Class JcePasswordRecipient

    • Method Detail

      • setPasswordConversionScheme

        public JcePasswordRecipient setPasswordConversionScheme​(int schemeID)
      • setAllowedContentAlgorithms

        public JcePasswordRecipient setAllowedContentAlgorithms​(java.util.Set<org.bouncycastle.asn1.ASN1ObjectIdentifier> allowedContentAlgorithms)
        Set the content-encryption algorithms this recipient is willing to unwrap a key for. When set, an attempt to recover content protected under any other algorithm is rejected, mitigating an attacker substituting a weaker content-encryption algorithm into the recipient info.
        Parameters:
        allowedContentAlgorithms - the set of permitted content-encryption algorithm OIDs.
        Returns:
        this recipient.
      • setMinimumTagSize

        public JcePasswordRecipient setMinimumTagSize​(int tagSizeInBits)
        Set the minimum AEAD authentication tag size (in bits) this recipient will accept. When set, an attempt to recover AuthEnvelopedData whose content algorithm carries a shorter tag is rejected, mitigating an attacker downgrading the tag to a weaker length.
        Parameters:
        tagSizeInBits - the minimum acceptable AEAD tag size, in bits.
        Returns:
        this recipient.
      • extractSecretKey

        protected java.security.Key extractSecretKey​(org.bouncycastle.asn1.x509.AlgorithmIdentifier keyEncryptionAlgorithm,
                                                     org.bouncycastle.asn1.x509.AlgorithmIdentifier contentEncryptionAlgorithm,
                                                     byte[] derivedKey,
                                                     byte[] encryptedContentEncryptionKey)
                                              throws CMSException
        Throws:
        CMSException