【问题标题】:Adding Certificates to CMS Signed Data将证书添加到 CMS 签名数据
【发布时间】:2016-11-30 08:45:11
【问题描述】:

我目前正在使用 java Bouncy Castle 库来创建 CMS 签名数据(或 PKCS7 签名数据)。然而,我似乎无法添加证书(即使证书签名者已正确添加)。

我查看了 this question 关于正确签署数据的信息,但它没有响应我的 SCEP 服务器的需求。我使用的代码来自 EJBCA,但似乎没有将证书添加到 PKCS7 签名数据中。

当我使用openssl cms 工具解析签名数据时,我看到“证书”字段为“空”。此外,当我尝试使用openssl pkcs7 [...] -print_certs 打印证书时,我什么也得不到。

这是我使用 Bouncy Castle 签署数据的方式(代码很多,但足以重现问题):

CMSEnvelopedDataGenerator edGen = new CMSEnvelopedDataGenerator();
CMSTypedData msg;
List<X509Certificate> certList = new ArrayList<>();
// Make sure the certificate is not null
if (this.certificate != null) {
    certList.add((X509Certificate) this.certificate);
}

/**
* Create the signed CMS message to be contained inside the envelope
* this message does not contain any message, and no signerInfo
**/
CMSSignedDataGenerator gen = new CMSSignedDataGenerator();
Collection<JcaX509CertificateHolder> x509CertificateHolder = new ArrayList<>();
try {
    for (X509Certificate certificate : certList) {
        x509CertificateHolder.add(new JcaX509CertificateHolder(certificate));
    }
    CollectionStore<JcaX509CertificateHolder> store = new CollectionStore<>(x509CertificateHolder);
    gen.addCertificates(store);
} catch (Handle all exceptions) {}

上面这段代码的 sn-p 通常应该添加证书。这是我从 EJBCA 拿来的。

这是我完成签名数据的方式:

CMSSignedDataGenerator gen1 = new CMSSignedDataGenerator();
// I add ALL of my attributes here
// Once they're added...
Certificate caCert = this.caCertificate;
try {
    String provider = BouncyCastleProvider.PROVIDER_NAME;
    ContentSigner contentSigner = new JcaContentSignerBuilder(signatureAlgorithmName).
            setProvider(provider).
            build(signerKey);
    JcaDigestCalculatorProviderBuilder calculatorProviderBuilder = new JcaDigestCalculatorProviderBuilder().
            setProvider(provider);
    JcaSignerInfoGeneratorBuilder builder = new JcaSignerInfoGeneratorBuilder(calculatorProviderBuilder.build());
    builder.setSignedAttributeGenerator(new DefaultSignedAttributeTableGenerator(new AttributeTable(attributes)));
    gen1.addSignerInfoGenerator(builder.build(contentSigner, (X509Certificate) ca));
} catch (Handle all exceptions) {}

// Create the signed data
CMSSignedData sd = gen1.generate(msg, true);
byte[] results = sd.getEncoded();

字节数组结果是 DER 格式的 PKCS7 签名数据...但没有添加证书。

我错过了什么吗?感谢您的帮助!

【问题讨论】:

    标签: java openssl bouncycastle pkcs#7


    【解决方案1】:

    CMSSignedDataGenerator gen1 必须明确添加我不知道的证书。

    可以通过以下方式完成:

    • 将证书添加到List 或X509Certificates;
    • 将List 转换为Collection 的JcaX509CertificateHolder;
    • 将此集合添加到CollectionStore 或JcaX509CertificateHolder;
    • 添加商店CMSSignedDataGenerator。

    代码示例:

     CMSSignedDataGenerator gen1 = new CMSSignedDataGenerator();
     List<X509Certificate> certificates = new ArrayList<>();
    
     // I chose to add the CA certificate
     certificates.add((X509Certificate) this.caCertificate);
    
     // In this case, this is a certificate that I need to add
     if (this.certificate != null)
         certificates.add((X509Certificate) this.certificate);
    
     // This is the recipient certificate
     if (this.recipientCert != null)
         certificates.add((X509Certificate) this.recipientCert);
     Collection<JcaX509CertificateHolder> x509CertificateHolder = new ArrayList<>();
    
     // Of course, we need to handle the exceptions...
     for (X509Certificate certificate : certificates) {
         x509CertificateHolder.add(new JcaX509CertificateHolder(certificate));
     }
     CollectionStore<JcaX509CertificateHolder> store = new CollectionStore<>(x509CertificateHolder);
    
    // The final stage.
     gen1.addCertificates(store);
    

    希望这对将来的任何人都有帮助。

    【讨论】:

    • 您好,我尝试了上述解决方案,但遗憾的是最终数字签名中没有证书。您是否验证过您的数字签名中是否存在证书?
    • 您好,抱歉回复晚了。不幸的是,我无法再访问源代码,但我仍然可以尝试帮助您。我确实记得在生成数字签名 (CSMSignedDataGenerator) 后获得了证书 (this.certificate)。我没有添加 CA,所以它不存在。您确定将您的证书添加到certificates 列表中吗?
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2020-12-22
    • 2019-08-23
    • 2013-04-18
    相关资源
    最近更新 更多