本文整理汇总了Java中org.bouncycastle.cert.ocsp.RespID类的典型用法代码示例。如果您正苦于以下问题:Java RespID类的具体用法?Java RespID怎么用?Java RespID使用的例子?那么恭喜您, 这里精选的类代码示例或许可以为您提供帮助。
RespID类属于org.bouncycastle.cert.ocsp包,在下文中一共展示了RespID类的2个代码示例,这些例子默认根据受欢迎程度排序。您可以为喜欢或者感觉有用的代码点赞,您的评价将有助于系统推荐出更棒的Java代码示例。
示例1: extractSigningCertificateFormResponderId
import org.bouncycastle.cert.ocsp.RespID; //导入依赖的package包/类
private void extractSigningCertificateFormResponderId(OCSPToken ocspToken) {
BasicOCSPResp basicOCSPResp = ocspToken.getBasicOCSPResp();
if (basicOCSPResp != null) {
final RespID responderId = basicOCSPResp.getResponderId();
final ResponderID responderIdAsASN1Object = responderId.toASN1Primitive();
final DERTaggedObject derTaggedObject = (DERTaggedObject) responderIdAsASN1Object.toASN1Primitive();
if (2 == derTaggedObject.getTagNo()) {
throw new DSSException("Certificate's key hash management not implemented yet!");
}
final ASN1Primitive derObject = derTaggedObject.getObject();
final byte[] derEncoded = DSSASN1Utils.getDEREncoded(derObject);
final X500Principal x500Principal_ = new X500Principal(derEncoded);
final X500Principal x500Principal = DSSUtils.getNormalizedX500Principal(x500Principal_);
final List<CertificateToken> certificateTokens = validationCertPool.get(x500Principal);
for (final CertificateToken issuerCertificateToken : certificateTokens) {
if (ocspToken.isSignedBy(issuerCertificateToken)) {
break;
}
}
}
}
示例2: findOcspCertificate
import org.bouncycastle.cert.ocsp.RespID; //导入依赖的package包/类
private X509Cert findOcspCertificate() {
String rId = "";
try {
RespID responderId = ocspResponse.getResponderId();
rId = responderId.toString();
String primitiveName = getCN(responderId.toASN1Primitive().getName());
byte[] keyHash = responderId.toASN1Primitive().getKeyHash();
boolean isKeyHash = useKeyHashForOCSP(primitiveName, keyHash);
if (isKeyHash) {
logger.debug("Using keyHash {} for OCSP certificate match", keyHash);
} else {
logger.debug("Using ASN1Primitive {} for OCSP certificate match", primitiveName);
}
for (CertificateToken cert : getDssSignature().getCertificates()) {
if (isKeyHash) {
ASN1Primitive skiPrimitive = JcaX509ExtensionUtils.parseExtensionValue(
cert.getCertificate().getExtensionValue(Extension.subjectKeyIdentifier.getId()));
byte[] keyIdentifier = ASN1OctetString.getInstance(skiPrimitive.getEncoded()).getOctets();
if (Arrays.equals(keyHash, keyIdentifier)) {
return new X509Cert(cert.getCertificate());
}
} else {
String certCn = getCN(new X500Name(cert.getSubjectX500Principal().getName()));
if (StringUtils.equals(certCn, primitiveName)) {
return new X509Cert(cert.getCertificate());
}
}
}
} catch (IOException e) {
logger.error("Unable to wrap and extract SubjectKeyIdentifier from certificate - technical error. {}", e);
}
logger.error("OCSP certificate for " + rId + " was not found in TSL");
throw new CertificateNotFoundException("OCSP certificate for " + rId + " was not found in TSL");
}