advertisement
javaboutique
Search Tips
Articles  |   Tutorials  |   Reviews  |   Tools  |   by Category  |   by Date  |   by Name  |   Submit  |   Source  |   Forums  |  
javaboutique
Browse DevX


Partners & Affiliates











advertisement

Tutorials : Tighten Data Security with the Java XML Digital Signature API :

Generating an Enveloped XML Signature

In this section, you'll be using an X509 certificate to generate an enveloped XML signature. To do this, follow these steps (many steps are identical to those in the previous section):
  1. Create an XMLSigantureFactory Object: You'll use the getInstance method. This method searches a DOM-supporting provider and returns the XMLSignatureFactory implementation.
  2. Create a Reference Object: You'll specify the URI ("" represents the whole document) and create a DigestMethod object and a Transform object. You'll use the Reference object to identify the data that will be signed. All these objects are created using the XMLSignatureFactory created during Step 1.
  3. Create a SignedInfo Object: This object is created using the CanonicalizationMethod object, a SignatureMethod object, and a list of References.
  4. Load the Certificate: To do this, use the KeyStore class in the usual manner. Now, the public/private keys will come from this KeyStore.
  5. Create the KeyInfo Object.
  6. Prepare the Document to be Signed: This is an easy job, based on a simple DOM routine for obtaining the Document object.
  7. Signing the Document: First, you'll need to create an instance of the DOMSignContext by using the private key and the Document root. This object will be passed to the sign method later. Next, to sign the document, create an XMLSignature object (using the SignedInfo and the KeyInfo objects) and call the sign method.
  8. Write the Signed Document into a File: This task can be accomplished in various ways (per example, using a Transformer).
The document to be signed is called in.xml and the output will be saved into a file named outCertEnveloped.xml, shown in Listing 3.

The output of this code is shown below:

<?xml version="1.0" encoding="UTF-8" standalone="no"?><math>
<simple-equations>
  <first_degree_equation>
      First-degree equation:
      <terms_first_degree a="0.0" b="0.0"/>
      <solution>"-b/a"</solution>
  </first_degree_equation>
</simple-equations>
<Signature xmlns=
"http://www.w3.org/2000/09/xmldsig#"><SignedInfo>
<CanonicalizationMethod Algorithm=
"http://www.w3.org/TR/2001/REC-xml-c14n-20010315"/>
<SignatureMethod Algorithm=
"http://www.w3.org/2000/09/xmldsig#dsa-sha1"/><Reference URI=
""><Transforms><Transform Algorithm=
"http://www.w3.org/2000/09/xmldsig#enveloped-signature"/></Transforms>
<DigestMethod Algorithm=
"http://www.w3.org/2000/09/xmldsig#sha1"/><DigestValue>PlQASEXK+FR8BAhzfgt
Kfh79LmM=</DigestValue></Reference></SignedInfo><SignatureValue>
ZCyu/5dfCcfQYYQxlKGzCDUq8DRVOMwF08PGgt3UNCLBZxQss5Q+KQ==</SignatureValue>
<KeyInfo><X509Data><X509SubjectName>CN=localhost,OU=none,O=none,
L=Bucharest,ST=Bucharest,C=RO</X509SubjectName><X509Certificate>
MIIDAzCCAsECBEbrjK0wCwYHKoZIzjgEAwUAMGcxCzAJBgNVBAYTAlJPMRIwEAYDVQQIEwlCdWNo
YXJlc3QxEjAQBgNVBAcTCUJ1Y2hhcmVzdDENMAsGA1UEChMEbm9uZTENMAsGA1UECxMEbm9uZTES
MBAGA1UEAxMJbG9jYWxob3N0MB4XDTA3MDkxNTA3NDEzM1oXDTA3MTIxNDA3NDEzM1owZzELMAkG
A1UEBhMCUk8xEjAQBgNVBAgTCUJ1Y2hhcmVzdDESMBAGA1UEBxMJQnVjaGFyZXN0MQ0wCwYDVQQK
EwRub25lMQ0wCwYDVQQLEwRub25lMRIwEAYDVQQDEwlsb2NhbGhvc3QwggG4MIIBLAYHKoZIzjgE
ATCCAR8CgYEA/X9TgR11EilS30qcLuzk5/YRt1I870QAwx4/gLZRJmlFXUAiUftZPY1Y+r/F9bow
9subVWzXgTuAHTRv8mZgt2uZUKWkn5/oBHsQIsJPu6nX/rfGG/g7V+fGqKYVDwT7g/bTxR7DAjVU
E1oWkTL2dfOuK2HXKu/yIgMZndFIAccCFQCXYFCPFSMLzLKSuYKi64QL8Fgc9QKBgQD34aCF1ps9
3su8q1w2uFe5eZSvu/o66oL5V0wLPQeCZ1FZV4661FlP5nEHEIGAtEkWcSPoTCgWE7fPCTKMyKbh
PBZ6i1R8jSjgo64eK7OmdZFuo38L+iE1YvH7YnoBJDvMpPG+qFGQiaiD3+Fa5Z8GkotmXoB7VSVk
AUw7/s9JKgOBhQACgYEAj2njSzMkk4YoB33OoLz0Bk04QBQF+qdxUyZ/qtgZCuhcMsl0SxtYJ5oY
NtWT+LcFtrNwsgvauSj+lf8MJ4DUsWLBCepWKYovxCOvQyWgH8/bge/O3NSiIsGxamVuaa+PAJ48
kjzbDeg4TdRSnBqqkYkzVVRzH/b+uLBn6RWMzrUwCwYHKoZIzjgEAwUAAy8AMCwCFCvKAwmcwzG5
ja7ERrAtts7a+crGAhQ+kh+qTk8MhnCKPPhPqQfWAbRMAg==
</X509Certificate></X509Data></KeyInfo>
</Signature></math>

Generate a Detached XML Signature

A detached XML signature is a signature that signs external data to the <Signature> element. For example, external data is data outside the document (like in an HTTP page) or data that's in the same document (a sibling element of the <Signature>).

Generally, you can follow the same steps from Page 2 to generate a detached XML signature. The main thing is that the URI passed to the Reference object must indicate data external to the <Signature> element. For example, in the application in Listing 4, the data is represented by a web page that can be accessed with the link http://www.w3.org/TR/xml-stylesheet.

The output looks like this:

<?xml version="1.0" encoding="UTF-8" standalone=
"no"?><Signature xmlns="http://www.w3.org/2000/09/xmldsig#"><SignedInfo>
<CanonicalizationMethod Algorithm=
"http://www.w3.org/TR/2001/REC-xml-c14n-20010315"/>
<SignatureMethod Algorithm=
"http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
<Reference URI="http://www.w3.org/TR/xml-stylesheet">
<DigestMethodAlgorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<DigestValue>60NvZvtdTB+7UnlLp/H24p7h4bs=</DigestValue>
</Reference></SignedInfo><SignatureValue>
HZVMG4lz28cmffaTJBDOqCr5fpG7EAG8QPvvMYsmcVrVrbheCppLA66yXFnikno5Ltbo+PmyKzLN
C7TuOJyQuQ==
</SignatureValue><KeyInfo><KeyValue>
<RSAKeyValue><Modulus>
lsWqIY2EDNKqnFmxB0ODCC5mlL3bXZSiDo91oMZrAzKcrk0fhARIpj58oFMqpu3epVquT9KQ3kSG
EtP+MVQKEw==
</Modulus><Exponent>AQAB</Exponent>
</RSAKeyValue></KeyValue></KeyInfo></Signature>

Home / Articles / Tighten Data Security with the Java XML Digital Signature API / 1 / 2 / 3 / Next Page

How to Add Java Applets to Your Site

New on the Java Boutique:

New Review:

Time Management Made Easy with the Quartz Enterprise Job Scheduler
Why not just use the Java timer API? This open source scheduling API boasts simplicity, ease-of-integration, a well-rounded feature set, and it's free!

New Applet:

Reverse Complement
Reverse Complement is a simple applet that converts DNA or RNA sequences into three useful formats.

Elsewhere on internet.com:

WebDeveloper Java
Lots of Java information on webdeveloper.com

WDVL Java
Thorough Java resource at the Web Developer's Virtual Library.

ScriptSearch Java
Hundreds of free Java code files to download.

jGuru: Your View of the Java Universe
Customizable portal with online training, FAQs, regular news updates, and tutorials.

 DevX Skillbuilding from IBM developerWorks
 RIA Run Contest: Build Next-Gen Apps in Microsoft Silverlight 2
 Avaya DevConnect Center
 Intel Go Parallel Portal
 Internet.com eBook Library
 Microsoft RIA Development Center
 Destination .NET
XML error: not well-formed (invalid token) at line 53
advertisement
Receive Articles via our XML/RSS feed
Receive Articles via our XML/RSS feed

JavaBytes
Internet Cyclone
This powerful, easy-to-use, internet optimizer is for Windows 95, 98, ME, NT, 2000 and XP. It's designed to automatically optimize your Windows settings, boosting your Internet connection up to 200%.

RIM Ups Ante With Mobile Software Push
Novell Readies Silverlight Clone for Linux
Yahoo Pitches The 'Next Generation of Search'
Alfresco's Latest ECM: Prying Open a Sector?
SaaS Tool Offers Custom Database Development
Microsoft’s Automated Agent: Can We Talk?
Borland Finally Sells CodeGear
Red Hat Heads for the JON 2.0
Out with the Old, in with the New at JavaOne
Trolltech Expands WebKit Footprint

Create Secure Java Applications Productively, Part 1: Use Rational Application Developer and Data Studio
.NET Building Blocks: Custom User Control Fundamentals
Secure Internet File-Sharing with PHP, MySQL, and JavaScript
Getting Started with TBB on Windows
Moving to VoIP: Should You Go It Alone?
Introduction to the WPF Command Framework
7.0, Microsoft's Lucky Version?
Will Hyper-V Make VMware This Decade's Netscape?
Eliminate Fragmentation Frustration with Netbiscuits
Taming Trees: Building Branching Structures

Advertising Info  |   Member Services  |   Contact Us  |   Help  |   Feedback  |   Site Map  |   Network Map  |   About



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES