SM2证书生成

证书SM2生成

import java.io.FileOutputStream;
import java.math.BigInteger;
import java.security.KeyPair;
import java.security.KeyPairGenerator;
import java.security.SecureRandom;
import java.security.Security;
import java.security.cert.X509Certificate;
import java.text.SimpleDateFormat;
import java.util.Calendar;
import java.util.Date;

import javax.security.auth.x500.X500Principal;

import org.bouncycastle.asn1.gm.GMNamedCurves;
import org.bouncycastle.asn1.x9.X9ECParameters;
import org.bouncycastle.crypto.params.ECDomainParameters;
import org.bouncycastle.jcajce.provider.asymmetric.ec.BCECPrivateKey;
import org.bouncycastle.jcajce.provider.asymmetric.ec.BCECPublicKey;
import org.bouncycastle.jce.spec.ECParameterSpec;
import org.bouncycastle.x509.X509V3CertificateGenerator;

public class SM2CertGen {
	private static X9ECParameters x9ECParameters = GMNamedCurves.getByName("sm2p256v1");
    private static ECParameterSpec ecParameterSpec = new ECParameterSpec(x9ECParameters.getCurve(), x9ECParameters.getG(), x9ECParameters.getN());
 
private static String SignAlgor = "1.2.156.10197.1.501";

/**
 * 生成国密ROOT证书方法
 * 
 * @param pageCert
 *            .getCn()+","+
 * @throws Exception
 */

public static Date getYearLater(int later) {
	Date date = new Date();
	try {
		Calendar calendar = Calendar.getInstance();
		calendar.add(Calendar.YEAR, later);
		date = calendar.getTime();
	} catch (Exception e) {
		System.out.println(e.getMessage());
	}
	return date;
}

public static KeyPair generateKeyPair() {
	try {
		KeyPairGenerator kpGen = KeyPairGenerator.getInstance("EC", "BC");
		kpGen.initialize(ecParameterSpec, new SecureRandom());
		KeyPair kp = kpGen.generateKeyPair();
		return kp;
	} catch (Exception e) {
		throw new RuntimeException(e);
	}
}

public static void genSM2CertByRoot() throws Exception {
	SimpleDateFormat format = new SimpleDateFormat("yyyy-MM-dd HH:mm:ss");
	org.bouncycastle.jce.provider.BouncyCastleProvider bouncyCastleProvider = new org.bouncycastle.jce.provider.BouncyCastleProvider();
	Security.addProvider(bouncyCastleProvider);
	// 证书的名称

	String rootCertPath ="d:/sm2.cer";
	try {
		KeyPair kp = generateKeyPair();// 这块就是生成SM2公私钥对
																// https://zb.oschina.net/service/70e3fdaf699a724b
		System.out
				.println("=====公钥算法=====" + kp.getPublic().getAlgorithm());
		BCECPrivateKey bcecPrivateKey = (BCECPrivateKey) kp.getPrivate();// 使用ECPrivateKey
																			// PrivateKey都可以
		BCECPublicKey bcecPublicKey = (BCECPublicKey) kp.getPublic();// 使用ECPublicKey
																		// PublicKey都可以

		X500Principal principal = new X500Principal("CN=KK丶SS,O=DD丶OO");
		// X500Principal principal = new
		// X500Principal("CN="+pageCert.getCn()+",O="+pageCert.getO());
		X509V3CertificateGenerator certGen = new X509V3CertificateGenerator();
		certGen.setSerialNumber(BigInteger.valueOf(System
				.currentTimeMillis()));
		certGen.setIssuerDN(principal);
		certGen.setNotBefore(new Date());
		certGen.setNotAfter(getYearLater(5));
		certGen.setSubjectDN(principal);
		certGen.setSignatureAlgorithm(SignAlgor);
		certGen.setPublicKey(bcecPublicKey);
		X509Certificate rootCert = certGen.generateX509Certificate(
				bcecPrivateKey, "BC");
		FileOutputStream outputStream = new FileOutputStream(rootCertPath);
		outputStream.write(rootCert.getEncoded());
		outputStream.close();
		System.out.println("success");
	} catch (Exception e) {
		System.out.println("error generate sm2");
	}
}

public static void main(String[] args) throws Exception{
	 genSM2CertByRoot();
}

}

  • 0
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 1
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值