStreamGenerator();
    
          gen.addSignerInfoGenerator(
                    new JcaSignerInfoGeneratorBuilder(
                         new JcaDigestCalculatorProviderBuilder().setProvider("BC").build())
                         .build(sha1Signer, signCert));
    
          gen.addCertificates(certs);
    
          OutputStream sigOut = gen.open(bOut);
    
          sigOut.write("Hello World!".getBytes());
    
          sigOut.close();
     

    Stream handling note:

    • The returned OutputStream must be closed to finalize the CMS structure (write certificates, CRLs, signer infos).
    • Closing the returned stream does not close the underlying OutputStream passed to open().
    • Callers are responsible for closing the underlying OutputStream separately.
    • Constructor Detail

      • CMSSignedDataStreamGenerator

        public CMSSignedDataStreamGenerator()
        base constructor
      • CMSSignedDataStreamGenerator

        public CMSSignedDataStreamGenerator​(DigestAlgorithmIdentifierFinder digestAlgIdFinder)
        base constructor with a custom DigestAlgorithmIdentifierFinder
    • Method Detail

      • setBufferSize

        public void setBufferSize​(int bufferSize)
        Set the underlying string size for encapsulated data
        Parameters:
        bufferSize - length of octet strings to buffer the data.
      • open

        public java.io.OutputStream open​(java.io.OutputStream out)
                                  throws java.io.IOException
        generate a signed object that for a CMS Signed Data object using the given provider.
        Throws:
        java.io.IOException
      • open

        public java.io.OutputStream open​(java.io.OutputStream out,
                                         boolean encapsulate)
                                  throws java.io.IOException
        generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature with the default content type "data".
        Throws:
        java.io.IOException
      • open

        public java.io.OutputStream open​(java.io.OutputStream out,
                                         boolean encapsulate,
                                         java.io.OutputStream dataOutputStream)
                                  throws java.io.IOException
        generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature with the default content type "data". If dataOutputStream is non null the data being signed will be written to the stream as it is processed.
        Parameters:
        out - stream the CMS object is to be written to.
        encapsulate - true if data should be encapsulated.
        dataOutputStream - output stream to copy the data being signed to.
        Throws:
        java.io.IOException
      • open

        public java.io.OutputStream open​(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType,
                                         java.io.OutputStream out,
                                         boolean encapsulate)
                                  throws java.io.IOException
        generate a signed object that for a CMS Signed Data object using the given provider - if encapsulate is true a copy of the message will be included in the signature. The content type is set according to the OID represented by the string signedContentType.
        Throws:
        java.io.IOException
      • open

        public java.io.OutputStream open​(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType,
                                         java.io.OutputStream out,
                                         boolean encapsulate,
                                         java.io.OutputStream dataOutputStream)
                                  throws java.io.IOException
        Open an OutputStream that in closing will generate a signed object for a CMS Signed Data object - if encapsulate is true a copy of the message will be included in the signature. The content type is set according to the OID represented by the string signedContentType.
        Parameters:
        eContentType - OID for data to be signed.
        out - stream the CMS object is to be written to.
        encapsulate - true if data should be encapsulated.
        dataOutputStream - output stream to copy the data being signed to.
        Throws:
        java.io.IOException
      • open

        public java.io.OutputStream open​(org.bouncycastle.asn1.ASN1ObjectIdentifier eContentType,
                                         java.io.OutputStream out,
                                         long contentLength,
                                         java.io.OutputStream dataOutputStream)
                                  throws CMSException,
                                         java.io.IOException
        Generate a definite-length (DL or DER, per CMSSignedGenerator.setEncoding(String)) signed object with encapsulated content of exactly contentLength octets, in a single pass with nothing buffered - so the content may exceed the size of a Java array.

        The SignerInfos trail the content in the encoding but their length feeds the enclosing headers, which are written before any content flows. Every SignerInfoGenerator must therefore be able to pre-commit its encoded SignerInfo length (see SignerInfoGenerator.getPredictedEncodedLength(org.bouncycastle.asn1.ASN1ObjectIdentifier)): the underlying signer has to implement FixedLengthContentSigner - RSA, Ed25519/Ed448 and ML-DSA qualify; DER-encoded ECDSA/DSA do not - and any attribute generators must be length-stable. Exactly contentLength octets must then be written to the returned stream; any mismatch, including a SignerInfo coming out at other than its predicted length, fails with an IOException, by which point the output is unusable and must be discarded.

        Parameters:
        eContentType - the type of the data being written to the object.
        out - stream the CMS object is to be written to.
        contentLength - the exact number of content octets that will be written.
        dataOutputStream - output stream to copy the content to as it is processed (may be null).
        Throws:
        CMSException
        java.io.IOException
      • generate

        public void generate​(CMSTypedData content,
                             java.io.OutputStream out)
                      throws CMSException,
                             java.io.IOException
        Write a definite-length (DL or DER, per CMSSignedGenerator.setEncoding(String)) signed object with encapsulated content in two passes over the supplied content, with nothing buffered - so the content may exceed the size of a Java array, and no length needs to be known in advance.

        Pass one streams the content through the signers' digest calculators and computes every signature, so all lengths are exact - unlike the single-pass open(OutputStream, long) this works with variable-length signature algorithms such as DER-encoded ECDSA. Pass two writes the structure, re-reading the content from content - which must therefore be re-readable (e.g. file-backed) and stable: the second pass is re-digested and compared against the first, so a source that changed between passes fails with an IOException rather than producing a structure whose signatures don't verify.

        Parameters:
        content - the content to sign and encapsulate; write is invoked twice.
        out - stream the CMS object is to be written to.
        Throws:
        CMSException
        java.io.IOException
      • getDigestAlgorithms

        public java.util.List<org.bouncycastle.asn1.x509.AlgorithmIdentifier> getDigestAlgorithms()
        Return a list of the current Digest AlgorithmIdentifiers applying to the next signature.
        Returns:
        a list of the Digest AlgorithmIdentifiers