Home | History | Annotate | Download | only in webkit
      1 /*
      2  * Copyright (C) 2009 The Android Open Source Project
      3  *
      4  * Licensed under the Apache License, Version 2.0 (the "License");
      5  * you may not use this file except in compliance with the License.
      6  * You may obtain a copy of the License at
      7  *
      8  *      http://www.apache.org/licenses/LICENSE-2.0
      9  *
     10  * Unless required by applicable law or agreed to in writing, software
     11  * distributed under the License is distributed on an "AS IS" BASIS,
     12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
     13  * See the License for the specific language governing permissions and
     14  * limitations under the License.
     15  */
     16 
     17 package android.webkit;
     18 
     19 import com.android.org.bouncycastle.asn1.pkcs.PKCSObjectIdentifiers;
     20 import com.android.org.bouncycastle.asn1.x509.AlgorithmIdentifier;
     21 import com.android.org.bouncycastle.jce.netscape.NetscapeCertRequest;
     22 import com.android.org.bouncycastle.util.encoders.Base64;
     23 
     24 import android.content.Context;
     25 import android.security.Credentials;
     26 import android.security.KeyChain;
     27 import android.util.Log;
     28 
     29 import java.security.KeyPair;
     30 import java.security.KeyPairGenerator;
     31 import java.util.HashMap;
     32 
     33 final class CertTool {
     34     private static final String LOGTAG = "CertTool";
     35 
     36     private static final AlgorithmIdentifier MD5_WITH_RSA =
     37             new AlgorithmIdentifier(PKCSObjectIdentifiers.md5WithRSAEncryption);
     38 
     39     private static HashMap<String, String> sCertificateTypeMap;
     40     static {
     41         sCertificateTypeMap = new HashMap<String, String>();
     42         sCertificateTypeMap.put("application/x-x509-ca-cert", KeyChain.EXTRA_CERTIFICATE);
     43         sCertificateTypeMap.put("application/x-x509-user-cert", KeyChain.EXTRA_CERTIFICATE);
     44         sCertificateTypeMap.put("application/x-pkcs12", KeyChain.EXTRA_PKCS12);
     45     }
     46 
     47     static String[] getKeyStrengthList() {
     48         return new String[] {"High Grade", "Medium Grade"};
     49     }
     50 
     51     static String getSignedPublicKey(Context context, int index, String challenge) {
     52         try {
     53             KeyPairGenerator generator = KeyPairGenerator.getInstance("RSA");
     54             generator.initialize((index == 0) ? 2048 : 1024);
     55             KeyPair pair = generator.genKeyPair();
     56 
     57             NetscapeCertRequest request = new NetscapeCertRequest(challenge,
     58                     MD5_WITH_RSA, pair.getPublic());
     59             request.sign(pair.getPrivate());
     60             byte[] signed = request.toASN1Object().getDEREncoded();
     61 
     62             Credentials.getInstance().install(context, pair);
     63             return new String(Base64.encode(signed));
     64         } catch (Exception e) {
     65             Log.w(LOGTAG, e);
     66         }
     67         return null;
     68     }
     69 
     70     static void addCertificate(Context context, String type, byte[] value) {
     71         Credentials.getInstance().install(context, type, value);
     72     }
     73 
     74     static String getCertType(String mimeType) {
     75         return sCertificateTypeMap.get(mimeType);
     76     }
     77 
     78     private CertTool() {}
     79 }
     80