jose.pem handles certificate chains as well as individual PEM keys. A PEM
chain can be parsed into X509Certificate values or converted directly to the
Base64 strings used by a JWK :x5c member:
(def certificates (pem/pem->certificates pem-text))
(def x5c (pem/pem->x5c pem-text))
(def pem-again (pem/certificates->pem certificates))
The file arity of pem->certificates accepts a java.io.File. Chain order is
preserved. pem/x5c->certificates is the inverse of pem->x5c.
JWK certificate metadata can be inspected in either form. jwk/x509-cert-chain
returns the raw Base64 values, while jwk/x509-certificates returns parsed
X509Certificate objects.
For JCA interoperability, jwk/to-java-keys converts one JWK or a collection
of JWK inputs to a vector of Java keys. The library works on JDK 11 and newer,
but converting OKP JWKs to Java security keys requires JDK 15 or newer because
Ed25519 and X25519 were added to the JDK in JDK 15. jwk/to-java-private-key
explicitly selects the private key from a private JWK. Inputs follow
jwk/parse: maps, JSON strings, and Nimbus JWK values are accepted.
To load every key entry in a key store, use jwk/keystore->jwks with either a
map of alias to password or a password lookup function:
(jwk/keystore->jwks keystore {"signing" "signing-pin"
"encryption" "encryption-pin"})
The existing jwk/keystore->jwk remains available for loading one alias with
one PIN.
Can you improve this documentation?Edit on GitHub
cljdoc builds & hosts documentation for Clojure/Script libraries
| Ctrl+k | Jump to recent docs |
| ← | Move to previous article |
| → | Move to next article |
| Ctrl+/ | Jump to the search field |