要生成不同目标的签名证书,您可以使用以下方式:
keytool -genkeypair -alias myAlias -keyalg RSA -keysize 2048 -validity 365 -keystore myKeystore.jks
这将生成一个包含私钥和公钥的密钥对,并将其存储在名为“myKeystore.jks”的密钥库文件中。
import org.bouncycastle.asn1.x500.X500Name;
import org.bouncycastle.cert.X509v3CertificateBuilder;
import org.bouncycastle.cert.jcajce.JcaContentSignerBuilder;
import org.bouncycastle.operator.ContentSigner;
import org.bouncycastle.operator.jcajce.JcaContentVerifierProviderBuilder;
import java.math.BigInteger;
import java.security.*;
import java.security.cert.X509Certificate;
import java.util.Date;
public class CertificateGenerator {
public static X509Certificate generateCertificate() throws Exception {
// Generate key pair
KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance("RSA");
keyPairGenerator.initialize(2048);
KeyPair keyPair = keyPairGenerator.generateKeyPair();
// Generate self-signed certificate
ContentSigner contentSigner = new JcaContentSignerBuilder("SHA256WithRSA").build(keyPair.getPrivate());
X509v3CertificateBuilder certificateBuilder = new X509v3CertificateBuilder(
new X500Name("CN=My Certificate"),
BigInteger.valueOf(new SecureRandom().nextInt()),
new Date(),
new Date(System.currentTimeMillis() + 365 * 24 * 60 * 60 * 1000),
new X500Name("CN=My Certificate"),
keyPair.getPublic()
);
X509Certificate certificate = certificateBuilder.build(contentSigner);
// Verify the generated certificate
certificate.verify(keyPair.getPublic());
return certificate;
}
public static void main(String[] args) throws Exception {
X509Certificate certificate = generateCertificate();
System.out.println(certificate);
}
}
这个示例使用Bouncy Castle库生成一个自签名的证书,其中包含了一个密钥对和相关的证书信息。您可以根据自己的需求修改证书的信息。