Merge "Document that RSA OAEP requires digest authorization." into mnc-dev
This commit is contained in:
@@ -634,11 +634,12 @@ public final class KeyGenParameterSpec implements AlgorithmParameterSpec {
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Sets the set of digests algorithms (e.g., {@code SHA-256}, {@code SHA-384}) with which
|
* Sets the set of digests algorithms (e.g., {@code SHA-256}, {@code SHA-384}) with which
|
||||||
* the key can be used when signing/verifying. Attempts to use the key with any other digest
|
* the key can be used. Attempts to use the key with any other digest algorithm will be
|
||||||
* algorithm will be rejected.
|
* rejected.
|
||||||
*
|
*
|
||||||
* <p>This must be specified for keys which are used for signing/verification. For HMAC
|
* <p>This must be specified for signing/verification keys and RSA encryption/decryption
|
||||||
* keys, the set of digests defaults to the digest associated with the key algorithm (e.g.,
|
* keys used with RSA OAEP padding scheme because these operations involve a digest. For
|
||||||
|
* HMAC keys, the default is the digest associated with the key algorithm (e.g.,
|
||||||
* {@code SHA-256} for key algorithm {@code HmacSHA256}).
|
* {@code SHA-256} for key algorithm {@code HmacSHA256}).
|
||||||
*
|
*
|
||||||
* <p>For private keys used for TLS/SSL client or server authentication it is usually
|
* <p>For private keys used for TLS/SSL client or server authentication it is usually
|
||||||
|
|||||||
@@ -417,12 +417,13 @@ public final class KeyProtection implements ProtectionParameter {
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Sets the set of digest algorithms (e.g., {@code SHA-256}, {@code SHA-384}) with which the
|
* Sets the set of digest algorithms (e.g., {@code SHA-256}, {@code SHA-384}) with which the
|
||||||
* key can be used when signing/verifying or generating MACs. Attempts to use the key with
|
* key can be used. Attempts to use the key with any other digest algorithm will be
|
||||||
* any other digest algorithm will be rejected.
|
* rejected.
|
||||||
*
|
*
|
||||||
* <p>For HMAC keys, the default is the digest algorithm specified in
|
* <p>This must be specified for signing/verification keys and RSA encryption/decryption
|
||||||
* {@link Key#getAlgorithm()}. For asymmetric signing keys the set of digest algorithms
|
* keys used with RSA OAEP padding scheme because these operations involve a digest. For
|
||||||
* must be specified.
|
* HMAC keys, the default is the digest specified in {@link Key#getAlgorithm()} (e.g.,
|
||||||
|
* {@code SHA-256} for key algorithm {@code HmacSHA256}).
|
||||||
*
|
*
|
||||||
* <p>For private keys used for TLS/SSL client or server authentication it is usually
|
* <p>For private keys used for TLS/SSL client or server authentication it is usually
|
||||||
* necessary to authorize the use of no digest ({@link KeyProperties#DIGEST_NONE}). This is
|
* necessary to authorize the use of no digest ({@link KeyProperties#DIGEST_NONE}). This is
|
||||||
|
|||||||
Reference in New Issue
Block a user