【发布时间】:2013-08-25 00:19:44
【问题描述】:
我们正在使用小程序进行加密解密。我们发现数字证书存在一些意想不到的问题。一个系统有证书,我们无法从该证书中找到私钥,但通过再次安装相同的证书可以正常工作。
Java Plug-in 10.25.2.17
Using JRE version 1.7.0_25-b17 Java HotSpot(TM) 64-Bit Server VM
User home directory = C:\Users\admin
要访问私钥,我们使用以下代码。
private PrivateKey getPrivateKeyFromKeyStore(String pubkey, KeyStore browser) {
PrivateKey privateKey = null;
String pubKey1 = "";
if (browser != null) {
try {
Field spiField = KeyStore.class.getDeclaredField("keyStoreSpi");
spiField.setAccessible(true);
KeyStoreSpi spi = (KeyStoreSpi) spiField.get(browser);
Field entriesField = spi.getClass().getSuperclass().getDeclaredField("entries");
entriesField.setAccessible(true);
@SuppressWarnings("rawtypes")
Collection entries = (Collection) entriesField.get(spi);
for (Object entry : entries) {
String alias = (String) invokeGetter(entry, "getAlias");
X509Certificate[] certificateChain = (X509Certificate[]) invokeGetter(entry, "getCertificateChain");
for (X509Certificate current : certificateChain) {
pubKey1 = this.bASE64Encoder.encode(current.getPublicKey().getEncoded());
if (pubkey.equals(pubKey1) && !pubkey.equals("")) {
privateKey = (PrivateKey) invokeGetter(entry, "getPrivateKey");
return privateKey;
}
}
}
} catch (Exception e) {
e.printStackTrace();
return null;
}
}
return privateKey;
}
【问题讨论】:
-
您不需要所有这些反射来调用 KeyStore API。尝试使用已发布的内容。
-
无法理解。请您详细解释一下。就像我必须更改哪一行代码...
-
改变它们all. 把它扔掉,看看Javadoc。 KeyStore 中已经有公共方法可以枚举内容并查找每个元素的类型。
-
元素类型是什么意思?您是在谈论证书的层次结构吗?如果
digitalSignature (1)比对其他密钥标识更明智地签署证书,我可以得到类似的结果。但是当相同的证书私钥变为空时,我没有特定的情况。现在在浏览器中,我有三个证书,其私钥为空。我删除了其中一个,然后再次添加它,然后我得到了预期的私钥。现在我想检查剩余的 2 个证书。private key null的实际问题是什么?how private key become null for same certificate?我想要根本原因。 -
“元素类型”是指证书或密钥。我建议你冷静下来阅读我已经建议的公共 API。有一些方法可以检索证书、密钥和迭代器。你目前的课程不会有任何收获。
标签: java security applet digital-certificate