Class JarSigner

java.lang.Object
jdk.security.jarsigner.JarSigner

public final class JarSigner extends Object
An immutable utility class to sign a jar file.

A caller creates a JarSigner.Builder object, (optionally) sets some parameters, and calls build to create a JarSigner object. This JarSigner object can then be used to sign a jar file.

Unless otherwise stated, calling a method of JarSigner or JarSigner.Builder with a null argument will throw a NullPointerException.

Example:

    JarSigner signer = new JarSigner.Builder(key, certPath)
            .digestAlgorithm("SHA-256")
            .signatureAlgorithm("SHA256withRSA")
            .build();
    try (ZipFile  in = new ZipFile(inputFile);
            FileOutputStream out = new FileOutputStream(outputFile)) {
        signer.sign(in, out);
    }
Since:
9
  • Nested Class Summary

    Nested Classes
    Modifier and Type
    Class
    Description
    static class 
    A mutable builder class that can create an immutable JarSigner from various signing-related parameters.
  • Method Summary

    Modifier and Type
    Method
    Description
    Returns the digest algorithm for this JarSigner.
    Returns the value of an additional implementation-specific property indicated by the specified key.
    Returns the signature algorithm for this JarSigner.
    Returns the signer name of this JarSigner.
    Returns the URI of the Time Stamping Authority (TSA).
    void
    Signs a file into an OutputStream.

    Methods declared in class Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
    Modifier and Type
    Method
    Description
    protected Object
    Answers a new instance of the same class as the receiver, whose slots have been filled in with the values in the slots of the receiver.
    boolean
    Compares the argument to the receiver, and answers true if they represent the same object using a class specific comparison.
    protected void
    Deprecated, for removal: This API element is subject to removal in a future version.
    May cause performance issues, deadlocks and hangs.
    final Class<? extends Object>
    Answers the unique instance of java.lang.Class which represents the class of the receiver.
    int
    Answers an integer hash code for the receiver.
    final void
    Causes one thread which is waiting on the receiver to be made ready to run.
    final void
    Causes all threads which are waiting on the receiver to be made ready to run.
    Answers a string containing a concise, human-readable description of the receiver.
    final void
    Causes the thread which sent this message to be made not ready to run pending some change in the receiver (as indicated by notify or notifyAll).
    final void
    wait(long time)
    Causes the thread which sent this message to be made not ready to run either pending some change in the receiver (as indicated by notify or notifyAll) or the expiration of the timeout.
    final void
    wait(long time, int frac)
    Causes the thread which sent this message to be made not ready to run either pending some change in the receiver (as indicated by notify or notifyAll) or the expiration of the timeout.
  • Method Details

    • sign

      public void sign(ZipFile file, OutputStream os)
      Signs a file into an OutputStream. This method will not close file or os.

      If an I/O error or signing error occurs during the signing, then it may do so after some bytes have been written. Consequently, the output stream may be in an inconsistent state. It is strongly recommended that it be promptly closed in this case.

      Parameters:
      file - the file to sign.
      os - the output stream.
      Throws:
      JarSignerException - if the signing fails.
    • getDigestAlgorithm

      public String getDigestAlgorithm()
      Returns the digest algorithm for this JarSigner.

      The return value is never null.

      Returns:
      the digest algorithm.
    • getSignatureAlgorithm

      public String getSignatureAlgorithm()
      Returns the signature algorithm for this JarSigner.

      The return value is never null.

      Returns:
      the signature algorithm.
    • getTsa

      public URI getTsa()
      Returns the URI of the Time Stamping Authority (TSA).
      Returns:
      the URI of the TSA.
    • getSignerName

      public String getSignerName()
      Returns the signer name of this JarSigner.

      The return value is never null.

      Returns:
      the signer name.
    • getProperty

      public String getProperty(String key)
      Returns the value of an additional implementation-specific property indicated by the specified key. If a property is not set but has a default value, the default value will be returned.
      Implementation Note:
      See JarSigner.Builder.setProperty(String, String) for a list of properties this implementation supports. All property names are case-insensitive.
      Parameters:
      key - the name of the property.
      Returns:
      the value for the property.
      Throws:
      UnsupportedOperationException - if the key is not supported by this implementation.