All Classes and Interfaces

Class
Description
A buffer that was allocated by a BufferAllocator.
Server-side selector for the ALPN protocol.
Compatibility utility for Arrays.
An object responsible for allocation of buffers.
Byte array wrapper for hashtable use.
A set of certificates that are blacklisted from trust.
CertificateEntry structure.
 
Comparator for prioritizing certificates in path building.
Certificate Transparency subsystem.
Certificate Transparency Verification Reason.
Interface for classes that implement certificate pinning for use in TrustManagerImpl.
Analyzes the cryptographic strength of a chain of X.509 certificates.
Cipher suites to metric mapping for metrics instrumentation.
Caches client sessions.
Core API for creating and configuring all Conscrypt types.
 
 
A certificate store that supports additional operations that are used in TrustManagerImpl.
This interface is used to implement hostname verification in Conscrypt.
Reimplement with reflection calls the logging class, generated by frameworks/statsd.
 
Support class for this package.
 
 
An implementation of SecretKeyFactory for use with DESEDE keys.
DigitallySigned structure, as defined by RFC5246 Section 4.7.
 
 
Duck typed implementation of HpkeSpi.
AlgorithmParameters implementation for elliptic curves.
Indicates a public API that can change at any time, and has no guarantee of API stability and backward-compatibility.
ByteArrayOutputStream that exposes the underlying byte array.
File-based cache implementation.
GCM parameters used during an ciphering operation with OpenSSLCipher.
Similar in concept to HandshakeCompletedListener, but used for listening directly to the engine.
Hkdf - perform HKDF key derivation operations per RFC 5869.
Hybrid Public Key Encryption (HPKE) sender APIs.
Hybrid Public Key Encryption (HPKE) recipient APIs.
Hybrid Public Key Encryption (HPKE) sender APIs.
 
Implementation of HpkeSpi.
Implementation of MLKEM_1024/HKDF_SHA256/AES_128_GCM.
Implementation of MLKEM_1024/HKDF_SHA256/AES_256_GCM.
Implementation of MLKEM_1024/HKDF_SHA256/CHACHA20_POLY1305.
Implementation of MLKEM_768/HKDF_SHA256/AES_128_GCM.
Implementation of MLKEM_768/HKDF_SHA256/AES_256_GCM.
Implementation of MLKEM_768/HKDF_SHA256/CHACHA20_POLY1305.
Implementation of X25519/HKDF_SHA256/AES_128_GCM.
Implementation of X25519/HKDF_SHA256/AES_256_GCM.
Implementation of X25519/HKDF_SHA256/CHACHA20_POLY1305.
Implementation of XWING/HKDF_SHA256/AES_128_GCM.
Implementation of XWING/HKDF_SHA256/AES_256_GCM.
Implementation of XWING/HKDF_SHA256/CHACHA20_POLY1305.
SPI for HPKE clients to communicate with implementations.
Holds the KEM, KDF, and AEAD that are used and supported by HpkeContextRecipient and HpkeContextSender defined on RFC 9180.
AEAD ciphers.
Key Derivation Functions (KDFs)
Key Encapsulation Mechanisms (KEMs)
Annotates a program element (class, method, package etc) which is internal to Conscrypt, not part of the public API, and should not be used by users of Conscrypt.
 
An implementation of AlgorithmParameters that contains only an IV.
 
 
 
An implementation of KeyGenerator suitable for use with other Conscrypt algorithms.
 
 
 
 
 
 
 
 
 
 
KeyManagerFactory implementation.
A utility class for working with KeySpecs.
Properties about a Certificate Transparency Log.
 
 
 
ML-DSA algorithm.
ML-KEM algorithm.
Provides the Java side of our JNI glue for OpenSSL.
Noop class for stats logging
AlgorithmParameters implementation for OAEP.
A HostnameVerifier consistent with RFC 2818.
 
 
 
 
 
 
 
 
 
Generic base classe for Diffie-Hellman style key agreement backed by the OpenSSL engine.
An implementation of Cipher using BoringSSL as the backing library.
Implementation of the ChaCha20 stream cipher.
 
 
 
 
 
 
 
 
 
 
OpenSSL-backed SSLContext service provider interface.
Public to allow construction via the provider framework.
Public to allow construction via the provider framework.
Public to allow construction via the provider framework.
Public to allow construction via the provider framework.
Elliptic Curve Diffie-Hellman key agreement backed by the OpenSSL engine.
An implementation of a KeyFactorySpi for EC keys based on BoringSSL.
An implementation of KeyPairGenerator for EC keys which uses BoringSSL to perform all the operations.
An implementation of a KeyFactorySpi for EdDSA keys based on BoringSSL.
An implementation of KeyPairGenerator for XDH keys which uses BoringSSL to perform all the operations.
An OpenSSL EdDSA private key.
An OpenSSL EdDSA public key.
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Represents a BoringSSL EVP_PKEY.
Marker interface for classes that hold an OpenSSLKey.
An implementation of Mac which uses BoringSSL to perform all the operations.
 
 
 
 
 
 
 
 
Implements the JDK MessageDigest interface using OpenSSL's EVP API.
 
 
 
 
 
 
An implementation of a KeyFactorySpi for MLDSA keys based on BoringSSL.
ML-DSA
ML-DSA-44
ML-DSA-65
ML-DSA-87
An implementation of KeyPairGenerator for ML-DSA keys which uses BoringSSL to perform all the operations.
ML-DSA uses ML-DSA-65.
ML-DSA-44
ML-DSA-65
ML-DSA-87
An OpenSSL ML-DSA private key.
An OpenSSL ML-DSA public key.
An implementation of a KeyFactorySpi for ML-KEM keys based on BoringSSL.
ML-KEM
ML-KEM-1024
ML-KEM-768
An implementation of KeyPairGenerator for ML-KEM keys which uses BoringSSL to perform all the operations.
ML-KEM uses ML-KEM-768.
ML-KEM-1024
ML-KEM-768
An ML-KEM private key.
An ML-KEM public key.
Provider that uses BoringSSL to perform the actual cryptographic operations.
Implements SecureRandom using BoringSSL's RAND interface.
An implementation of KeyFactory which uses BoringSSL to perform all the operations.
An implementation of KeyPairGenerator which uses BoringSSL to perform all the operations.
An implementation of PublicKey for RSA keys which uses BoringSSL to perform all the operations.
Implements the subset of the JDK Signature interface needed for signature verification using OpenSSL.
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Implements the JDK Signature interface needed for EdDSA signature generation and verification using BoringSSL.
Implements the JDK Signature interface needed for ML-DSA signature generation and verification using BoringSSL.
ML-DSA
ML-DSA-44
ML-DSA-65
ML-DSA-87
Implements the JDK Signature interface needed for RAW ECDSA signature generation and verification using BoringSSL.
Implements the JDK Signature interface needed for RAW RSA signature generation and verification using BoringSSL.
Implements the JDK Signature interface needed for SLH-DSA-SHA2-128S signature generation and verification using BoringSSL.
An implementation of a KeyFactorySpi for SLH-DSL keys based on BoringSSL.
An implementation of KeyPairGenerator for SLH-DSA keys which uses BoringSSL to perform all the operations.
A SLH-DSA private key.
An SLH-DSA public key.
Public shim allowing us to stay backward-compatible with legacy applications which were using Conscrypt's extended socket API before the introduction of the Conscrypt class.
 
 
 
An implementation of X509Certificate based on BoringSSL.
An implementation of CertificateFactory based on BoringSSL.
Elliptic Curve Diffie-Hellman key agreement backed by the OpenSSL engine.
An implementation of a KeyFactorySpi for XEC keys based on BoringSSL.
An implementation of KeyPairGenerator for XDH keys which uses BoringSSL to perform all the operations.
An implementation of a KeyFactorySpi for XWING keys based on BoringSSL.
An implementation of KeyPairGenerator for XWING keys which uses BoringSSL to perform all the operations.
An X-Wing private key.
An X-Wing public key.
Helper class to handle reflexive loading and invocation of methods which may be absent.
Platform-specific methods for OpenJDK.
 
 
Protocols to metric mapping for metrics instrumentation.
Deprecated.
This abstraction is deprecated because it does not work with TLS 1.3.
AlgorithmParameters implementation for PSS.
Reflection wrapper around android.util.StatsEvent.
 
Reflection wrapper around android.util.StatsLog.
Mirrors the class of the same name from BouncyCastle.
 
 
 
Caches server sessions.
SignedCertificateTimestamp structure, as defined by RFC6962 Section 3.2.
 
 
 
Data Sources to metric mapping for metrics instrumentation.
Provider of key material for Spake2Plus
Noop TrustManager for Spake2Plus
A persistent SSLSession cache used by SSLSessionContext to share client-side SSL sessions across processes.
A persistent SSLSession cache used by SSLSessionContext to share server-side SSL sessions across processes.
 
Implements logging for Conscrypt metrics.
Indexes TrustAnchor instances so they can be found in O(1) time instead of O(N).
TrustManagerFactory service provider interface implementation.
TrustManager implementation.
Container for verified SignedCertificateTimestamp.
Verification result for a single SCT.
 
 
 
External Diffie–Hellman key spec holding a key which could be either a public or private key.