2 * ============LICENSE_START=======================================================
4 * ================================================================================
5 * Copyright (C) 2020 Nokia. All rights reserved.
6 * ================================================================================
7 * Licensed under the Apache License, Version 2.0 (the "License");
8 * you may not use this file except in compliance with the License.
9 * You may obtain a copy of the License at
11 * http://www.apache.org/licenses/LICENSE-2.0
13 * Unless required by applicable law or agreed to in writing, software
14 * distributed under the License is distributed on an "AS IS" BASIS,
15 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 * See the License for the specific language governing permissions and
17 * limitations under the License.
18 * ============LICENSE_END=========================================================
21 package org.onap.oom.certservice.certification.model;
23 import java.io.IOException;
24 import java.security.KeyFactory;
25 import java.security.NoSuchAlgorithmException;
26 import java.security.PrivateKey;
27 import java.security.PublicKey;
28 import java.security.spec.InvalidKeySpecException;
29 import java.security.spec.PKCS8EncodedKeySpec;
30 import java.security.spec.X509EncodedKeySpec;
31 import java.util.Arrays;
32 import java.util.Collections;
33 import java.util.List;
34 import java.util.Objects;
35 import java.util.stream.Collectors;
37 import org.bouncycastle.asn1.x500.X500Name;
38 import org.bouncycastle.asn1.x509.Extension;
39 import org.bouncycastle.asn1.x509.Extensions;
40 import org.bouncycastle.asn1.x509.GeneralName;
41 import org.bouncycastle.asn1.x509.GeneralNames;
42 import org.bouncycastle.pkcs.PKCS10CertificationRequest;
43 import org.bouncycastle.util.io.pem.PemObject;
45 import org.onap.oom.certservice.certification.exception.CsrDecryptionException;
46 import org.onap.oom.certservice.certification.exception.DecryptionException;
47 import org.onap.oom.certservice.certification.exception.KeyDecryptionException;
50 public class CsrModel {
52 private final PKCS10CertificationRequest csr;
53 private final X500Name subjectData;
54 private final PrivateKey privateKey;
55 private final PublicKey publicKey;
56 private final List<String> sans;
58 public CsrModel(PKCS10CertificationRequest csr, X500Name subjectData, PrivateKey privateKey, PublicKey publicKey,
61 this.subjectData = subjectData;
62 this.privateKey = privateKey;
63 this.publicKey = publicKey;
67 public PKCS10CertificationRequest getCsr() {
71 public X500Name getSubjectData() {
75 public PrivateKey getPrivateKey() {
79 public PublicKey getPublicKey() {
83 public List<String> getSans() {
88 public String toString() {
89 return "Subject: { " + subjectData + " ,SANs: " + sans + " }";
92 public static class CsrModelBuilder {
94 private final PKCS10CertificationRequest csr;
95 private final PemObject privateKey;
97 public CsrModel build() throws DecryptionException {
99 X500Name subjectData = getSubjectData();
100 PrivateKey javaPrivateKey = convertingPemPrivateKeyToJavaSecurityPrivateKey(getPrivateKey());
101 PublicKey javaPublicKey = convertingPemPublicKeyToJavaSecurityPublicKey(getPublicKey());
102 List<String> sans = getSansData();
104 return new CsrModel(csr, subjectData, javaPrivateKey, javaPublicKey, sans);
107 public CsrModelBuilder(PKCS10CertificationRequest csr, PemObject privateKey) {
109 this.privateKey = privateKey;
112 private PemObject getPublicKey() throws CsrDecryptionException {
114 return new PemObject("PUBLIC KEY", csr.getSubjectPublicKeyInfo().getEncoded());
115 } catch (IOException e) {
116 throw new CsrDecryptionException("Reading Public Key from CSR failed", e.getCause());
120 private PemObject getPrivateKey() {
124 private X500Name getSubjectData() {
125 return csr.getSubject();
128 private List<String> getSansData() {
129 if (!isAttrsEmpty() && !isAttrsValuesEmpty()) {
130 Extensions extensions = Extensions.getInstance(csr.getAttributes()[0].getAttrValues().getObjectAt(0));
131 GeneralName[] arrayOfAlternativeNames =
132 GeneralNames.fromExtensions(extensions, Extension.subjectAlternativeName).getNames();
133 return Arrays.stream(arrayOfAlternativeNames).map(GeneralName::getName).map(Objects::toString)
134 .collect(Collectors.toList());
136 return Collections.emptyList();
139 private boolean isAttrsValuesEmpty() {
140 return csr.getAttributes()[0].getAttrValues().size() == 0;
143 private boolean isAttrsEmpty() {
144 return csr.getAttributes().length == 0;
147 private PrivateKey convertingPemPrivateKeyToJavaSecurityPrivateKey(PemObject privateKey)
148 throws KeyDecryptionException {
150 KeyFactory factory = KeyFactory.getInstance("RSA");
151 PKCS8EncodedKeySpec keySpec = new PKCS8EncodedKeySpec(privateKey.getContent());
152 return factory.generatePrivate(keySpec);
153 } catch (NoSuchAlgorithmException | InvalidKeySpecException e) {
154 throw new KeyDecryptionException("Converting Private Key failed", e.getCause());
158 private PublicKey convertingPemPublicKeyToJavaSecurityPublicKey(PemObject publicKey)
159 throws KeyDecryptionException {
161 KeyFactory factory = KeyFactory.getInstance("RSA");
162 X509EncodedKeySpec keySpec = new X509EncodedKeySpec(publicKey.getContent());
163 return factory.generatePublic(keySpec);
164 } catch (InvalidKeySpecException | NoSuchAlgorithmException e) {
165 throw new KeyDecryptionException("Converting Public Key from CSR failed", e.getCause());