/* * This file is part of cert-signer * Copyright (c) 2024 Paolo Lulli. * * This program is free software: you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation, version 3. * * This program is distributed in the hope that it will be useful, but * WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU * General Public License for more details. * * You should have received a copy of the GNU General Public License * along with this program. If not, see . */ package net.lulli.certsigner.ca; import net.lulli.certsigner.util.Serde; import net.lulli.certsigner.util.PemUtil; import net.lulli.certsigner.Settings; import org.bouncycastle.jce.provider.BouncyCastleProvider; import org.bouncycastle.pkcs.PKCS10CertificationRequest; import java.security.PrivateKey; import java.security.PublicKey; import java.security.Security; import java.security.cert.X509Certificate; import java.util.Objects; public class CertificateData { private final String certificateSubject; private String pemCertificate; private CertificateData(String certificateSubject) { Objects.requireNonNull(certificateSubject); this.certificateSubject = certificateSubject; } public static CertificateData withSubject(String rootSubject) { return new CertificateData(rootSubject); } public String certificate() { return pemCertificate; } public void sign( String pemPrivateKey, String pemRootCertificate, PKCS10CertificationRequest csr, String rootSubject ) { try { Security.addProvider(new BouncyCastleProvider()); PrivateKey caPrivateKey = Serde.readPKCS8PrivateKey(pemPrivateKey); X509Certificate rootCert = Serde.readX509Certificate(pemRootCertificate); PublicKey caPublicKey = rootCert.getPublicKey(); X509Certificate issuedCert = CertificateIssue.clientCertificate( caPrivateKey, rootSubject, rootCert, csr); issuedCert.verify(caPublicKey, Settings.BC_PROVIDER); this.pemCertificate = PemUtil.toString(issuedCert); } catch (Exception e) { throw new IllegalStateException(e.getMessage()); } } }