Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,14 @@
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.codehaus.mojo</groupId>
<artifactId>exec-maven-plugin</artifactId>
<version>1.2.1</version>
<configuration>
<mainClass>com.opencsi.jscepcli.App</mainClass>
</configuration>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-compiler-plugin</artifactId>
Expand Down
32 changes: 0 additions & 32 deletions src/main/java/com/opencsi/jscepcli/App.java
Original file line number Diff line number Diff line change
Expand Up @@ -194,38 +194,6 @@ public void scepCLI() throws Exception {
}
System.out.println("Certificate issued for subject DN: " + clientCertificate.getSubjectDN().getName());

if(params.getText() || params.getCrlFile() != null)
{
X509CRL crl;

try {
crl = client.getRevocationList(clientCertificate,
kp.getPrivate(),
clientCertificate.getIssuerX500Principal(),
clientCertificate.getSerialNumber(),
params.getCaIdentifier());

saveToPEM(params.getCrlFile(), crl);

if(params.getText() && crl != null) {
printPEM("Certificate Revocation List", crl);
}

}
catch(OperationFailureException ofe)
{
System.err.println("Could not retrieve CRL.");
if(params.getVerbose()) {
ofe.printStackTrace();
}
}
}
else
{
if(params.getVerbose()) {
System.err.println("Skipping CRL output (neither a file nor --text was specified)");
}
}

} else {
System.err.println("Failure response: " + response.getFailInfo());
Expand Down
3 changes: 2 additions & 1 deletion src/main/java/com/opencsi/jscepcli/CertUtil.java
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@

import java.io.ByteArrayInputStream;
import java.math.BigInteger;
import java.time.temporal.ChronoUnit;
import java.security.KeyPair;
import java.security.cert.CertificateFactory;
import java.security.cert.X509Certificate;
Expand Down Expand Up @@ -40,7 +41,7 @@ public X509Certificate createSelfSignedCertificate(KeyPair kp, String dn) throws

X500Name principal = new X500Name(dn);
SubjectPublicKeyInfo spki = SubjectPublicKeyInfo.getInstance(kp.getPublic().getEncoded());
final X509v3CertificateBuilder certbuilder = new X509v3CertificateBuilder(principal, serial, now, now, principal, spki);
final X509v3CertificateBuilder certbuilder = new X509v3CertificateBuilder(principal, serial, now, Date.from(now.toInstant ().plus(1, ChronoUnit.DAYS)), principal, spki);
final ContentSigner signer = new JcaContentSignerBuilder("SHA256WithRSA").setProvider(new BouncyCastleProvider()).build(kp.getPrivate());
final X509CertificateHolder certHolder = certbuilder.build(signer);
return (X509Certificate) CertificateFactory.getInstance("X.509", new BouncyCastleProvider()).generateCertificate(new ByteArrayInputStream(certHolder.getEncoded()));
Expand Down