pki

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 20 Imported by: 0

Documentation

Overview

Package pki is the private certificate authority of the central: server and edge certificates, and the fingerprint edges pin.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func CSR

func CSR(key crypto.Signer) ([]byte, error)

CSR builds a certificate request for an existing key.

func CertPEM

func CertPEM(der []byte) []byte

func EdgeID

func EdgeID(cert *x509.Certificate) (uuid.UUID, error)

EdgeID reads the edge identity from a certificate.

func Fingerprint

func Fingerprint(cert *x509.Certificate) string

Fingerprint returns "sha256:<hex>" of the certificate public key.

func KeyPEM

func KeyPEM(key crypto.Signer) ([]byte, error)

func NewEdgeKey

func NewEdgeKey() (crypto.Signer, []byte, error)

NewEdgeKey generates an edge key and its CSR.

func ParseCertPEM

func ParseCertPEM(b []byte) (*x509.Certificate, error)

func ParseKeyPEM

func ParseKeyPEM(b []byte) (crypto.Signer, error)

Types

type CA

type CA struct {
	Cert *x509.Certificate
	Key  crypto.Signer
}

CA is the private authority that signs the central and every edge.

func LoadOrCreateCA

func LoadOrCreateCA(dir string) (*CA, error)

LoadOrCreateCA reads ca.crt and ca.key from dir, or creates them.

func (*CA) Fingerprint

func (ca *CA) Fingerprint() string

Fingerprint is the value edges pin at enrollment.

func (*CA) IssueServer

func (ca *CA) IssueServer(hosts []string, validity time.Duration) (*x509.Certificate, crypto.Signer, error)

IssueServer signs a server certificate for hosts. The key stays in memory.

func (*CA) SignEdge

func (ca *CA) SignEdge(csrDER []byte, id uuid.UUID, name string, validity time.Duration) (*x509.Certificate, error)

SignEdge signs an edge certificate. Only the public key comes from the CSR.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL