Skip to content

Commit 1fe1ba8

Browse files
committed
Fix JCE implementation
1 parent d12a902 commit 1fe1ba8

13 files changed

Lines changed: 950 additions & 132 deletions

‎pg/src/main/java/org/bouncycastle/openpgp/api/OpenPGPMessageProcessor.java‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,13 @@ public OpenPGPMessageProcessor(OpenPGPImplementation implementation, OpenPGPPoli
5454
{
5555
this.implementation = implementation;
5656
this.configuration = new Configuration(policy);
57+
configuration.exceptionCallback = new PGPExceptionCallback() {
58+
@Override
59+
public void onException(PGPException e) {
60+
// -
61+
e.printStackTrace();
62+
}
63+
};
5764
}
5865

5966
/**
Lines changed: 0 additions & 85 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,11 @@
11
package org.bouncycastle.openpgp.operator;
22

3-
import org.bouncycastle.bcpg.ECDHPublicBCPGKey;
43
import org.bouncycastle.bcpg.InputStreamPacket;
54
import org.bouncycastle.bcpg.PublicKeyAlgorithmTags;
65
import org.bouncycastle.bcpg.PublicKeyEncSessionPacket;
76
import org.bouncycastle.bcpg.SymmetricEncIntegrityPacket;
87
import org.bouncycastle.bcpg.X25519PublicBCPGKey;
98
import org.bouncycastle.bcpg.X448PublicBCPGKey;
10-
import org.bouncycastle.crypto.InvalidCipherTextException;
11-
import org.bouncycastle.crypto.params.AsymmetricKeyParameter;
12-
import org.bouncycastle.crypto.params.ECPublicKeyParameters;
139
import org.bouncycastle.openpgp.PGPException;
1410
import org.bouncycastle.util.Arrays;
1511

@@ -82,85 +78,4 @@ protected static void checkRange(int pLen, byte[] enc)
8278
throw new PGPException("encoded length out of range");
8379
}
8480
}
85-
86-
/**
87-
* Return a callback to perform low-level public-key cryptographic operations.
88-
* @return callback
89-
*/
90-
protected abstract PublicKeyCryptoCallback getCryptoCallback();
91-
92-
/**
93-
* Callback for low-level PK crypto operations.
94-
*
95-
*/
96-
public static abstract class PublicKeyCryptoCallback
97-
{
98-
/**
99-
* Perform RSA decryption of an encrypted session key.
100-
*
101-
* @param keyAlgorithm public key algorithm
102-
* @param pEnc encrypted session key
103-
* @param privKey RSA private key
104-
* @return decrypted session key
105-
* @throws PGPException if the message cannot be decrypted
106-
* @throws InvalidCipherTextException if the ciphertext is invalid
107-
*/
108-
public abstract byte[] decryptRSA(int keyAlgorithm,
109-
byte[] pEnc,
110-
AsymmetricKeyParameter privKey)
111-
throws PGPException, InvalidCipherTextException;
112-
113-
/**
114-
* Perform ElGamal decryption of an encrypted session key.
115-
*
116-
* @param keyAlgorithm public key algorithm
117-
* @param secKeyData encrypted session key data
118-
* @param privKey ElGamal private key
119-
* @return decrypted session key
120-
* @throws InvalidCipherTextException if the ciphertext is invalid
121-
* @throws PGPException if the message cannot be decrypted
122-
*/
123-
public abstract byte[] decryptElGamal(int keyAlgorithm,
124-
byte[][] secKeyData,
125-
AsymmetricKeyParameter privKey)
126-
throws InvalidCipherTextException, PGPException;
127-
128-
/**
129-
* Perform an ECDH handshake to calculate a shared secret.
130-
*
131-
* @param pubKey our ECDH public key
132-
* @param ephemeralKeyBytes encoded ephemeral key pair
133-
* @param privKey private ECDH key
134-
* @return shared secret
135-
* @throws PGPException if the message cannot be decrypted
136-
*/
137-
public abstract byte[] decryptECDH(ECDHPublicBCPGKey pubKey,
138-
byte[] ephemeralKeyBytes,
139-
AsymmetricKeyParameter privKey)
140-
throws PGPException;
141-
142-
/**
143-
* Perform an X25519 handshake to calculate a shared secret.
144-
*
145-
* @param privKey private X25519 key
146-
* @param ephemeralKey encoded ephemeral X25519 public key
147-
* @return shared secret
148-
* @throws PGPException if the message cannot be decrypted
149-
*/
150-
public abstract byte[] decryptX25519(AsymmetricKeyParameter privKey,
151-
byte[] ephemeralKey)
152-
throws PGPException;
153-
154-
/**
155-
* Perform an X448 handshake to calculate a shared secret.
156-
*
157-
* @param privKey private X448 key
158-
* @param ephemeralKey encoded ephemeral X448 public key
159-
* @return shared secret
160-
* @throws PGPException if the message cannot be decrypted
161-
*/
162-
public abstract byte[] decryptX448(AsymmetricKeyParameter privKey,
163-
byte[] ephemeralKey)
164-
throws PGPException;
165-
}
16681
}

‎pg/src/main/java/org/bouncycastle/openpgp/operator/bc/BcPublicKeyDataDecryptorFactory.java‎

Lines changed: 93 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -240,8 +240,17 @@ private byte[] recoverX448SessionData(byte[][] secKeyData,
240240

241241
byte[] secret = getCryptoCallback().decryptX448(privKey, ephemeralKey);
242242

243+
PublicKeyPacket publicKeyPacket;
244+
if (pgpPubKey != null)
245+
{
246+
publicKeyPacket = pgpPubKey.getPublicKeyPacket();
247+
}
248+
else
249+
{
250+
publicKeyPacket = pgpPrivKey.getPublicKeyPacket();
251+
}
243252
byte[] hkdfOut = RFC6637KDFCalculator.createKey(HashAlgorithmTags.SHA512, SymmetricKeyAlgorithmTags.AES_256,
244-
Arrays.concatenate(ephemeralKey, pgpPrivKey.getPublicKeyPacket().getKey().getEncoded(), secret),
253+
Arrays.concatenate(ephemeralKey, publicKeyPacket.getKey().getEncoded(), secret),
245254
"OpenPGP X448");
246255

247256
return unwrapSessionData(keyEnc, SymmetricKeyAlgorithmTags.AES_128, new KeyParameter(hkdfOut));
@@ -310,7 +319,85 @@ public PGPDataDecryptor createDataDecryptor(SymmetricEncIntegrityPacket seipd, P
310319
return BcAEADUtil.createOpenPgpV6DataDecryptor(seipd, sessionKey);
311320
}
312321

313-
@Override
322+
/**
323+
* Callback for low-level PK crypto operations.
324+
*
325+
*/
326+
public static abstract class PublicKeyCryptoCallback
327+
{
328+
/**
329+
* Perform RSA decryption of an encrypted session key.
330+
*
331+
* @param keyAlgorithm public key algorithm
332+
* @param pEnc encrypted session key
333+
* @param privKey RSA private key
334+
* @return decrypted session key
335+
* @throws PGPException if the message cannot be decrypted
336+
* @throws InvalidCipherTextException if the ciphertext is invalid
337+
*/
338+
public abstract byte[] decryptRSA(int keyAlgorithm,
339+
byte[] pEnc,
340+
AsymmetricKeyParameter privKey)
341+
throws PGPException, InvalidCipherTextException;
342+
343+
/**
344+
* Perform ElGamal decryption of an encrypted session key.
345+
*
346+
* @param keyAlgorithm public key algorithm
347+
* @param secKeyData encrypted session key data
348+
* @param privKey ElGamal private key
349+
* @return decrypted session key
350+
* @throws InvalidCipherTextException if the ciphertext is invalid
351+
* @throws PGPException if the message cannot be decrypted
352+
*/
353+
public abstract byte[] decryptElGamal(int keyAlgorithm,
354+
byte[][] secKeyData,
355+
AsymmetricKeyParameter privKey)
356+
throws InvalidCipherTextException, PGPException;
357+
358+
/**
359+
* Perform an ECDH handshake to calculate a shared secret.
360+
*
361+
* @param pubKey our ECDH public key
362+
* @param ephemeralKeyBytes encoded ephemeral key pair
363+
* @param privKey private ECDH key
364+
* @return shared secret
365+
* @throws PGPException if the message cannot be decrypted
366+
*/
367+
public abstract byte[] decryptECDH(ECDHPublicBCPGKey pubKey,
368+
byte[] ephemeralKeyBytes,
369+
AsymmetricKeyParameter privKey)
370+
throws PGPException;
371+
372+
/**
373+
* Perform an X25519 handshake to calculate a shared secret.
374+
*
375+
* @param privKey private X25519 key
376+
* @param ephemeralKey encoded ephemeral X25519 public key
377+
* @return shared secret
378+
* @throws PGPException if the message cannot be decrypted
379+
*/
380+
public abstract byte[] decryptX25519(AsymmetricKeyParameter privKey,
381+
byte[] ephemeralKey)
382+
throws PGPException;
383+
384+
/**
385+
* Perform an X448 handshake to calculate a shared secret.
386+
*
387+
* @param privKey private X448 key
388+
* @param ephemeralKey encoded ephemeral X448 public key
389+
* @return shared secret
390+
* @throws PGPException if the message cannot be decrypted
391+
*/
392+
public abstract byte[] decryptX448(AsymmetricKeyParameter privKey,
393+
byte[] ephemeralKey)
394+
throws PGPException;
395+
}
396+
397+
/**
398+
* Return a callback to perform low-level public-key cryptographic operations.
399+
* @return callback
400+
*/
314401
protected PublicKeyCryptoCallback getCryptoCallback() {
315402
return new BcPublicKeyCryptoCallback();
316403
}
@@ -322,9 +409,12 @@ static class BcPublicKeyCryptoCallback
322409
public byte[] decryptRSA(int keyAlgorithm, byte[] sessionKey, AsymmetricKeyParameter privKey)
323410
throws PGPException, InvalidCipherTextException
324411
{
412+
System.out.println("BC pEnc: " + org.bouncycastle.util.encoders.Hex.toHexString(sessionKey));
325413
BufferedAsymmetricBlockCipher c1 = getBufferedAsymmetricBlockCipher(keyAlgorithm, privKey);
326414
c1.processBytes(sessionKey, 0, sessionKey.length);
327-
return c1.doFinal();
415+
byte[] decSess = c1.doFinal();
416+
System.out.println("BC decSes: " + org.bouncycastle.util.encoders.Hex.toHexString(decSess));
417+
return decSess;
328418
}
329419

330420
@Override

‎pg/src/main/java/org/bouncycastle/openpgp/operator/bc/RFC6637KDFCalculator.java‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@
1515
/**
1616
* Calculator for the EC based KDF algorithm described in RFC 6637
1717
*/
18-
class RFC6637KDFCalculator
18+
public class RFC6637KDFCalculator
1919
{
2020
// "Anonymous Sender ", which is the octet sequence
2121
private static final byte[] ANONYMOUS_SENDER = Hex.decode("416E6F6E796D6F75732053656E64657220202020");
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
package org.bouncycastle.openpgp.operator.jcajce;
2+
3+
public class JcePublicKeyDataDecryptorFactory {
4+
}

‎pg/src/main/java/org/bouncycastle/openpgp/operator/jcajce/JcePublicKeyDataDecryptorFactoryBuilder.java‎

Lines changed: 0 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -130,11 +130,6 @@ public PublicKeyDataDecryptorFactory build(final PrivateKey privKey)
130130
{
131131
return new AbstractPublicKeyDataDecryptorFactory()
132132
{
133-
@Override
134-
protected PublicKeyCryptoCallback getCryptoCallback() {
135-
return null;
136-
}
137-
138133
final int expectedPayLoadSize = getExpectedPayloadSize(privKey);
139134

140135
@Override
@@ -178,11 +173,6 @@ public PublicKeyDataDecryptorFactory build(final PGPPrivateKey privKey)
178173
{
179174
return new AbstractPublicKeyDataDecryptorFactory()
180175
{
181-
@Override
182-
protected PublicKeyCryptoCallback getCryptoCallback() {
183-
return null;
184-
}
185-
186176
@Override
187177
public byte[] recoverSessionData(int keyAlgorithm, byte[][] secKeyData, int pkeskVersion)
188178
throws PGPException

0 commit comments

Comments
 (0)