java生成pfx_JAVA代码-数字证书公私钥生成-公钥cer ,私钥jks, pfx格式

java生成pfx_JAVA代码-数字证书公私钥生成-公钥cer ,私钥jks, pfx格式importjava.io.File;importjava.io.FileInputStream;importjava.io.FileOutputStream;importjava.io.FileWriter;importjava.io.IOException;importjava.math.BigInteger;importjava.security.InvalidKeyException;im…

大家好,又见面了,我是你们的朋友全栈君。

importjava.io.File;importjava.io.FileInputStream;importjava.io.FileOutputStream;importjava.io.FileWriter;importjava.io.IOException;importjava.math.BigInteger;importjava.security.InvalidKeyException;importjava.security.Key;importjava.security.KeyPair;importjava.security.KeyPairGenerator;importjava.security.KeyStore;importjava.security.KeyStoreException;importjava.security.NoSuchAlgorithmException;importjava.security.NoSuchProviderException;importjava.security.SecureRandom;importjava.security.Security;importjava.security.SignatureException;importjava.security.cert.CertificateEncodingException;importjava.security.cert.CertificateException;importjava.security.cert.CertificateFactory;importjava.security.cert.X509Certificate;importjava.util.Date;importjava.util.Enumeration;importorg.bouncycastle.asn1.x509.X509Name;importorg.bouncycastle.jce.X509V3CertificateGenerator;importorg.bouncycastle.jce.provider.BouncyCastleProvider;importsun.misc.BASE64Encoder;public classDataCertCreate {private String path = “D:/”;/*** 公钥方法*/

static{

Security.addProvider(newBouncyCastleProvider());

}/*** 产生数字公钥证书 String[]

* info长度为9,分别是{cn,ou,o,c,l,st,starttime,endtime,serialnumber}

*

*@throwsSignatureException

*@throwsSecurityException

*@throwsNoSuchProviderException

*@throwsInvalidKeyException*/

publicX509Certificate generateCert(String[] info, KeyPair keyPair_root, KeyPair keyPair_user)throwsInvalidKeyException, NoSuchProviderException, SecurityException, SignatureException {

X509V3CertificateGenerator certGen= newX509V3CertificateGenerator();

X509Certificate cert= null;

certGen.setSerialNumber(new BigInteger(info[8]));

certGen.setIssuerDN(new X509Name(“CN=huahua, OU=hnu, O=university , C=china”));

certGen.setNotBefore(new Date(Long.parseLong(info[6])));

certGen.setNotAfter(new Date(Long.parseLong(info[7])));

certGen.setSubjectDN(new X509Name(“C=” + info[0] + “,OU=” + info[1] + “,O=” + info[2] + “,C=” + info[3] + “,L=”

+ info[4] + “,ST=” + info[3]));

certGen.setPublicKey(keyPair_user.getPublic());

certGen.setSignatureAlgorithm(“SHA1WithRSA”);

cert= certGen.generateX509Certificate(keyPair_root.getPrivate(), “BC”);returncert;

}/*** 私钥方法*/

private String KEYSTORE_PASSWORD = “2078888”;/*** 创建空的jks文件 String[]

* info长度为9,分别是{cn,ou,o,c,l,st,starttime,endtime,serialnumber}*/

public voidgenerateJKS(String[] info) {try{

KeyStore keyStore= KeyStore.getInstance(“jks”);

keyStore.load(null, null);

keyStore.store(new FileOutputStream(“D:/” + info[0] + “.jks”), KEYSTORE_PASSWORD.toCharArray());

}catch (KeyStoreException | NoSuchAlgorithmException | CertificateException |IOException e) {

e.printStackTrace();

}

}/*** 使用空的jks创建自己的jks String[]

* info长度为9,分别是{cn,ou,o,c,l,st,starttime,endtime,serialnumber}*/

public voidstoreJKS(String[] info, KeyPair keyPair_root, KeyPair keyPair_user) {

KeyStore keyStore;try{//use exited jks file

keyStore = KeyStore.getInstance(“JKS”);

keyStore.load(new FileInputStream(“D:/” + info[0] + “.jks”), KEYSTORE_PASSWORD.toCharArray());//generate user’s keystore by info[8] —–keypair

X509V3CertificateGenerator certGen = newX509V3CertificateGenerator();

certGen.setSerialNumber(new BigInteger(info[8]));

certGen.setIssuerDN(new X509Name(“CN=huahua, OU=hnu, O=university , C=china”));

certGen.setNotBefore(new Date(Long.parseLong(info[6])));

certGen.setNotAfter(new Date(Long.parseLong(info[7])));

certGen.setSubjectDN(new X509Name(“C=” + info[0] + “,OU=” + info[1] + “,O=” + info[2] + “,C=” + info[3]+ “,L=” + info[4] + “,ST=” + info[3]));

certGen.setPublicKey(keyPair_user.getPublic());

certGen.setSignatureAlgorithm(“SHA1WithRSA”);

X509Certificate cert= null;

Security.addProvider(neworg.bouncycastle.jce.provider.BouncyCastleProvider());

cert= certGen.generateX509Certificate(keyPair_root.getPrivate(), “BC”);

X509Certificate[] chain= new X509Certificate[1];

chain[0] =cert;

keyStore.setKeyEntry(“mykey”, keyPair_user.getPrivate(), KEYSTORE_PASSWORD.toCharArray(), chain);

keyStore.setCertificateEntry(“single_cert”, cert);

keyStore.store(new FileOutputStream(“D:/” + info[0] + “.jks”), KEYSTORE_PASSWORD.toCharArray());

}catch(Exception e) {

e.printStackTrace();

}

}/*** 公私钥公共方法*/

/*** 根据seed产生密钥对

*

*@paramseed

*@return*@throwsNoSuchAlgorithmException*/

public KeyPair generateKeyPair(int seed) throwsNoSuchAlgorithmException {

KeyPairGenerator kpg= KeyPairGenerator.getInstance(“RSA”);

kpg.initialize(1024, new SecureRandom(new byte[seed]));

KeyPair keyPair=kpg.generateKeyPair();returnkeyPair;

}public static final String PKCS12 = “PKCS12”;/*** 转换成pfx格式

*

*@paraminfo*/

publicBoolean toPFX(String[] info) {try{

String pfx_keystore_file= “D:/” + info[0] + “.pfx”;

String jkx_keystore_file= “D:/” + info[0] + “.jks”;

KeyStore inputKeyStore= KeyStore.getInstance(“JKS”);

FileInputStream fis= newFileInputStream(jkx_keystore_file);char[] nPassword = null;if ((KEYSTORE_PASSWORD == null) || KEYSTORE_PASSWORD.trim().equals(“”)) {

nPassword= null;

}else{

nPassword=KEYSTORE_PASSWORD.toCharArray();

}

inputKeyStore.load(fis, nPassword);

fis.close();

KeyStore outputKeyStore= KeyStore.getInstance(“PKCS12”);

outputKeyStore.load(null, KEYSTORE_PASSWORD.toCharArray());

Enumeration enums=inputKeyStore.aliases();while(enums.hasMoreElements()) {

String keyAlias=(String) enums.nextElement();

System.out.println(“alias=[” + keyAlias + “]”);if(inputKeyStore.isKeyEntry(keyAlias)) {

Key key=inputKeyStore.getKey(keyAlias, nPassword);

java.security.cert.Certificate[] certChain=inputKeyStore.getCertificateChain(keyAlias);

outputKeyStore.setKeyEntry(keyAlias, key, KEYSTORE_PASSWORD.toCharArray(), certChain);

}

}

FileOutputStream out= newFileOutputStream(pfx_keystore_file);

outputKeyStore.store(out, nPassword);

out.close();return true;

}catch(Exception e) {

e.printStackTrace();

System.out.println(“toPFX :” +e.getMessage());return false;

}

}public booleancreatePublicKey(String[] info) {try{

KeyPair keyPair_root= generateKeyPair(10);

KeyPair keyPair_user= generateKeyPair(100);

X509Certificate cert=generateCert(info, keyPair_root, keyPair_user);

String certPath= path + info[0] + “.cer”;

FileOutputStream fos= newFileOutputStream(certPath);

BASE64Encoder encoder= newBASE64Encoder();

String string=encoder.encode(cert.getEncoded());

System.out.println(string);

fos.write(cert.getEncoded());

fos.close();return true;

}catch(Exception e) {

e.printStackTrace();

System.out.println(“public key :” +e.getMessage());return false;

}

}public booleancreatePublicKeyBYDecode(String[] info) {try{

KeyPair keyPair_root= generateKeyPair(10);

KeyPair keyPair_user= generateKeyPair(100);

X509Certificate cert=generateCert(info, keyPair_root, keyPair_user);

String certPath= path + info[0] + “_base.cer”;

FileWriter wr= new java.io.FileWriter(newFile(certPath));

String encode= newBASE64Encoder().encode(cert.getEncoded());

String strCertificate= “—–BEGIN CERTIFICATE—–\r\n” + encode + “\r\n—–END CERTIFICATE—–\r\n”;

wr.write(strCertificate);//给证书编码

wr.flush();

wr.close();return true;

}catch(Exception e) {

e.printStackTrace();

System.out.println(“public key :” +e.getMessage());return false;

}

}publicX509Certificate fromString(String cert) {try{

CertificateFactory certificateFactory= CertificateFactory.getInstance(“X.509”);

String strCertificate= “—–BEGIN CERTIFICATE—–\n” + cert + “\n—–END CERTIFICATE—–\n”;

java.io.ByteArrayInputStream streamCertificate= newjava.io.ByteArrayInputStream(

strCertificate.getBytes(“UTF-8”));return(X509Certificate) certificateFactory.generateCertificate(streamCertificate);

}catch(Exception ex) {

System.out.println(ex.getMessage());

}return null;

}public booleancreatePrivateKey(String[] info) {try{

KeyPair keyPair_root= generateKeyPair(10);

KeyPair keyPair_user= generateKeyPair(100);

generateJKS(info);

storeJKS(info, keyPair_root, keyPair_user);return true;

}catch(NoSuchAlgorithmException e) {

e.printStackTrace();

System.out.println(“private key :” +e.getMessage());return false;

}

}public static void main(String[] args) throwsNoSuchAlgorithmException, InvalidKeyException,

NoSuchProviderException, SecurityException, SignatureException, CertificateEncodingException, IOException {

DataCertCreate dataCertCreate= newDataCertCreate();

String[] info= { “huahua_user”, “hnu”, “university”, “china”, “hunan”, “changsha”, “111111”, “11111111”, “1”};//生成公钥

boolean createPublicKey =dataCertCreate.createPublicKey(info);

System.out.println(“PUBLIC KEY CREATE OK, result==” +createPublicKey);boolean createPublicKeyBYDecode =dataCertCreate.createPublicKeyBYDecode(info);

System.out.println(“PUBLIC KEY BY BASE64Encoder CREATE OK, result==” +createPublicKeyBYDecode);boolean createPrivateKey =dataCertCreate.createPrivateKey(info);

System.out.println(“PRIVATE KEY CREATE OK, result==” +createPrivateKey);

Boolean pfx=dataCertCreate.toPFX(info);

System.out.println(“transToPFX OK, result==” +pfx);

}

}

版权声明:本文内容由互联网用户自发贡献,该文观点仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请联系我们举报,一经查实,本站将立刻删除。

发布者:全栈程序员-站长,转载请注明出处:https://javaforall.net/139701.html原文链接:https://javaforall.net

(0)
全栈程序员-站长的头像全栈程序员-站长


相关推荐

  • 关于 RenderControl 的问题

    关于 RenderControl 的问题主要解决RenderControl时提示控件必须放在具有runat=server的窗体标记内”错误的解决方法1,http://www.cnblogs.com/zhangronghua/archive/2008/11/07/951899.html2,http://hi.baidu.com/tyrant8203/blog/item/615d77082777c0960a7b82b6.html…

    2022年7月20日
    11
  • JavaIO BufferedReader和BufferedWriter介绍和实例

    JavaIO BufferedReader和BufferedWriter介绍和实例BufferedReader和BufferedWriter简介为了提高字符流读写的效率,引入了缓冲机制,进行字符批量的读写,提高了单个字符读写的效率。BufferedReader用于加快读取字符的速度,BufferedWriter用于加快写入的速度BufferedReader和BufferedWriter类各拥有8192个字符的缓冲区。当BufferedReader在读取文本文件时,会先尽…

    2022年5月1日
    42
  • Java多线程——基本概念「建议收藏」

    Java多线程——基本概念「建议收藏」线程和多线程程序:是一段静态的代码,是应用软件执行的蓝本进程:是程序的一次动态执行过程,它对应了从代码加载、执行至执行完毕的一个完整过程,这个过程也是进程本身从产生、发展至消亡的过程线程:是比进程更小的执行单位。进程在其执行过程中,可以产生多个线程,形成多条执行线索,每条线索,即每个线程也有它自身的产生、存在和消亡的过程,也是一个动态的概念主线程:(每个Java程序都有一个…

    2022年5月13日
    37
  • idea 2022.01.4激活码(注册激活)2022.02.14

    (idea 2022.01.4激活码)最近有小伙伴私信我,问我这边有没有免费的intellijIdea的激活码,然后我将全栈君台教程分享给他了。激活成功之后他一直表示感谢,哈哈~https://javaforall.net/100143.htmlIntelliJ2021最新激活注册码,破解教程可免费永久激活,亲测有效,上面是详细链接哦~4KDD…

    2022年4月1日
    51
  • 算法学习笔记——动态规划法

    算法学习笔记——动态规划法

    2022年1月20日
    67
  • kafka 集群配置_kafka集群原理

    kafka 集群配置_kafka集群原理一、kafka简述1、简介kafka是一个高吞吐的分布式消息队列系统。特点是生产者消费者模式,先进先出(FIFO)保证顺序,自己不丢数据,默认每隔7天清理数据。消息列队常见场景:系统之间解耦合、峰值压力缓冲、异步通信。2、集群介绍(1)Kafka架构是由producer(消息生产者)、consumer(消息消费者)、borker(kafka集群的server,负责处理消息读、…

    2022年8月31日
    1

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

关注全栈程序员社区公众号