id = new CertificateID(CertificateID.HASH_SHA1, testCert, BigInteger.valueOf(1), null);
//
// basic request generation
//
OCSPReqGenerator gen = new OCSPReqGenerator();
gen.addRequest(
new CertificateID(CertificateID.HASH_SHA1, testCert, BigInteger.valueOf(1)));
OCSPReq req = gen.generate();
if (req.isSigned())
{
fail("signed but shouldn't be");
}
X509Certificate[] certs = req.getCerts("BC");
if (certs != null)
{
fail("null certs expected, but not found");
}
Req[] requests = req.getRequestList();
if (!requests[0].getCertID().equals(id))
{
fail("Failed isFor test");
}
//
// request generation with signing
//
X509Certificate[] chain = new X509Certificate[1];
gen = new OCSPReqGenerator();
gen.setRequestorName(new GeneralName(GeneralName.directoryName, new X509Principal("CN=fred")));
gen.addRequest(
new CertificateID(CertificateID.HASH_SHA1, testCert, BigInteger.valueOf(1)));
chain[0] = testCert;
req = gen.generate("SHA1withRSA", signKP.getPrivate(), chain, "BC");
if (!req.isSigned())
{
fail("not signed but should be");
}
if (!req.verify(signKP.getPublic(), "BC"))
{
fail("signature failed to verify");
}
requests = req.getRequestList();
if (!requests[0].getCertID().equals(id))
{
fail("Failed isFor test");
}
certs = req.getCerts("BC");
if (certs == null)
{
fail("null certs found");
}
if (certs.length != 1 || !certs[0].equals(testCert))
{
fail("incorrect certs found in request");
}
//
// encoding test
//
byte[] reqEnc = req.getEncoded();
OCSPReq newReq = new OCSPReq(reqEnc);
if (!newReq.verify(signKP.getPublic(), "BC"))
{
fail("newReq signature failed to verify");
}
//
// request generation with signing and nonce
//
chain = new X509Certificate[1];
gen = new OCSPReqGenerator();
Vector oids = new Vector();
Vector values = new Vector();
byte[] sampleNonce = new byte[16];
Random rand = new Random();
rand.nextBytes(sampleNonce);
gen.setRequestorName(new GeneralName(GeneralName.directoryName, new X509Principal("CN=fred")));
oids.addElement(OCSPObjectIdentifiers.id_pkix_ocsp_nonce);
values.addElement(new X509Extension(false, new DEROctetString(new DEROctetString(sampleNonce))));
gen.setRequestExtensions(new X509Extensions(oids, values));
gen.addRequest(
new CertificateID(CertificateID.HASH_SHA1, testCert, BigInteger.valueOf(1)));
chain[0] = testCert;
req = gen.generate("SHA1withRSA", signKP.getPrivate(), chain, "BC");
if (!req.isSigned())
{
fail("not signed but should be");
}