|
21 | 21 | import org.bouncycastle.bcpg.SecretKeyPacket;
|
22 | 22 | import org.bouncycastle.bcpg.SymmetricKeyAlgorithmTags;
|
23 | 23 | import org.bouncycastle.crypto.AsymmetricCipherKeyPair;
|
| 24 | +import org.bouncycastle.crypto.CryptoServicesRegistrar; |
24 | 25 | import org.bouncycastle.crypto.generators.Ed25519KeyPairGenerator;
|
25 | 26 | import org.bouncycastle.crypto.params.Ed25519KeyGenerationParameters;
|
26 | 27 | import org.bouncycastle.jce.provider.BouncyCastleProvider;
|
|
45 | 46 | import org.bouncycastle.openpgp.operator.jcajce.JcaPGPKeyPair;
|
46 | 47 | import org.bouncycastle.openpgp.operator.jcajce.JcePBEProtectionRemoverFactory;
|
47 | 48 | import org.bouncycastle.openpgp.operator.jcajce.JcePBESecretKeyDecryptorBuilder;
|
| 49 | +import org.bouncycastle.openpgp.operator.jcajce.JcePBESecretKeyEncryptorBuilder; |
48 | 50 | import org.bouncycastle.util.encoders.Hex;
|
49 | 51 |
|
50 | 52 | public class AEADProtectedPGPSecretKeyTest
|
@@ -363,14 +365,57 @@ private void lockUnlockKeyJca(
|
363 | 365 | keyPair.getPrivateKey().getPrivateKeyDataPacket().getEncoded(), dec.getPrivateKeyDataPacket().getEncoded());
|
364 | 366 | }
|
365 | 367 |
|
366 |
| - private void reencryptKey() throws PGPException { |
| 368 | + private void reencryptKey() |
| 369 | + throws PGPException, InvalidAlgorithmParameterException, NoSuchAlgorithmException |
| 370 | + { |
367 | 371 | reencryptKeyBc();
|
368 | 372 | reencryptKeyJca();
|
369 | 373 | }
|
370 | 374 |
|
371 | 375 | private void reencryptKeyJca()
|
| 376 | + throws NoSuchAlgorithmException, InvalidAlgorithmParameterException, PGPException |
372 | 377 | {
|
| 378 | + BouncyCastleProvider prov = new BouncyCastleProvider(); |
| 379 | + KeyPairGenerator eddsaGen = KeyPairGenerator.getInstance("EdDSA", prov); |
373 | 380 |
|
| 381 | + eddsaGen.initialize(new ECNamedCurveGenParameterSpec("ed25519")); |
| 382 | + KeyPair kp = eddsaGen.generateKeyPair(); |
| 383 | + Date creationTime = currentTimeRounded(); |
| 384 | + String passphrase = "recycle"; |
| 385 | + |
| 386 | + PGPKeyPair keyPair = new JcaPGPKeyPair(PublicKeyPacket.VERSION_6, PublicKeyAlgorithmTags.Ed25519, kp, creationTime); |
| 387 | + PBESecretKeyEncryptor cfbEncBuilder = new JcePBESecretKeyEncryptorBuilder(SymmetricKeyAlgorithmTags.AES_128) |
| 388 | + .setProvider(prov) |
| 389 | + .setSecureRandom(CryptoServicesRegistrar.getSecureRandom()) |
| 390 | + .build(passphrase.toCharArray()); |
| 391 | + PGPDigestCalculatorProvider digestProv = new JcaPGPDigestCalculatorProviderBuilder() |
| 392 | + .setProvider(prov) |
| 393 | + .build(); |
| 394 | + |
| 395 | + // Encrypt key using CFB mode |
| 396 | + PGPSecretKey cfbEncKey = new PGPSecretKey( |
| 397 | + keyPair.getPrivateKey(), |
| 398 | + keyPair.getPublicKey(), |
| 399 | + digestProv.get(HashAlgorithmTags.SHA1), |
| 400 | + true, |
| 401 | + cfbEncBuilder); |
| 402 | + |
| 403 | + PBESecretKeyDecryptor cfbDecryptor = new JcePBESecretKeyDecryptorBuilder(digestProv) |
| 404 | + .setProvider(prov) |
| 405 | + .build(passphrase.toCharArray()); |
| 406 | + |
| 407 | + JcaAEADSecretKeyEncryptorBuilder aeadEncBuilder = new JcaAEADSecretKeyEncryptorBuilder( |
| 408 | + AEADAlgorithmTags.OCB, SymmetricKeyAlgorithmTags.AES_128, S2K.Argon2Params.memoryConstrainedParameters()) |
| 409 | + .setProvider(prov); |
| 410 | + |
| 411 | + PGPSecretKey aeadEncKey = PGPSecretKey.copyWithNewPassword( |
| 412 | + cfbEncKey, |
| 413 | + cfbDecryptor, |
| 414 | + aeadEncBuilder.build(passphrase.toCharArray(), cfbEncKey.getPublicKey().getPublicKeyPacket())); |
| 415 | + PBESecretKeyDecryptor aeadDecryptor = new JcePBESecretKeyDecryptorBuilder(digestProv) |
| 416 | + .setProvider(prov) |
| 417 | + .build(passphrase.toCharArray()); |
| 418 | + isNotNull(aeadEncKey.extractPrivateKey(aeadDecryptor)); |
374 | 419 | }
|
375 | 420 |
|
376 | 421 | private void reencryptKeyBc()
|
|
0 commit comments