2018-06-02 21:21:35 +02:00
|
|
|
package de.vanitasvitae.crypto.pgpainless.key.generation;
|
|
|
|
|
|
|
|
|
|
|
|
import java.nio.charset.Charset;
|
2018-06-04 14:50:09 +02:00
|
|
|
import java.security.InvalidAlgorithmParameterException;
|
2018-06-02 21:21:35 +02:00
|
|
|
import java.security.KeyPair;
|
|
|
|
import java.security.KeyPairGenerator;
|
|
|
|
import java.security.NoSuchAlgorithmException;
|
|
|
|
import java.security.NoSuchProviderException;
|
|
|
|
import java.util.ArrayList;
|
|
|
|
import java.util.Date;
|
|
|
|
import java.util.List;
|
|
|
|
|
2018-06-04 14:50:09 +02:00
|
|
|
import de.vanitasvitae.crypto.pgpainless.algorithm.KeyFlag;
|
|
|
|
import de.vanitasvitae.crypto.pgpainless.key.generation.type.ECDH;
|
|
|
|
import de.vanitasvitae.crypto.pgpainless.key.generation.type.ECDSA;
|
2018-06-02 21:21:35 +02:00
|
|
|
import de.vanitasvitae.crypto.pgpainless.key.generation.type.KeyType;
|
2018-06-04 14:50:09 +02:00
|
|
|
import de.vanitasvitae.crypto.pgpainless.key.generation.type.RSA_GENERAL;
|
|
|
|
import de.vanitasvitae.crypto.pgpainless.key.generation.type.curve.EllipticCurve;
|
|
|
|
import de.vanitasvitae.crypto.pgpainless.key.generation.type.length.RsaLength;
|
2018-06-02 21:21:35 +02:00
|
|
|
import org.bouncycastle.bcpg.HashAlgorithmTags;
|
2018-06-04 14:50:09 +02:00
|
|
|
import org.bouncycastle.bcpg.sig.KeyFlags;
|
2018-06-02 21:21:35 +02:00
|
|
|
import org.bouncycastle.jce.provider.BouncyCastleProvider;
|
|
|
|
import org.bouncycastle.openpgp.PGPEncryptedData;
|
|
|
|
import org.bouncycastle.openpgp.PGPException;
|
|
|
|
import org.bouncycastle.openpgp.PGPKeyPair;
|
|
|
|
import org.bouncycastle.openpgp.PGPKeyRingGenerator;
|
|
|
|
import org.bouncycastle.openpgp.PGPSecretKeyRing;
|
|
|
|
import org.bouncycastle.openpgp.PGPSignature;
|
2018-06-04 14:50:09 +02:00
|
|
|
import org.bouncycastle.openpgp.PGPSignatureSubpacketVector;
|
2018-06-02 21:21:35 +02:00
|
|
|
import org.bouncycastle.openpgp.operator.PBESecretKeyEncryptor;
|
|
|
|
import org.bouncycastle.openpgp.operator.PGPContentSignerBuilder;
|
|
|
|
import org.bouncycastle.openpgp.operator.PGPDigestCalculator;
|
2018-06-07 18:12:13 +02:00
|
|
|
import org.bouncycastle.openpgp.operator.bc.BcPGPKeyPair;
|
2018-06-02 21:21:35 +02:00
|
|
|
import org.bouncycastle.openpgp.operator.jcajce.JcaPGPContentSignerBuilder;
|
|
|
|
import org.bouncycastle.openpgp.operator.jcajce.JcaPGPDigestCalculatorProviderBuilder;
|
|
|
|
import org.bouncycastle.openpgp.operator.jcajce.JcaPGPKeyPair;
|
|
|
|
import org.bouncycastle.openpgp.operator.jcajce.JcePBESecretKeyEncryptorBuilder;
|
|
|
|
|
|
|
|
public class KeyRingBuilder implements KeyRingBuilderInterface {
|
|
|
|
|
|
|
|
private final Charset UTF8 = Charset.forName("UTF-8");
|
|
|
|
|
|
|
|
private List<KeySpec> keySpecs = new ArrayList<>();
|
2018-06-04 14:50:09 +02:00
|
|
|
private String userId;
|
2018-06-02 21:21:35 +02:00
|
|
|
private char[] passphrase;
|
|
|
|
|
2018-06-04 19:44:47 +02:00
|
|
|
/**
|
|
|
|
* Creates a simple RSA KeyPair of length {@code length} with user-id {@code userId}.
|
|
|
|
*
|
|
|
|
* @param userId user id.
|
|
|
|
* @param length length in bits.
|
|
|
|
* @return {@link PGPSecretKeyRing} containing the KeyPair.
|
|
|
|
* @throws PGPException
|
|
|
|
* @throws NoSuchAlgorithmException
|
|
|
|
* @throws NoSuchProviderException
|
|
|
|
* @throws InvalidAlgorithmParameterException
|
|
|
|
*/
|
2018-06-04 14:50:09 +02:00
|
|
|
public PGPSecretKeyRing simpleRsaKeyRing(String userId, RsaLength length)
|
|
|
|
throws PGPException, NoSuchAlgorithmException, NoSuchProviderException, InvalidAlgorithmParameterException {
|
|
|
|
return withMasterKey(
|
2018-06-04 19:44:47 +02:00
|
|
|
KeySpec.getBuilder(RSA_GENERAL.withLength(length))
|
2018-06-04 14:50:09 +02:00
|
|
|
.withDefaultKeyFlags()
|
|
|
|
.withDefaultAlgorithms())
|
|
|
|
.withPrimaryUserId(userId)
|
|
|
|
.withoutPassphrase()
|
|
|
|
.build();
|
2018-06-02 21:21:35 +02:00
|
|
|
}
|
|
|
|
|
2018-06-04 14:50:09 +02:00
|
|
|
public PGPSecretKeyRing simpleEcKeyRing(String userId)
|
|
|
|
throws PGPException, NoSuchAlgorithmException, NoSuchProviderException, InvalidAlgorithmParameterException {
|
|
|
|
return withSubKey(
|
2018-06-04 19:44:47 +02:00
|
|
|
KeySpec.getBuilder(ECDH.fromCurve(EllipticCurve._P256))
|
2018-06-04 14:50:09 +02:00
|
|
|
.withKeyFlags(KeyFlag.ENCRYPT_STORAGE, KeyFlag.ENCRYPT_COMMS)
|
|
|
|
.withDefaultAlgorithms())
|
|
|
|
.withMasterKey(
|
2018-06-04 19:44:47 +02:00
|
|
|
KeySpec.getBuilder(ECDSA.fromCurve(EllipticCurve._P256))
|
2018-06-04 14:50:09 +02:00
|
|
|
.withKeyFlags(KeyFlag.AUTHENTICATION, KeyFlag.CERTIFY_OTHER, KeyFlag.SIGN_DATA)
|
|
|
|
.withDefaultAlgorithms())
|
|
|
|
.withPrimaryUserId(userId)
|
|
|
|
.withoutPassphrase()
|
|
|
|
.build();
|
2018-06-02 21:21:35 +02:00
|
|
|
}
|
|
|
|
|
2018-06-04 14:50:09 +02:00
|
|
|
@Override
|
|
|
|
public KeyRingBuilderInterface withSubKey(KeySpec type) {
|
|
|
|
KeyRingBuilder.this.keySpecs.add(type);
|
|
|
|
return this;
|
2018-06-02 21:21:35 +02:00
|
|
|
}
|
|
|
|
|
2018-06-04 14:50:09 +02:00
|
|
|
@Override
|
|
|
|
public WithPrimaryUserId withMasterKey(KeySpec spec) {
|
|
|
|
if ((spec.getSubpackets().getKeyFlags() & KeyFlags.CERTIFY_OTHER) == 0) {
|
|
|
|
throw new IllegalArgumentException("Certification Key MUST have KeyFlag CERTIFY_OTHER");
|
2018-06-02 21:21:35 +02:00
|
|
|
}
|
2018-06-04 14:50:09 +02:00
|
|
|
KeyRingBuilder.this.keySpecs.add(0, spec);
|
|
|
|
return new WithPrimaryUserIdImpl();
|
2018-06-02 21:21:35 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
class WithPrimaryUserIdImpl implements WithPrimaryUserId {
|
|
|
|
|
|
|
|
@Override
|
2018-06-04 14:50:09 +02:00
|
|
|
public WithPassphrase withPrimaryUserId(String userId) {
|
|
|
|
KeyRingBuilder.this.userId = userId;
|
|
|
|
return new WithPassphraseImpl();
|
2018-06-02 21:21:35 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
@Override
|
2018-06-04 14:50:09 +02:00
|
|
|
public WithPassphrase withPrimaryUserId(byte[] userId) {
|
2018-06-02 21:21:35 +02:00
|
|
|
return withPrimaryUserId(new String(userId, UTF8));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
class WithPassphraseImpl implements WithPassphrase {
|
|
|
|
|
|
|
|
@Override
|
|
|
|
public Build withPassphrase(String passphrase) {
|
|
|
|
return withPassphrase(passphrase.toCharArray());
|
|
|
|
}
|
|
|
|
|
|
|
|
@Override
|
|
|
|
public Build withPassphrase(char[] passphrase) {
|
|
|
|
KeyRingBuilder.this.passphrase = passphrase;
|
|
|
|
return new BuildImpl();
|
|
|
|
}
|
|
|
|
|
|
|
|
@Override
|
|
|
|
public Build withoutPassphrase() {
|
|
|
|
KeyRingBuilder.this.passphrase = null;
|
|
|
|
return new BuildImpl();
|
|
|
|
}
|
|
|
|
|
|
|
|
class BuildImpl implements Build {
|
|
|
|
|
|
|
|
@Override
|
2018-06-04 14:50:09 +02:00
|
|
|
public PGPSecretKeyRing build() throws NoSuchAlgorithmException, PGPException, NoSuchProviderException,
|
|
|
|
InvalidAlgorithmParameterException {
|
2018-06-02 21:21:35 +02:00
|
|
|
|
|
|
|
// Hash Calculator
|
|
|
|
PGPDigestCalculator calculator = new JcaPGPDigestCalculatorProviderBuilder()
|
|
|
|
.setProvider(BouncyCastleProvider.PROVIDER_NAME)
|
|
|
|
.build()
|
|
|
|
.get(HashAlgorithmTags.SHA1);
|
|
|
|
|
|
|
|
// Encryptor for encrypting secret keys
|
|
|
|
PBESecretKeyEncryptor encryptor = passphrase == null ?
|
|
|
|
null : // unencrypted key pair, otherwise AES-256 encrypted
|
|
|
|
new JcePBESecretKeyEncryptorBuilder(PGPEncryptedData.AES_256, calculator)
|
|
|
|
.setProvider(BouncyCastleProvider.PROVIDER_NAME)
|
|
|
|
.build(passphrase);
|
|
|
|
|
|
|
|
// First key is the Master Key
|
|
|
|
KeySpec certKeySpec = keySpecs.get(0);
|
2018-06-04 14:50:09 +02:00
|
|
|
// Remove master key, so that we later only add sub keys.
|
|
|
|
keySpecs.remove(0);
|
2018-06-02 21:21:35 +02:00
|
|
|
|
|
|
|
// Generate Master Key
|
|
|
|
PGPKeyPair certKey = generateKeyPair(certKeySpec);
|
|
|
|
|
|
|
|
// Signer for creating self-signature
|
|
|
|
PGPContentSignerBuilder signer = new JcaPGPContentSignerBuilder(
|
2018-06-04 14:50:09 +02:00
|
|
|
certKey.getPublicKey().getAlgorithm(), HashAlgorithmTags.SHA512)
|
|
|
|
.setProvider(BouncyCastleProvider.PROVIDER_NAME);
|
2018-06-02 21:21:35 +02:00
|
|
|
|
2018-06-04 14:50:09 +02:00
|
|
|
PGPSignatureSubpacketVector hashedSubPackets = certKeySpec.getSubpackets();
|
2018-06-02 21:21:35 +02:00
|
|
|
|
|
|
|
// Generator which the user can get the key pair from
|
|
|
|
PGPKeyRingGenerator ringGenerator = new PGPKeyRingGenerator(
|
|
|
|
PGPSignature.POSITIVE_CERTIFICATION, certKey,
|
2018-06-04 14:50:09 +02:00
|
|
|
userId, calculator,
|
|
|
|
hashedSubPackets, null, signer, encryptor);
|
2018-06-02 21:21:35 +02:00
|
|
|
|
|
|
|
for (KeySpec subKeySpec : keySpecs) {
|
|
|
|
PGPKeyPair subKey = generateKeyPair(subKeySpec);
|
2018-06-04 14:50:09 +02:00
|
|
|
if (subKeySpec.isInheritedSubPackets()) {
|
|
|
|
ringGenerator.addSubKey(subKey);
|
|
|
|
} else {
|
|
|
|
ringGenerator.addSubKey(subKey, subKeySpec.getSubpackets(), null);
|
|
|
|
}
|
2018-06-02 21:21:35 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
return ringGenerator.generateSecretKeyRing();
|
|
|
|
}
|
|
|
|
|
|
|
|
private PGPKeyPair generateKeyPair(KeySpec spec)
|
2018-06-04 14:50:09 +02:00
|
|
|
throws NoSuchProviderException, NoSuchAlgorithmException, PGPException,
|
|
|
|
InvalidAlgorithmParameterException {
|
2018-06-02 21:21:35 +02:00
|
|
|
KeyType type = spec.getKeyType();
|
|
|
|
KeyPairGenerator certKeyGenerator = KeyPairGenerator.getInstance(
|
|
|
|
type.getName(), BouncyCastleProvider.PROVIDER_NAME);
|
2018-06-04 14:50:09 +02:00
|
|
|
certKeyGenerator.initialize(type.getAlgorithmSpec());
|
2018-06-02 21:21:35 +02:00
|
|
|
|
|
|
|
// Create raw Key Pair
|
2018-06-04 14:50:09 +02:00
|
|
|
KeyPair keyPair = certKeyGenerator.generateKeyPair();
|
2018-06-02 21:21:35 +02:00
|
|
|
|
|
|
|
// Form PGP key pair
|
|
|
|
PGPKeyPair pgpKeyPair = new JcaPGPKeyPair(type.getAlgorithm().getAlgorithmId(),
|
2018-06-04 14:50:09 +02:00
|
|
|
keyPair, new Date());
|
2018-06-02 21:21:35 +02:00
|
|
|
|
|
|
|
return pgpKeyPair;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|