The Bouncy Castle Cryptographic
C#® API
Contents:
- The Bouncy
Castle Cryptographic C#® API
-
-
Contents:
-
License & Contributors:
-
Features:
-
How To Build.
-
The Source:
-
Documentation:
-
For first time users.
-
Notes:
-
Release 1.3
-
Release 1.2
-
Release 1.1
-
Release 1.0
-
Tuesday Febuary 1, 2005
-
Sunday December 12, 2004
-
Trademarks.
License & Contributors:
See License & Contributors
files.
Features:
-
Generation and parsing of PKCS-12 files.
-
X.509: Generators and parsers for V1 and V3 certificates, V2 CRLs and attribute
certificates.
-
PBE algorithms supported by PBEUtil: PBEwithMD2andDES-CBC,
PBEwithMD2andRC2-CBC, PBEwithMD5andDES-CBC, PBEwithMD5andRC2-CBC,
PBEwithSHA1andDES-CBC, PBEwithSHA1andRC2-CBC, PBEwithSHA-1and128bitRC4,
PBEwithSHA-1and40bitRC4, PBEwithSHA-1and3-keyDESEDE-CBC,
PBEwithSHA-1and2-keyDESEDE-CBC, PBEwithSHA-1and128bitRC2-CBC,
PBEwithSHA-1and40bitRC2-CBC, PBEwithHmacSHA-1, PBEwithHmacSHA-224,
PBEwithHmacSHA-256, PBEwithHmacRIPEMD128, PBEwithHmacRIPEMD160, and
PBEwithHmacRIPEMD256.
-
Signature algorithms supported by SignerUtilities: MD2withRSA, MD4withRSA,
MD5withRSA, RIPEMD128withRSA, RIPEMD160withECDSA, RIPEMD160withRSA,
RIPEMD256withRSA, SHA-1withRSA, SHA-224withRSA, SHA-256withRSAandMGF1,
SHA-384withRSAandMGF1, SHA-512withRSAandMGF1, SHA-1withDSA, and SHA-1withECDSA.
-
Symmetric key algorithms: AES, Blowfish, Camellia, CAST5, CAST6, DESede, DES,
GOST28147, HC-128, HC-256, IDEA, ISAAC, NaccacheStern, Noekeon, RC2, RC4,
RC5-32, RC5-64, RC6, Rijndael, Salsa20, SEED, Serpent, Skipjack, TEA/XTEA,
Twofish and VMPC.
-
Symmetric key modes: CBC, CFB, CTS, GOFB, OFB, OpenPGPCFB, and SIC (or CTR).
-
Symmetric key paddings: ISO10126d2, ISO7816d4, PKCS-5/7, TBC, X.923, and Zero
Byte.
-
Asymmetric key algorithms: RSA (with blinding), ElGamal, DSA, and ECDSA.
-
Asymmetric key paddings/encodings: ISO9796d1, OAEP, and PKCS-1.
-
AEAD block cipher modes: CCM an EAX.
-
Digests: GOST3411, MD2, MD4, MD5, RIPEMD128, RIPEMD160, RIPEMD256, RIPEMD320,
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, Tiger, and Whirlpool.
-
Signer mechanisms: DSA, ECDSA, ECGOST3410, GOST3410, ISO9796d2, PSS, RSA.
-
Key Agreement: Diffie-Hellman and EC-DH.
-
Macs: CBCBlockCipher, CFBBlockCipher, GOST28147, HMac, ISO9797 Alg. 3, and VMPCMAC.
-
PBE generators: PKCS-12, and PKCS-5 - schemes 1 and 2.
-
OpenPGP (RFC 2440)
-
Cryptographic Message Syntax (CMS, RFC 3852), including streaming API.
-
Online Certificate Status Protocol (OCSP, RFC 2560).
-
Time Stamp Protocol (TSP, RFC 3161).
-
Elliptic Curve Cryptography (support for F2m and Fp curves).
-
Reading/writing of PEM files, including RSA and DSA keys, with a variety of
encryptions.
Porting notes from the old ASN.1 library For the most part code using the
old subset of ASN.1 classes should be easy to transfer, providing the following
changes are made:
-
DERObject becomes Asn1Object
-
DEREncodable becomes Asn1Encodable
-
GetDERObject() becomes ToAsn1Object()
-
BERConstructedOctetString becomes BerOctetString
-
If you were using the older mutable DERConstructedSequence/Set and
BERConstructedSequence, use an Asn1EncodableVector in conjunction with
DerSequence/Set and BerSequence
-
BERInputStream and DERInputStream are replaced with Asn1InputStream
-
AsymmetricKeyParameter is now in the Org.Bouncycastle.Crypto namespace
How To Build.
The BC C# API uses NAnt (http://nant.sourceforge.net)
to provide a platform independent build environment. There is also a solution
file for Visual Studio, and one for MonoDevelop. The API requires .NET
Framework 1.1, and should work fine with .NET 2.0 also. It has been
successfully built and tested with Mono versions from 1.1.13 onwards. The
source code can be built for .NET Compact Framework 1.0 by setting the
compilation flag NETCF_1_0.
Using a command prompt (DOS window), cd into the 'crypto' folder of this
distribution.
Use,
-
'nant' without arguments to compile
debug code, the tests and run the tests.
-
'nant compile-release' to compile
release code.
-
'nant compile-debug' to compile
debug code.
-
'nant test' to run the included unit
tests (using NUnit; you may need to edit the build file to set the location
where NUnit is installed).
Output:
The compiled API can be found in the 'api/bin/release' &
'api/bin/debug' directories.
The compiled tests can be found in the 'test/bin' directory
(by default a debug build is used for testing).
The Source:
Source code can be found in the 'src'directory.
Documentation:
There is limited documentation available at the moment. Some of the source
contains XML comments, but this is a work in progress. We will be working to
improve this now that 1.0 is out the door.
For first time users.
Java® heritage,
The Bouncy Castle C# API is a port of the Bouncy Castle Java APIs.
Approximately %80 of the functionality in the Java build has now been ported.
For the most part, the naming conventions of the .NET platform have been
adopted. The C# API is constantly kept uptodate with bug fixes and new test
cases from the Java build (and vice versa sometimes), thus benefitting from the
large user base and real-world use the Java version has seen.
Please consider.
The Bouncy Castle C# API is a library of transformations that when combined
properly will enable developers to create standard conforming cryptographic
systems. In order to use this API you must have some knowledge of how to build
cryptographic systems, namely what transformations to use and the when, where
and why of their use.
Developing good cryptographic systems takes practice and understanding.
There are many resources available online and in book shops; please use those
to your advantage.
Notes:
Release 1.3, Saturday December 8, 2007
ASN.1 stream parsing now handles definite length encodings efficiently.
Buffering in the streaming CMS has been reworked. Throughput is now usually higher and the behaviour is more predictable.
BcpgInputStream now handles data blocks in the 2**31->2**32-1 range.
Some confusion over the parameters J and L in connection with Diffie-Hellman has been resolved.
Added CryptoApiRandomGenerator, a wrapper for RNGCryptoServiceProvider.
Added VMPC stream cipher, VMPCMAC and a VMPC-based implementation of IRandomGenerator.
Added support in OpenPGP for fetching keyrings by case-insensitive user ID [#BMA-8].
Fixed a vulnerability of CMS signatures that do not use signed attributes (Bleichenbacher RSA forgery).
Fixed a bug causing second and later encrypted objects to be ignored in KeyBasedFileProcessor example.
Fixed case-sensitivity issue with deletion from a PKCS#12 file.
Fixed problem overwriting entities in a PKCS#12 file.
Fixed PgpUtilities.MakeKeyFromPassPhrase for 8-bit characters [#BMA-13].
Fixed duplicate certificate problem in Pkcs12Store.Save [#BMA-12].
Fixed NAnt build under Mono [#BMA-10].
Fixed BigInteger.ModPow for negative exponents [#BMA-7].
Release 1.2, Thursday July 5, 2007
Source now builds on .NET Compact Framework 1.0 (compilation flag NETCF_1_0).
Release assembly now signed with a strong name.
Added CCM and EAX block cipher modes.
Added Noekeon block cipher.
Added HC-128, HC-256, and ISAAC stream ciphers.
Added RIPEMD160withECDSA signature algorithm.
Added support for notation data signature subpackets to OpenPGP.
Added support for parsing of experimental signatures to OpenPGP.
Added the complete set of SEC-2 EC curves.
Added support for implicit tagging to DerApplicationSpecific.
Added remaining ASN.1 structures from RFC 3126 to Asn1.Esf namespace.
Performance of ECDSA improved.
Performance of ASN.1 stream parsing improved.
Fixed default private key length for Diffie-Hellman parameters.
Fixed DerT61String to correctly support 8-bit characters.
Fixed duplicate attribute problem in Pkcs12Store.Save.
Fixed a problem writing public keys in OpenPGP [#BMA-5].
Release 1.1, Friday May 4, 2007
Added support for writing DSA private keys, and more encodings, in OpenSsl
(PemReader/PemWriter).
Removed SharpZipLib dependency.
Added RSA blinded signature classes.
Added Asn1.IsisMtt namespace (ISIS-MTT ASN.1 classes).
Added SEED block cipher engine.
Added Salsa20 stream cipher engine.
Performance optimisations for F2m elliptic curves.
Fixed OpenPGP bug decrypting files with multiple types of encryption on the
session key.
Release 1.0, Thursday January 18,
2007
Implementations of CMS, OCSP, OpenPGP, and TSP.
Elliptic Curves (F2m and Fp).
A basic TLS client.
PEM file reading and writing.
Symmetric key algorithms: Camellia, GOST28147, NaccacheStern, and TEA/XTEA.
Symmetric key modes: GOFB and OpenPGPCFB.
Symmetric key paddings: ISO7816d4.
Asymmetric key algorithms: RSA blinding.
Digests: GOST3411 and Whirlpool.
Macs: GOST28147 and ISO9797 Alg 3.
Signer mechanisms: ECDSA, ECGOST3410, and GOST3410.
...and many more features, bug fixes, and performance improvements.
Tuesday Febuary 1, 2005
This is the second beta release of the Bouncy Castle API C# implementation.
Reliability improvement to ASN1InputStream.
The OID entries in SignerUtilities for RSA signature algorithms for SHA-256,
SHA-384, and SHA-512 were pointing creating the wrong signature objects.
Sunday December 12, 2004
This is the first beta release of the Bouncy Castle Cryptographic API C#
implementation.
The Legion of the Bouncy Castle would like to extend their thanks to all those
who contributed to this API during the alpha stages of its development.
Keep up the good work folks.
Please send any questions or bug reports to
dev-crypto-csharp@bouncycastle.org
Trademarks.
C#, .NET, and MSDN are Registered Trademarks of Microsoft.
Microsoft.com
Java is a Registered Trademark of Sun Microsystems. Sun
Microsystems
© 2007 Legion of the Bouncy Castle