java生成pfx_JAVA代码-数字证书公私钥生成-公钥cer ,私钥jks, pfx格式

java生成pfx_JAVA代码-数字证书公私钥生成-公钥cer ,私钥jks, pfx格式importjava.io.File;importjava.io.FileInputStream;importjava.io.FileOutputStream;importjava.io.FileWriter;importjava.io.IOException;importjava.math.BigInteger;importjava.security.InvalidKeyException;im…

大家好,又见面了,我是你们的朋友全栈君。

importjava.io.File;importjava.io.FileInputStream;importjava.io.FileOutputStream;importjava.io.FileWriter;importjava.io.IOException;importjava.math.BigInteger;importjava.security.InvalidKeyException;importjava.security.Key;importjava.security.KeyPair;importjava.security.KeyPairGenerator;importjava.security.KeyStore;importjava.security.KeyStoreException;importjava.security.NoSuchAlgorithmException;importjava.security.NoSuchProviderException;importjava.security.SecureRandom;importjava.security.Security;importjava.security.SignatureException;importjava.security.cert.CertificateEncodingException;importjava.security.cert.CertificateException;importjava.security.cert.CertificateFactory;importjava.security.cert.X509Certificate;importjava.util.Date;importjava.util.Enumeration;importorg.bouncycastle.asn1.x509.X509Name;importorg.bouncycastle.jce.X509V3CertificateGenerator;importorg.bouncycastle.jce.provider.BouncyCastleProvider;importsun.misc.BASE64Encoder;public classDataCertCreate {private String path = “D:/”;/*** 公钥方法*/

static{

Security.addProvider(newBouncyCastleProvider());

}/*** 产生数字公钥证书 String[]

* info长度为9,分别是{cn,ou,o,c,l,st,starttime,endtime,serialnumber}

*

*@throwsSignatureException

*@throwsSecurityException

*@throwsNoSuchProviderException

*@throwsInvalidKeyException*/

publicX509Certificate generateCert(String[] info, KeyPair keyPair_root, KeyPair keyPair_user)throwsInvalidKeyException, NoSuchProviderException, SecurityException, SignatureException {

X509V3CertificateGenerator certGen= newX509V3CertificateGenerator();

X509Certificate cert= null;

certGen.setSerialNumber(new BigInteger(info[8]));

certGen.setIssuerDN(new X509Name(“CN=huahua, OU=hnu, O=university , C=china”));

certGen.setNotBefore(new Date(Long.parseLong(info[6])));

certGen.setNotAfter(new Date(Long.parseLong(info[7])));

certGen.setSubjectDN(new X509Name(“C=” + info[0] + “,OU=” + info[1] + “,O=” + info[2] + “,C=” + info[3] + “,L=”

+ info[4] + “,ST=” + info[3]));

certGen.setPublicKey(keyPair_user.getPublic());

certGen.setSignatureAlgorithm(“SHA1WithRSA”);

cert= certGen.generateX509Certificate(keyPair_root.getPrivate(), “BC”);returncert;

}/*** 私钥方法*/

private String KEYSTORE_PASSWORD = “2078888”;/*** 创建空的jks文件 String[]

* info长度为9,分别是{cn,ou,o,c,l,st,starttime,endtime,serialnumber}*/

public voidgenerateJKS(String[] info) {try{

KeyStore keyStore= KeyStore.getInstance(“jks”);

keyStore.load(null, null);

keyStore.store(new FileOutputStream(“D:/” + info[0] + “.jks”), KEYSTORE_PASSWORD.toCharArray());

}catch (KeyStoreException | NoSuchAlgorithmException | CertificateException |IOException e) {

e.printStackTrace();

}

}/*** 使用空的jks创建自己的jks String[]

* info长度为9,分别是{cn,ou,o,c,l,st,starttime,endtime,serialnumber}*/

public voidstoreJKS(String[] info, KeyPair keyPair_root, KeyPair keyPair_user) {

KeyStore keyStore;try{//use exited jks file

keyStore = KeyStore.getInstance(“JKS”);

keyStore.load(new FileInputStream(“D:/” + info[0] + “.jks”), KEYSTORE_PASSWORD.toCharArray());//generate user’s keystore by info[8] —–keypair

X509V3CertificateGenerator certGen = newX509V3CertificateGenerator();

certGen.setSerialNumber(new BigInteger(info[8]));

certGen.setIssuerDN(new X509Name(“CN=huahua, OU=hnu, O=university , C=china”));

certGen.setNotBefore(new Date(Long.parseLong(info[6])));

certGen.setNotAfter(new Date(Long.parseLong(info[7])));

certGen.setSubjectDN(new X509Name(“C=” + info[0] + “,OU=” + info[1] + “,O=” + info[2] + “,C=” + info[3]+ “,L=” + info[4] + “,ST=” + info[3]));

certGen.setPublicKey(keyPair_user.getPublic());

certGen.setSignatureAlgorithm(“SHA1WithRSA”);

X509Certificate cert= null;

Security.addProvider(neworg.bouncycastle.jce.provider.BouncyCastleProvider());

cert= certGen.generateX509Certificate(keyPair_root.getPrivate(), “BC”);

X509Certificate[] chain= new X509Certificate[1];

chain[0] =cert;

keyStore.setKeyEntry(“mykey”, keyPair_user.getPrivate(), KEYSTORE_PASSWORD.toCharArray(), chain);

keyStore.setCertificateEntry(“single_cert”, cert);

keyStore.store(new FileOutputStream(“D:/” + info[0] + “.jks”), KEYSTORE_PASSWORD.toCharArray());

}catch(Exception e) {

e.printStackTrace();

}

}/*** 公私钥公共方法*/

/*** 根据seed产生密钥对

*

*@paramseed

*@return*@throwsNoSuchAlgorithmException*/

public KeyPair generateKeyPair(int seed) throwsNoSuchAlgorithmException {

KeyPairGenerator kpg= KeyPairGenerator.getInstance(“RSA”);

kpg.initialize(1024, new SecureRandom(new byte[seed]));

KeyPair keyPair=kpg.generateKeyPair();returnkeyPair;

}public static final String PKCS12 = “PKCS12”;/*** 转换成pfx格式

*

*@paraminfo*/

publicBoolean toPFX(String[] info) {try{

String pfx_keystore_file= “D:/” + info[0] + “.pfx”;

String jkx_keystore_file= “D:/” + info[0] + “.jks”;

KeyStore inputKeyStore= KeyStore.getInstance(“JKS”);

FileInputStream fis= newFileInputStream(jkx_keystore_file);char[] nPassword = null;if ((KEYSTORE_PASSWORD == null) || KEYSTORE_PASSWORD.trim().equals(“”)) {

nPassword= null;

}else{

nPassword=KEYSTORE_PASSWORD.toCharArray();

}

inputKeyStore.load(fis, nPassword);

fis.close();

KeyStore outputKeyStore= KeyStore.getInstance(“PKCS12”);

outputKeyStore.load(null, KEYSTORE_PASSWORD.toCharArray());

Enumeration enums=inputKeyStore.aliases();while(enums.hasMoreElements()) {

String keyAlias=(String) enums.nextElement();

System.out.println(“alias=[” + keyAlias + “]”);if(inputKeyStore.isKeyEntry(keyAlias)) {

Key key=inputKeyStore.getKey(keyAlias, nPassword);

java.security.cert.Certificate[] certChain=inputKeyStore.getCertificateChain(keyAlias);

outputKeyStore.setKeyEntry(keyAlias, key, KEYSTORE_PASSWORD.toCharArray(), certChain);

}

}

FileOutputStream out= newFileOutputStream(pfx_keystore_file);

outputKeyStore.store(out, nPassword);

out.close();return true;

}catch(Exception e) {

e.printStackTrace();

System.out.println(“toPFX :” +e.getMessage());return false;

}

}public booleancreatePublicKey(String[] info) {try{

KeyPair keyPair_root= generateKeyPair(10);

KeyPair keyPair_user= generateKeyPair(100);

X509Certificate cert=generateCert(info, keyPair_root, keyPair_user);

String certPath= path + info[0] + “.cer”;

FileOutputStream fos= newFileOutputStream(certPath);

BASE64Encoder encoder= newBASE64Encoder();

String string=encoder.encode(cert.getEncoded());

System.out.println(string);

fos.write(cert.getEncoded());

fos.close();return true;

}catch(Exception e) {

e.printStackTrace();

System.out.println(“public key :” +e.getMessage());return false;

}

}public booleancreatePublicKeyBYDecode(String[] info) {try{

KeyPair keyPair_root= generateKeyPair(10);

KeyPair keyPair_user= generateKeyPair(100);

X509Certificate cert=generateCert(info, keyPair_root, keyPair_user);

String certPath= path + info[0] + “_base.cer”;

FileWriter wr= new java.io.FileWriter(newFile(certPath));

String encode= newBASE64Encoder().encode(cert.getEncoded());

String strCertificate= “—–BEGIN CERTIFICATE—–\r\n” + encode + “\r\n—–END CERTIFICATE—–\r\n”;

wr.write(strCertificate);//给证书编码

wr.flush();

wr.close();return true;

}catch(Exception e) {

e.printStackTrace();

System.out.println(“public key :” +e.getMessage());return false;

}

}publicX509Certificate fromString(String cert) {try{

CertificateFactory certificateFactory= CertificateFactory.getInstance(“X.509”);

String strCertificate= “—–BEGIN CERTIFICATE—–\n” + cert + “\n—–END CERTIFICATE—–\n”;

java.io.ByteArrayInputStream streamCertificate= newjava.io.ByteArrayInputStream(

strCertificate.getBytes(“UTF-8”));return(X509Certificate) certificateFactory.generateCertificate(streamCertificate);

}catch(Exception ex) {

System.out.println(ex.getMessage());

}return null;

}public booleancreatePrivateKey(String[] info) {try{

KeyPair keyPair_root= generateKeyPair(10);

KeyPair keyPair_user= generateKeyPair(100);

generateJKS(info);

storeJKS(info, keyPair_root, keyPair_user);return true;

}catch(NoSuchAlgorithmException e) {

e.printStackTrace();

System.out.println(“private key :” +e.getMessage());return false;

}

}public static void main(String[] args) throwsNoSuchAlgorithmException, InvalidKeyException,

NoSuchProviderException, SecurityException, SignatureException, CertificateEncodingException, IOException {

DataCertCreate dataCertCreate= newDataCertCreate();

String[] info= { “huahua_user”, “hnu”, “university”, “china”, “hunan”, “changsha”, “111111”, “11111111”, “1”};//生成公钥

boolean createPublicKey =dataCertCreate.createPublicKey(info);

System.out.println(“PUBLIC KEY CREATE OK, result==” +createPublicKey);boolean createPublicKeyBYDecode =dataCertCreate.createPublicKeyBYDecode(info);

System.out.println(“PUBLIC KEY BY BASE64Encoder CREATE OK, result==” +createPublicKeyBYDecode);boolean createPrivateKey =dataCertCreate.createPrivateKey(info);

System.out.println(“PRIVATE KEY CREATE OK, result==” +createPrivateKey);

Boolean pfx=dataCertCreate.toPFX(info);

System.out.println(“transToPFX OK, result==” +pfx);

}

}

版权声明:本文内容由互联网用户自发贡献,该文观点仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请联系我们举报,一经查实,本站将立刻删除。

发布者:全栈程序员-站长,转载请注明出处:https://javaforall.net/139701.html原文链接:https://javaforall.net

(0)
全栈程序员-站长的头像全栈程序员-站长


相关推荐

  • IDEA 热部署设置(JRebel插件激活)「建议收藏」

    IDEA 热部署设置(JRebel插件激活)「建议收藏」1.打开File>>setting,选择Plugins>>BrowseRepositories2.搜索Jrebel找到JRebelforIntelliJ,选择install安装                            3. 打开File->setting,选择JRebel>>…

    2022年6月11日
    154
  • java递归下降分析_JAVA中的递归下降

    java递归下降分析_JAVA中的递归下降publicclassParser{//ThesearethetokentypefinalintNONE=0;finalintDELIMITER=1;finalintVARIABLE=2;finalintNUMBER=3;//ThesearethetypeofsyntaxerrorsfinalintSYNTAX=0;final…

    2022年6月16日
    29
  • oracle修改sequence最大最小值_oracle取最大值的记录

    oracle修改sequence最大最小值_oracle取最大值的记录序列是oracle提供的用于生成一系列唯一数字的数据库对象,序列会自动生成顺序递增的序列号,以实现自动提供唯一的主键值,系列可以在多个用户并发环境中使用,并且可以为所有用户生成不重复的顺序数字,而不需要任何额外的I/O开销。创建序列序列和视图一样,并不占用实际的存储空间,只是在数据字典中保存他的定义信息。当创建序列时必须拥有createsequence系统权限。语法格式:createsequ…

    2022年10月18日
    2
  • pycharm使用python_pytorch中文手册

    pycharm使用python_pytorch中文手册本小节只讲如何通过pycharm使用pytorch,pytorch的详细安装点击这里https://blog.csdn.net/huang_shao1/article/details/82958551anaconda的详细安装点击这里https://blog.csdn.net/huang_shao1/article/details/82958615如图所示,我们编辑好了自己pytorch项…

    2022年8月26日
    8
  • 对数的计算公式[通俗易懂]

    对数的计算公式[通俗易懂]性质编辑①;②;③负数与零无对数.④*=1;恒等式及证明a^log(a)(N)=N(a>0,a≠1)推导:log(a)(a^N)=N恒等式证明在a>0且a≠1,N>0时设:当l

    2022年8月1日
    5
  • TCP和UDP协议的区别_朋友关系

    TCP和UDP协议的区别_朋友关系在解释两者之间的关系之前,我们必须从宏观的角度了解互联网的整个交互模型。因为当了解互联网在大体上是如何运作时,我们才能了解HTTP和TCP存在的意义,包括他们所要解决的问题是。 (此图来自Udacity的网络协议教程)互联网的模型被分为4层,从上至下每一层都依赖其底层协议。换言之,Application(应用层)的协议操作成功的前提是Transport(运输层)的存在。没有运输层就没有应…

    2022年9月20日
    3

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

关注全栈程序员社区公众号