java – RSA密钥对生成和存储到密钥库

前端之家收集整理的这篇文章主要介绍了java – RSA密钥对生成和存储到密钥库前端之家小编觉得挺不错的,现在分享给大家,也给大家做个参考。
我尝试生成RSA密钥对并将其存储在HSM密钥库中.我现在的代码如下所示:
  1. String configName = "C:\\eTokenConfig.cfg";
  2. Provider p = new sun.security.pkcs11.SunPKCS11(configName);
  3. Security.addProvider(p);
  4. // Read the keystore form the smart card
  5. char[] pin = { 'p','4','s','w','0','r','d' };
  6. KeyStore keyStore = KeyStore.getInstance("PKCS11",p);
  7. keyStore.load(null,pin);
  8. //generate keys
  9. KeyPairGenerator kpg = KeyPairGenerator.getInstance("RSA",p);
  10. kpg.initialize(512);
  11. KeyPair pair = kpg.generateKeyPair();
  12.  
  13. PrivateKey privateKey = pair.getPrivate();
  14. PublicKey publicKey = pair.getPublic();
  15. // Save Keys How ???

我试图使用keyStore.setEntry方法,但问题是它需要一个证书链,我不知道如何获得此证书?

解决方法

http://docs.oracle.com/javase/tutorial/security/apisign/vstep2.html

保存公钥:

  1. X509EncodedKeySpec x509ks = new X509EncodedKeySpec(
  2. publicKey.getEncoded());
  3. FileOutputStream fos = new FileOutputStream(strPathFilePubKey);
  4. fos.write(x509ks.getEncoded());

加载公钥:

  1. byte[] encodedKey = IoUtils.toByteArray(new FileInputStream(strPathFilePubKey));
  2. KeyFactory keyFactory = KeyFactory.getInstance("RSA",p);
  3. X509EncodedKeySpec pkSpec = new X509EncodedKeySpec(
  4. encodedKey);
  5. PublicKey publicKey = keyFactory.generatePublic(pkSpec);

保存私钥:

  1. PKCS8EncodedKeySpec pkcsKeySpec = new PKCS8EncodedKeySpec(
  2. privateKey.getEncoded());
  3. FileOutputStream fos = new FileOutputStream(strPathFilePrivbKey);
  4. fos.write(pkcsKeySpec.getEncoded());

加载私钥:

  1. byte[] encodedKey = IoUtils.toByteArray(new FileInputStream(strPathFilePrivKey));
  2. KeyFactory keyFactory = KeyFactory.getInstance("RSA",p);
  3. PKCS8EncodedKeySpec privKeySpec = new PKCS8EncodedKeySpec(
  4. encodedKey);
  5. PrivateKey privateKey = keyFactory.generatePrivate(privKeySpec);

猜你在找的Java相关文章