View Javadoc
1   /*
2    * Copyright (c) 2002-2022, City of Paris
3    * All rights reserved.
4    *
5    * Redistribution and use in source and binary forms, with or without
6    * modification, are permitted provided that the following conditions
7    * are met:
8    *
9    *  1. Redistributions of source code must retain the above copyright notice
10   *     and the following disclaimer.
11   *
12   *  2. Redistributions in binary form must reproduce the above copyright notice
13   *     and the following disclaimer in the documentation and/or other materials
14   *     provided with the distribution.
15   *
16   *  3. Neither the name of 'Mairie de Paris' nor 'Lutece' nor the names of its
17   *     contributors may be used to endorse or promote products derived from
18   *     this software without specific prior written permission.
19   *
20   * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
21   * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22   * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23   * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDERS OR CONTRIBUTORS BE
24   * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25   * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26   * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
27   * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
28   * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29   * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
30   * POSSIBILITY OF SUCH DAMAGE.
31   *
32   * License 1.0
33   */
34  package fr.paris.lutece.util.rsa;
35  
36  import java.security.GeneralSecurityException;
37  import java.security.KeyFactory;
38  import java.security.KeyPair;
39  import java.security.KeyPairGenerator;
40  import java.security.NoSuchAlgorithmException;
41  import java.security.PrivateKey;
42  import java.security.PublicKey;
43  import java.security.spec.PKCS8EncodedKeySpec;
44  import java.security.spec.X509EncodedKeySpec;
45  import java.util.Base64;
46  
47  import fr.paris.lutece.portal.service.datastore.DatastoreService;
48  
49  public class RSAKeyDatastoreProvider implements IRSAKeyProvider 
50  {
51  
52  	private static final String DATASTORE_PUBLIC_KEY = "lutece.rsa.key.public";
53      private static final String DATASTORE_PRIVATE_KEY = "lutece.rsa.key.private";
54  
55  	@Override
56  	public PublicKey getPublicKey( ) throws GeneralSecurityException 
57  	{
58  		if ( !DatastoreService.existsKey( DATASTORE_PUBLIC_KEY ) )
59  		{ 
60  			initKeys( );
61  		}
62  		
63          X509EncodedKeySpec keySpecPublic = new X509EncodedKeySpec(
64                      Base64.getDecoder( ).decode( DatastoreService.getDataValue( DATASTORE_PUBLIC_KEY, "" ).getBytes( ) ) );
65              
66          KeyFactory keyFactory = KeyFactory.getInstance( "RSA" );
67  
68          return keyFactory.generatePublic( keySpecPublic );
69          
70  	}
71  	
72  	@Override
73  	public PrivateKey getPrivateKey( ) throws GeneralSecurityException 
74  	{
75  		if ( !DatastoreService.existsKey( DATASTORE_PRIVATE_KEY ) )
76          {
77  			initKeys();
78          }
79  
80          PKCS8EncodedKeySpec keySpecPrivate = new PKCS8EncodedKeySpec(
81                  Base64.getDecoder( ).decode( DatastoreService.getDataValue( DATASTORE_PRIVATE_KEY, "" ).getBytes( ) ) );
82  
83          KeyFactory keyFactory = KeyFactory.getInstance( "RSA" );
84  
85          return keyFactory.generatePrivate( keySpecPrivate );
86  	}
87  
88  	/**
89  	 * init keys if missing
90  	 * @throws GeneralSecurityException 
91  	 */
92  	private void initKeys( ) throws GeneralSecurityException
93  	{
94  		// generate new keys
95  	    KeyPairGenerator keyGen = KeyPairGenerator.getInstance( "RSA" );
96  	    keyGen.initialize( 2048 );
97  	    KeyPair pair = keyGen.generateKeyPair( );
98  	    PrivateKey privateKey = pair.getPrivate( );
99  	    PublicKey publicKey = pair.getPublic( );
100 	    
101 	    // store in DataStore
102 	    DatastoreService.setDataValue( DATASTORE_PUBLIC_KEY, Base64.getEncoder( ).encodeToString( publicKey.getEncoded( ) ) );
103 	    DatastoreService.setDataValue( DATASTORE_PRIVATE_KEY, Base64.getEncoder( ).encodeToString( privateKey.getEncoded( ) ) );
104 	}
105 
106 }