You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 033b499
Browse filesBrowse the repository at this point in the historyBrowse files
Administrator
committed
Merge branch 'openpgp-smartcard-decryption' into 'main'
Implement support for OpenPGP External Secret Keys
See merge request root/bc-java!305
Copy file name to clipboardExpand all lines: CONTRIBUTORS.html
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -450,7 +450,7 @@
450
450
<li>Adam Vartanian <https://github.com/flooey> use of ShortBuffer exception and buffer size pre-check in Cipher.doFinal().</li>
451
451
<li>Bernd <https://github.com/ecki> Fix to make PGPUtil.pipeFileContents use buffer and not leak file handle.</li>
452
452
<li>Shartung <https://github.com/shartung> Additional EC Key Agreement algorithms in support of German BSI TR-03111.</li>
453
-
<li>Paul Schaub <https://github.com/vanitasvitae> bringing PGPSecretKey.getUserIds() into line with PGPPublicKey.getUserIds(). Exception message fix in BcPublicKeyDataDecryptorFactory. Additional tests on PGP key ring generation. Improved functionality of PGPSignatureSubpacketGenerator, PGPPublicKeyRing. Tweaks to PGPDataEncryptorBuilder interface, fix for JcaPGP/BcPGP Ed25519 private key conversion. Added configurable CRC detection to ArmoredInputStream, additional control character skipping in ArmoredInputStream. Rewind code for PGPPBEEncryptedData, addition of PGPSignature.getDigestPrefix(). Wrong list traversal fix in PGPSecretKeyRing. Further improvement to use of generics in PGP API. General interop improvements. PGP Public / Secure keyring ignore marker packets when reading. Initial work on PGP session key handling, filtering literal data for canoncialization. Addition of direct key identified key-ring construction. PGPSecretKeyRing.insertOrReplacePublicKey addition. Addition of utility methods for joining/merging signatures and public keys. Addition of PGP regexp packet, PolicyURI packet handling, UTF8 comment testing. Efficiency improvements to TruncatedStream. Initial Argon2 support for OpenPGP. General cleanups. Fast CRC24 implementation, SHA3 addtions to BcImplProvider, improvements to One Pass Signature support, signatue validation, read() consistency in BCPGInputStream. Contributions to AEAD support (v6 & v5) in PGP API. Addition of PGP WildCard ID, moving the PGP example code into the 21st century. Security patches for encrypted data generation, initial thread safe certification verification. Support for V6 EC keys, V6 signatures, V6 encryption, V6 PKESK, PGP packet criticality, and Preferred AEAD CipherSuites sigsubpacket support. Introduce high-level OpenPGP API for message creation/consumption and certificate evaluation. OpenPGP fuzz testing. Fix to prevent a null pointer exception on processing a partial stripped key. Moving the Argon2 memory size exponent bounds check from S2K packet parsing to decryption time. ArmoredInputStream CSF dash-escape hardening. Report and initial patch for OnePassSignaturePacket defaulting to the Legacy packet format for v6 packets (github #2347). PGPKeyPairGenerator factory methods for the OpenPGP brainpool curves (github #2375).</li>
453
+
<li>Paul Schaub <https://github.com/vanitasvitae> bringing PGPSecretKey.getUserIds() into line with PGPPublicKey.getUserIds(). Exception message fix in BcPublicKeyDataDecryptorFactory. Additional tests on PGP key ring generation. Improved functionality of PGPSignatureSubpacketGenerator, PGPPublicKeyRing. Tweaks to PGPDataEncryptorBuilder interface, fix for JcaPGP/BcPGP Ed25519 private key conversion. Added configurable CRC detection to ArmoredInputStream, additional control character skipping in ArmoredInputStream. Rewind code for PGPPBEEncryptedData, addition of PGPSignature.getDigestPrefix(). Wrong list traversal fix in PGPSecretKeyRing. Further improvement to use of generics in PGP API. General interop improvements. PGP Public / Secure keyring ignore marker packets when reading. Initial work on PGP session key handling, filtering literal data for canoncialization. Addition of direct key identified key-ring construction. PGPSecretKeyRing.insertOrReplacePublicKey addition. Addition of utility methods for joining/merging signatures and public keys. Addition of PGP regexp packet, PolicyURI packet handling, UTF8 comment testing. Efficiency improvements to TruncatedStream. Initial Argon2 support for OpenPGP. General cleanups. Fast CRC24 implementation, SHA3 addtions to BcImplProvider, improvements to One Pass Signature support, signatue validation, read() consistency in BCPGInputStream. Contributions to AEAD support (v6 & v5) in PGP API. Addition of PGP WildCard ID, moving the PGP example code into the 21st century. Security patches for encrypted data generation, initial thread safe certification verification. Support for V6 EC keys, V6 signatures, V6 encryption, V6 PKESK, PGP packet criticality, and Preferred AEAD CipherSuites sigsubpacket support. Introduce high-level OpenPGP API for message creation/consumption and certificate evaluation. OpenPGP fuzz testing. Fix to prevent a null pointer exception on processing a partial stripped key. Moving the Argon2 memory size exponent bounds check from S2K packet parsing to decryption time. ArmoredInputStream CSF dash-escape hardening. Report and initial patch for OnePassSignaturePacket defaulting to the Legacy packet format for v6 packets (github #2347). PGPKeyPairGenerator factory methods for the OpenPGP brainpool curves (github #2375). Support for OpenPGP External Secret Keys, and the initial OpenPGP smart card API (bcpgsc) with YubiKey and simulator backends (github #2339, #2374).</li>
454
454
<li>Nick of Nexxar <https://github.com/nros> update to OpenPGP package to handle a broader range of EC curves.</li>
455
455
<li>catbref <https://github.com/catbref> sample implementation of RFC 7748/Ed25519 (incorporated work from github users Valodim and str4d as well).</li>
456
456
<li>gerlion <https://github.com/gerlion> detection of concurrency issue with pre-1.60 EC math library.</li>
Copy file name to clipboardExpand all lines: docs/releasenotes.html
+2Lines changed: 2 additions & 0 deletions
Original file line number
Diff line number
Diff line change
@@ -83,6 +83,8 @@ <h3>2.1.2 Defects Fixed</h3>
83
83
84
84
<h3>2.1.3 Additional Features and Functionality</h3>
85
85
<ul>
86
+
<li>OpenPGP secret keys whose private key material is held outside the key - on a hardware token - are now supported, following <a href="https://datatracker.ietf.org/doc/draft-dkg-openpgp-external-secrets/">draft-dkg-openpgp-external-secrets</a>. org.bouncycastle.bcpg.SecretKeyPacket recognises the External S2K usage octet (SecretKeyPacket.USAGE_EXTERNAL) and its locator hint, PGPSecretKey exposes isExternalKey() / getExternalKeyLocatorHint(), and a decryption backend is plugged into the high level API by registering an org.bouncycastle.openpgp.api.PublicKeyDataDecryptorFactoryProvider with OpenPGPMessageProcessor. On the lightweight side BcPublicKeyDataDecryptorFactory now isolates the raw private-key operation behind BcPublicKeyCryptoCallback, so a subclass of the new BcExternalPublicKeyDataDecryptorFactory routes only the RSA decryption or the ECDH/X25519 agreement to a device while inheriting all packet parsing, KDF and key-unwrap logic. Note the External S2K usage octet is provisional: the draft records it as "TBD (252?)" and IANA has not assigned it.</li>
87
+
<li>A new module, bcpgsc (org.bouncycastle.openpgp.smartcard), provides an OpenPGP smart-card API on top of the external-secret-key support: listing cards across pluggable backends, uploading key material, and decrypting messages with a card-held key. Two backends ship - a YubiKey backend built on the YubiKit libraries, and an in-memory simulator for testing without hardware. The YubiKit libraries are a compile-only dependency, so the published bcpgsc jar carries no third-party runtime dependency; an application using org.bouncycastle.openpgp.smartcard.yubikey must add them to its own classpath. Contributed by Paul Schaub.</li>
86
88
<li>org.bouncycastle.openpgp.operator.PGPKeyPairGenerator gained named convenience methods for the three brainpool curves RFC 9580 sec. 9.2 permits for OpenPGP - generateBrainpoolP256r1ECDHKeyPair / generateBrainpoolP384r1ECDHKeyPair / generateBrainpoolP512r1ECDHKeyPair and the matching ECDSA variants - alongside the existing NIST P-256/P-384/P-521 methods. The generated ECDH keys carry the per-curve KDF hash and KEK symmetric algorithm required by sec. 11.5.1, which the key-pair generator tests now assert for the brainpool and the NIST curves alike. Contributed by Paul Schaub.</li>
87
89
<li>Further extended key usages are now available as KeyPurposeId constants: id-kp-secureShellClient and id-kp-secureShellServer (RFC 6187 sec. 2.2.2, id-kp 21/22), id-kp-cmcArchive (RFC 6402 sec. 2.10, id-kp 29) and id-kp-bundleSecurity (RFC 9174, id-kp 35).</li>
88
90
<li>The two RFC 4556 (PKINIT) extended key usages are now available as KeyPurposeId constants: id-pkinit-KPClientAuth (1.3.6.1.5.2.3.4, sec. 3.2.2) as KeyPurposeId.id_kp_pkinitClientAuth and id-pkinit-KPKdc (1.3.6.1.5.2.3.5, sec. 3.2.4) as KeyPurposeId.id_kp_pkinitKdc. Note these sit under the Kerberos id-pkinit arc rather than the PKIX id-kp arc, and are distinct from the Microsoft smartcard logon usage already available as id_kp_smartcardlogon.</li>
0 commit comments