[英]Detached signature in CMSSignedData verifies using Bouncy Castle but NOT using java.security.Signature
我已经在网上浏览了几天,以找到造成这种情况的原因,但没有成功。
我正在这样做 :
我发现的事实 :
问题 :
要考虑的想法 :
我认为原因在于签名的生成,但我想我根据文档进行了签名。 或-验证过程可能期望生成器提供PKCS7的某种不同结构,例如PKCS1。 实际上没有什么告诉我下一步要搜索什么。
这是一段代码,应该说明问题和输出(在提供您自己的证书和私钥之后):
import org.bouncycastle.cms.*;
import org.bouncycastle.jce.provider.BouncyCastleProvider;
import java.security.PrivateKey;
import java.security.Security;
import java.security.Signature;
import java.security.cert.CertStore;
import java.security.cert.CollectionCertStoreParameters;
import java.security.cert.X509Certificate;
import java.util.ArrayList;
import java.util.Collection;
import java.util.Iterator;
import java.util.List;
import static org.bouncycastle.cms.CMSSignedGenerator.DIGEST_SHA1;
import static org.bouncycastle.jce.provider.BouncyCastleProvider.PROVIDER_NAME;
public final class VerifyCMSSignedData {
private static final byte[] DATA_TO_BE_SIGNED = "data".getBytes();
private static final String SHA_1_WITH_RSA = "SHA1WithRSA";
private static final boolean DATA_NOT_ATTACHED = false;
private static final String COLLECTION_STORE_TYPE = "Collection";
private static X509Certificate signer;
private static PrivateKey signerPrivateKey;
private static X509Certificate parent;
private VerifyCMSSignedData() {
}
public static void main(String[] args) throws Exception {
Security.addProvider(new BouncyCastleProvider());
setUpCertificates();
shouldVerifySignature();
}
public static void shouldVerifySignature() throws Exception {
CMSSignedData signature = createSignature();
shouldVerifyBySignature(signature.getEncoded());
shouldVerifyByBC(signature.getEncoded());
}
private static void shouldVerifyByBC(byte[] signatureBytes) {
boolean verified = false;
try {
CMSSignedData cms = new CMSSignedData(new CMSProcessableByteArray(DATA_TO_BE_SIGNED), signatureBytes);
CertStore certStore = cms.getCertificatesAndCRLs(COLLECTION_STORE_TYPE, PROVIDER_NAME);
SignerInformationStore signers = cms.getSignerInfos();
Collection c = signers.getSigners();
for (Object aC : c) {
SignerInformation signer = (SignerInformation) aC;
Collection certCollection = certStore.getCertificates(signer.getSID());
Iterator certIt = certCollection.iterator();
X509Certificate cert = (X509Certificate) certIt.next();
verified = signer.verify(cert, PROVIDER_NAME);
}
} catch (Exception e) {
e.printStackTrace();
verified = false;
}
System.out.println(verified ? "VERIFIED BY BC" : "! Not verified through BC !");
}
private static void shouldVerifyBySignature(byte[] signatureBytes) throws Exception {
Signature signatureVerifier = Signature.getInstance(SHA_1_WITH_RSA, PROVIDER_NAME);
signatureVerifier.initVerify(signer.getPublicKey());
signatureVerifier.update(DATA_TO_BE_SIGNED);
boolean verified = signatureVerifier.verify(signatureBytes);
System.out.println(verified ? "VERIFIED BY SIGNATURE CLASS" : "! Not verified by Signature class !");
}
private static CMSSignedData createSignature() throws Exception {
CMSSignedDataGenerator gen = new CMSSignedDataGenerator();
gen.addSigner(signerPrivateKey, signer, DIGEST_SHA1);
List<X509Certificate> allCerts = new ArrayList<>();
if (parent != null) {
allCerts.add(parent);
}
allCerts.add(signer);
CertStore store = CertStore.getInstance(
COLLECTION_STORE_TYPE,
new CollectionCertStoreParameters(allCerts),
PROVIDER_NAME
);
gen.addCertificatesAndCRLs(store);
return gen.generate(new CMSProcessableByteArray(DATA_TO_BE_SIGNED), DATA_NOT_ATTACHED, PROVIDER_NAME);
}
private static void setUpCertificates() throws Exception {
// TODO setup your certificates here
}
}
输出 :
! 未经签名类验证!
由BC验证
流程结束,退出代码为0
您正在验证不同的事物。 验证永远不会成功,因为Java SHA1withRSA
验证需要RSA PKCS#1_v15签名,但是您已生成CMS签名。
CMS封装数字签名或加密的消息以及一些其他元素,例如证书。 CMS消息包含PCKS#1签名,但是,如果要直接使用Java Api对其进行验证,请注意,不会对要签名的数据计算已签名的哈希。 它包含一些其他元素,例如对ASN.1语法中的签名证书的引用,因此您需要以相同的方式计算哈希
您在这里错了:
signatureVerifier.update(DATA_TO_BE_SIGNED);
和这里:
布尔值已验证= signatureVerifier.verify(signatureBytes);
修改您的shouldVerifyBySignature方法以使其工作:
private static void shouldVerifyBySignature(byte[] signatureBytes) throws Exception {
boolean verified = false;
CMSSignedData cms = new CMSSignedData(new CMSProcessableByteArray(DATA_TO_BE_SIGNED), signatureBytes);
CertStore certStore = cms.getCertificatesAndCRLs(COLLECTION_STORE_TYPE, PROVIDER_NAME);
SignerInformationStore signers = cms.getSignerInfos();
Collection c = signers.getSigners();
for (Object aC : c) {
SignerInformation si = (SignerInformation) aC;
Signature signatureVerifier = Signature.getInstance(SHA_1_WITH_RSA, PROVIDER_NAME);
signatureVerifier.initVerify(signer.getPublicKey());
signatureVerifier.update(si.getEncodedSignedAttributes());
verified = signatureVerifier.verify(si.getSignature());
}
System.out.println(verified ? "VERIFIED BY SIGNATURE CLASS" : "! Not verified by Signature class !");
}
我希望这能帮到您!
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.