|
20 | 20 | import org.bouncycastle.bcpg.SecretKeyPacket;
|
21 | 21 | import org.bouncycastle.bcpg.SymmetricKeyAlgorithmTags;
|
22 | 22 | import org.bouncycastle.crypto.AsymmetricCipherKeyPair;
|
| 23 | +import org.bouncycastle.crypto.CryptoServicesRegistrar; |
23 | 24 | import org.bouncycastle.crypto.generators.Ed25519KeyPairGenerator;
|
24 | 25 | import org.bouncycastle.crypto.params.Ed25519KeyGenerationParameters;
|
25 | 26 | import org.bouncycastle.jce.provider.BouncyCastleProvider;
|
|
45 | 46 | import org.bouncycastle.openpgp.operator.jcajce.JcePBEProtectionRemoverFactory;
|
46 | 47 | import org.bouncycastle.openpgp.operator.jcajce.JcePBESecretKeyDecryptorBuilder;
|
47 | 48 | import org.bouncycastle.util.Strings;
|
| 49 | +import org.bouncycastle.openpgp.operator.jcajce.JcePBESecretKeyEncryptorBuilder; |
48 | 50 | import org.bouncycastle.util.encoders.Hex;
|
49 | 51 |
|
50 | 52 | public class AEADProtectedPGPSecretKeyTest
|
@@ -365,14 +367,57 @@ private void lockUnlockKeyJca(
|
365 | 367 | keyPair.getPrivateKey().getPrivateKeyDataPacket().getEncoded(), dec.getPrivateKeyDataPacket().getEncoded());
|
366 | 368 | }
|
367 | 369 |
|
368 |
| - private void reencryptKey() throws PGPException { |
| 370 | + private void reencryptKey() |
| 371 | + throws PGPException, InvalidAlgorithmParameterException, NoSuchAlgorithmException |
| 372 | + { |
369 | 373 | reencryptKeyBc();
|
370 | 374 | reencryptKeyJca();
|
371 | 375 | }
|
372 | 376 |
|
373 | 377 | private void reencryptKeyJca()
|
| 378 | + throws NoSuchAlgorithmException, InvalidAlgorithmParameterException, PGPException |
374 | 379 | {
|
| 380 | + BouncyCastleProvider prov = new BouncyCastleProvider(); |
| 381 | + KeyPairGenerator eddsaGen = KeyPairGenerator.getInstance("EdDSA", prov); |
375 | 382 |
|
| 383 | + eddsaGen.initialize(new ECNamedCurveGenParameterSpec("ed25519")); |
| 384 | + KeyPair kp = eddsaGen.generateKeyPair(); |
| 385 | + Date creationTime = currentTimeRounded(); |
| 386 | + String passphrase = "recycle"; |
| 387 | + |
| 388 | + PGPKeyPair keyPair = new JcaPGPKeyPair(PublicKeyPacket.VERSION_6, PublicKeyAlgorithmTags.Ed25519, kp, creationTime); |
| 389 | + PBESecretKeyEncryptor cfbEncBuilder = new JcePBESecretKeyEncryptorBuilder(SymmetricKeyAlgorithmTags.AES_128) |
| 390 | + .setProvider(prov) |
| 391 | + .setSecureRandom(CryptoServicesRegistrar.getSecureRandom()) |
| 392 | + .build(passphrase.toCharArray()); |
| 393 | + PGPDigestCalculatorProvider digestProv = new JcaPGPDigestCalculatorProviderBuilder() |
| 394 | + .setProvider(prov) |
| 395 | + .build(); |
| 396 | + |
| 397 | + // Encrypt key using CFB mode |
| 398 | + PGPSecretKey cfbEncKey = new PGPSecretKey( |
| 399 | + keyPair.getPrivateKey(), |
| 400 | + keyPair.getPublicKey(), |
| 401 | + digestProv.get(HashAlgorithmTags.SHA1), |
| 402 | + true, |
| 403 | + cfbEncBuilder); |
| 404 | + |
| 405 | + PBESecretKeyDecryptor cfbDecryptor = new JcePBESecretKeyDecryptorBuilder(digestProv) |
| 406 | + .setProvider(prov) |
| 407 | + .build(passphrase.toCharArray()); |
| 408 | + |
| 409 | + JcaAEADSecretKeyEncryptorBuilder aeadEncBuilder = new JcaAEADSecretKeyEncryptorBuilder( |
| 410 | + AEADAlgorithmTags.OCB, SymmetricKeyAlgorithmTags.AES_128, S2K.Argon2Params.memoryConstrainedParameters()) |
| 411 | + .setProvider(prov); |
| 412 | + |
| 413 | + PGPSecretKey aeadEncKey = PGPSecretKey.copyWithNewPassword( |
| 414 | + cfbEncKey, |
| 415 | + cfbDecryptor, |
| 416 | + aeadEncBuilder.build(passphrase.toCharArray(), cfbEncKey.getPublicKey().getPublicKeyPacket())); |
| 417 | + PBESecretKeyDecryptor aeadDecryptor = new JcePBESecretKeyDecryptorBuilder(digestProv) |
| 418 | + .setProvider(prov) |
| 419 | + .build(passphrase.toCharArray()); |
| 420 | + isNotNull(aeadEncKey.extractPrivateKey(aeadDecryptor)); |
376 | 421 | }
|
377 | 422 |
|
378 | 423 | private void reencryptKeyBc()
|
|
0 commit comments