public abstract class JWK extends Object implements net.minidev.json.JSONAware, Serializable
The following JSON object members are common to all JWK types:
Example JWK (of the Elliptic Curve type):
{ "kty" : "EC", "crv" : "P-256", "x" : "MKBCTNIcKUSDii11ySs3526iDZ8AiTo7Tu6KPAqv7D4", "y" : "4Etl6SRW2YiLUrN5vfvVHuhp7x8PxltmWWlbbM4IFyM", "use" : "enc", "kid" : "1" }
Modifier and Type | Field and Description |
---|---|
static String |
MIME_TYPE
The MIME type of JWK objects:
application/jwk+json; charset=UTF-8 |
Constructor and Description |
---|
JWK(KeyType kty,
KeyUse use,
Set<KeyOperation> ops,
Algorithm alg,
String kid,
URI x5u,
Base64URL x5t,
List<Base64> x5c)
Creates a new JSON Web Key (JWK).
|
Modifier and Type | Method and Description |
---|---|
Base64URL |
computeThumbprint()
Computes the SHA-256 thumbprint of this JWK.
|
Base64URL |
computeThumbprint(String hashAlg)
Computes the thumbprint of this JWK using the specified hash
algorithm.
|
Algorithm |
getAlgorithm()
Gets the intended JOSE algorithm (
alg ) for this JWK. |
String |
getKeyID()
Gets the ID (
kid ) of this JWK. |
Set<KeyOperation> |
getKeyOperations()
Gets the operations (
key_ops ) for this JWK. |
KeyType |
getKeyType()
Gets the type (
kty ) of this JWK. |
KeyUse |
getKeyUse()
Gets the use (
use ) of this JWK. |
abstract LinkedHashMap<String,?> |
getRequiredParams()
Returns the required JWK parameters.
|
List<Base64> |
getX509CertChain()
Gets the X.509 certificate chain (
x5c ) of this JWK. |
Base64URL |
getX509CertThumbprint()
Gets the X.509 certificate thumbprint (
x5t ) of this JWK. |
URI |
getX509CertURL()
Gets the X.509 certificate URL (
x5u ) of this JWK. |
abstract boolean |
isPrivate()
Returns
true if this JWK contains private or sensitive
(non-public) parameters. |
static JWK |
parse(net.minidev.json.JSONObject jsonObject)
Parses a JWK from the specified JSON object representation.
|
static JWK |
parse(String s)
Parses a JWK from the specified JSON object string representation.
|
abstract int |
size()
Returns the size of this JWK.
|
net.minidev.json.JSONObject |
toJSONObject()
Returns a JSON object representation of this JWK.
|
String |
toJSONString()
Returns the JSON object string representation of this JWK.
|
abstract JWK |
toPublicJWK()
Creates a copy of this JWK with all private or sensitive parameters
removed.
|
String |
toString() |
public static final String MIME_TYPE
application/jwk+json; charset=UTF-8
public JWK(KeyType kty, KeyUse use, Set<KeyOperation> ops, Algorithm alg, String kid, URI x5u, Base64URL x5t, List<Base64> x5c)
kty
- The key type. Must not be null
.use
- The key use, null
if not specified or if the key
is intended for signing as well as encryption.ops
- The key operations, null
if not specified.alg
- The intended JOSE algorithm for the key, null
if
not specified.kid
- The key ID, null
if not specified.x5u
- The X.509 certificate URL, null
if not specified.x5t
- The X.509 certificate thumbprint, null
if not
specified.x5c
- The X.509 certificate chain, null
if not
specified.public KeyType getKeyType()
kty
) of this JWK.public KeyUse getKeyUse()
use
) of this JWK.null
if not specified or if the key is
intended for signing as well as encryption.public Set<KeyOperation> getKeyOperations()
key_ops
) for this JWK.null
if not specified.public Algorithm getAlgorithm()
alg
) for this JWK.null
if not specified.public String getKeyID()
kid
) of this JWK. The key ID can be used to
match a specific key. This can be used, for instance, to choose a
key within a JWKSet
during key rollover. The key ID may also
correspond to a JWS/JWE kid
header parameter value.null
if not specified.public URI getX509CertURL()
x5u
) of this JWK.null
if not specified.public Base64URL getX509CertThumbprint()
x5t
) of this JWK.null
if not
specified.public List<Base64> getX509CertChain()
x5c
) of this JWK.null
if not specified.public abstract LinkedHashMap<String,?> getRequiredParams()
public Base64URL computeThumbprint() throws JOSEException
JOSEException
- If the SHA-256 hash algorithm is not
supported.public Base64URL computeThumbprint(String hashAlg) throws JOSEException
hashAlg
- The hash algorithm. Must not be null
.JOSEException
- If the hash algorithm is not supported.public abstract boolean isPrivate()
true
if this JWK contains private or sensitive
(non-public) parameters.true
if this JWK contains private parameters, else
false
.public abstract JWK toPublicJWK()
null
if none can be
created.public abstract int size()
public net.minidev.json.JSONObject toJSONObject()
Example:
{ "kty" : "RSA", "use" : "sig", "kid" : "fd28e025-8d24-48bc-a51a-e2ffc8bc274b" }
public String toJSONString()
toJSONString
in interface net.minidev.json.JSONAware
public String toString()
toString
in class Object
toJSONString()
public static JWK parse(String s) throws ParseException
ECKey
, an RSAKey
, or a
OctetSequenceKey
.s
- The JSON object string to parse. Must not be null
.ParseException
- If the string couldn't be parsed to a
supported JWK.public static JWK parse(net.minidev.json.JSONObject jsonObject) throws ParseException
ECKey
, an RSAKey
, or a
OctetSequenceKey
.jsonObject
- The JSON object to parse. Must not be
null
.ParseException
- If the JSON object couldn't be parsed to a
supported JWK.Copyright © 2016 Connect2id Ltd.. All rights reserved.