Class BcKeyTransRecipient

    • Constructor Detail

      • BcKeyTransRecipient

        public BcKeyTransRecipient​(org.bouncycastle.crypto.params.AsymmetricKeyParameter recipientKey)
    • Method Detail

      • setAllowedContentAlgorithms

        public BcKeyTransRecipient setAllowedContentAlgorithms​(java.util.Set<org.bouncycastle.asn1.ASN1ObjectIdentifier> allowedContentAlgorithms)
        Set the content-encryption algorithms this recipient is willing to unwrap a key for. When set, an attempt to recover content protected under any other algorithm is rejected, mitigating an attacker substituting a weaker content-encryption algorithm into the recipient info.
        Parameters:
        allowedContentAlgorithms - the set of permitted content-encryption algorithm OIDs.
        Returns:
        this recipient.
      • extractSecretKey

        protected org.bouncycastle.crypto.CipherParameters extractSecretKey​(org.bouncycastle.asn1.x509.AlgorithmIdentifier keyEncryptionAlgorithm,
                                                                            org.bouncycastle.asn1.x509.AlgorithmIdentifier encryptedKeyAlgorithm,
                                                                            byte[] encryptedEncryptionKey)
                                                                     throws CMSException
        Throws:
        CMSException