Class Jwk

java.lang.Object
com.codename1.backend.security.crypto.Jwk

public final class Jwk extends Object

One key, as a JSON Web Key describes it (RFC 7517): an RSA key, an EC key on P-256 or P-384, or a shared secret.

Jwk signing = Jwk.ofPrivateKey(KeyFiles.readPrivateKey("/etc/app/signing.pem"));
Map<String, Object> published = signing.toPublicJson();   // n and e, never d
Jwk theirs = Jwk.parse(Json.parseObject(text));

Inside, a key is held in the form the runtime computes with -- PKCS#8 and SubjectPublicKeyInfo -- and the JSON form is made and read at the edges.

A key has an id. Unless one is given it is the base64url SHA-256 of the SubjectPublicKeyInfo, so the same key has the same id wherever it is loaded and a rotated key has a new one without anybody naming it.

  • Field Summary

    Fields
    Modifier and Type
    Field
    Description
    static final String
    The key type of a shared secret.
  • Method Summary

    Modifier and Type
    Method
    Description
    The one algorithm the key is for, or null when it is for any its type allows.
    P-256 or P-384 for an EC key; null otherwise.
    The id given, or else the base64url SHA-256 of the SubjectPublicKeyInfo; null for a shared secret that was given none.
    RSA, EC or oct.
    byte[]
    The PKCS#8 private key, or the bytes of a shared secret; null for a key that only verifies.
    byte[]
    The SubjectPublicKeyInfo; null for a shared secret.
    The declared use, or null.
    boolean
    Whether the key can sign.
    static Jwk
    ofKeyPair(byte[] privateKey, byte[] publicKey)
    A key that signs and verifies, from a PKCS#8 private key and its SubjectPublicKeyInfo.
    static Jwk
    The key in a PEM text: a private key of any of the forms KeyFiles reads, or a public key.
    static Jwk
    ofPrivateKey(byte[] privateKey)
    A key that signs and verifies, from a PKCS#8 private key that holds its public half; see Der.publicKeyOf(byte[]).
    static Jwk
    ofPublicKey(byte[] publicKey)
    A key that verifies, from a SubjectPublicKeyInfo.
    static Jwk
    ofSecret(byte[] secret)
    A shared secret, for the HMAC algorithms.
    static Jwk
    The public key a JSON Web Key describes.
    The key as the JSON a key set publishes: its type, id and public numbers, with alg and use when it has them.
    Returns a string representation of the object.
    withAlgorithm(String algorithm)
    This key for one algorithm alone: RS256.
    This key under another id.
    This key with a declared use: sig.

    Methods inherited from class Object

    clone, equals, getClass, hashCode, notify, notifyAll, wait, wait, wait
  • Field Details

  • Method Details

    • ofPublicKey

      public static Jwk ofPublicKey(byte[] publicKey) throws IOException
      A key that verifies, from a SubjectPublicKeyInfo.
      Throws:
      IOException
    • ofPrivateKey

      public static Jwk ofPrivateKey(byte[] privateKey) throws IOException
      A key that signs and verifies, from a PKCS#8 private key that holds its public half; see Der.publicKeyOf(byte[]).
      Throws:
      IOException
    • ofKeyPair

      public static Jwk ofKeyPair(byte[] privateKey, byte[] publicKey) throws IOException
      A key that signs and verifies, from a PKCS#8 private key and its SubjectPublicKeyInfo.
      Throws:
      IOException
    • ofSecret

      public static Jwk ofSecret(byte[] secret)
      A shared secret, for the HMAC algorithms. It has no id unless given one, and is never written to JSON.
    • ofPem

      public static Jwk ofPem(String pem) throws IOException
      The key in a PEM text: a private key of any of the forms KeyFiles reads, or a public key.
      Throws:
      IOException
    • parse

      public static Jwk parse(Map<String,Object> json) throws IOException
      The public key a JSON Web Key describes. Only what verifies is read: a d in the JSON is ignored, and a shared secret is refused.
      Throws:
      IOException - when the JSON is not an RSA key or an EC key on P-256 or P-384, with what is wrong
    • withKeyId

      public Jwk withKeyId(String keyId)
      This key under another id.
    • withAlgorithm

      public Jwk withAlgorithm(String algorithm)
      This key for one algorithm alone: RS256. A token signed under any other is not verified with it.
    • withUse

      public Jwk withUse(String use)
      This key with a declared use: sig.
    • getKeyType

      public String getKeyType()
      RSA, EC or oct.
    • getCurve

      public String getCurve()
      P-256 or P-384 for an EC key; null otherwise.
    • getKeyId

      public String getKeyId()
      The id given, or else the base64url SHA-256 of the SubjectPublicKeyInfo; null for a shared secret that was given none.
    • getAlgorithm

      public String getAlgorithm()
      The one algorithm the key is for, or null when it is for any its type allows.
    • getUse

      public String getUse()
      The declared use, or null.
    • getPublicKey

      public byte[] getPublicKey()
      The SubjectPublicKeyInfo; null for a shared secret.
    • getPrivateKey

      public byte[] getPrivateKey()
      The PKCS#8 private key, or the bytes of a shared secret; null for a key that only verifies.
    • isPrivate

      public boolean isPrivate()
      Whether the key can sign.
    • toPublicJson

      public Map<String,Object> toPublicJson()
      The key as the JSON a key set publishes: its type, id and public numbers, with alg and use when it has them. Nothing private is ever in it.
      Throws:
      IllegalStateException - for a shared secret, which has no public form
    • toString

      public String toString()
      Description copied from class: Object
      Returns a string representation of the object. In general, the toString method returns a string that "textually represents" this object. The result should be a concise but informative representation that is easy for a person to read. It is recommended that all subclasses override this method. The toString method for class Object returns a string consisting of the name of the class of which the object is an instance, the at-sign character `@', and the unsigned hexadecimal representation of the hash code of the object. In other words, this method returns a string equal to the value of: getClass().getName() + '@' + Integer.toHexString(hashCode())
      Overrides:
      toString in class Object