key-transparency

module
v0.0.0-...-1e3cd99 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 25, 2017 License: Apache-2.0

README

Key Transparency

Build Status Go Report Card GoDoc

Key Transparency Logo

Key Transparency provides a lookup service for generic records and a public, tamper-proof audit log of all record changes. While being publicly auditable, individual records are only revealed in response to queries for specific IDs.

Key Transparency can be used as a public key discovery service to authenticate users and provides a mechanism to keep the service accountable. It can be used by account owners to reliably see what keys have been associated with their account, and it can be used by senders to see how long an account has been active and stable before trusting it.

Key Transparency is inspired by CONIKS and Certificate Transparency. It is a work-in-progress with the following milestones under development.

Key Transparency Client

Setup
  1. Install Go 1.7.
  2. go get -u github.com/google/keytransparency/cmd/keytransparency-client
  3. Get an OAuth client ID and download the generated JSON file to client_secret.json.
Client operations
Publish a public key
keytransparency-client authorized-keys --help 
keytransparency-client authorized-keys add --generate --type=ecdsa --activate
keytransparency-client post user@domain.com app1 --client-secret=client_secret.json --insecure -d 'dGVzdA==' #Base64
Get and verify a public key
keytransparency-client get <email> <app> --insecure --verbose
✓ Commitment verified.
✓ VRF verified.
✓ Sparse tree proof verified.
✓ Signed Map Head signature verified.
CT ✓ STH signature verified.
CT ✓ Consistency proof verified.
CT   New trusted STH: 2016-09-12 15:31:19.547 -0700 PDT
CT ✓ SCT signature verified. Saving SCT for future inclusion proof verification.
✓ Signed Map Head CT inclusion proof verified.
keys:<key:"app1" value:"test" >
Verify key history
keytransparency-client history <email> --insecure
Epoch |Timestamp                    |Profile
4     |Mon Sep 12 22:23:54 UTC 2016 |keys:<key:"app1" value:"test" >

Running the server

Install
  1. OpenSSL
  2. Docker
    • Docker Engine 1.13.0+ docker version -f '{{.Server.APIVersion}}'
    • Docker Compose 1.11.0+ docker-compose --version
  3. go get -u github.com/google/keytransparency/...
  4. go get -u github.com/google/trillian/...
  5. ./scripts/prepare_server.sh -f
Run
  1. Start Trillian
$ docker-compose up -d trillian-map trillian-log
Creating keytransparency_db_1
Creating  keytransparency_trillian-map_1
Creating  keytransparency_trillian-log_1
  1. Provision a log and a map
source scripts/configure_trillian.sh && createLog && createMap
  1. Run Key Transparency

Directories

Path Synopsis
cmd
core
authentication
Package authentication implements authentication mechanisms.
Package authentication implements authentication mechanisms.
authorization
Package authorization defines the authorization interface of Key Transparency.
Package authorization defines the authorization interface of Key Transparency.
client/gobindclient
Package gobindclient contains a gobind friendly implementation of a KeyTransparency Client able to make GetEntry requests to a KT server and verify the soundness of the responses.
Package gobindclient contains a gobind friendly implementation of a KeyTransparency Client able to make GetEntry requests to a KT server and verify the soundness of the responses.
crypto/commitments
Package commitments implements a cryptographic commitment.
Package commitments implements a cryptographic commitment.
crypto/dev
Package dev provides pseudo dev/* readers and writers.
Package dev provides pseudo dev/* readers and writers.
crypto/vrf
Package vrf defines the interface to a verifiable random function.
Package vrf defines the interface to a verifiable random function.
crypto/vrf/p256
Package p256 implements a verifiable random function using curve p256.
Package p256 implements a verifiable random function using curve p256.
keyserver
Package keyserver implements a transparent key server for End to End.
Package keyserver implements a transparent key server for End to End.
monitor
Package monitor implements the monitor service.
Package monitor implements the monitor service.
mutation
Package mutation implements the monitor service.
Package mutation implements the monitor service.
mutator
Package mutator defines the operations to transform mutations into changes in the map as well as operations to write and read mutations to and from the database.
Package mutator defines the operations to transform mutations into changes in the map as well as operations to write and read mutations to and from the database.
mutator/entry
Package entry implements a simple replacement strategy as a mapper.
Package entry implements a simple replacement strategy as a mapper.
proto/authorization
Package authorization is a generated protocol buffer package.
Package authorization is a generated protocol buffer package.
proto/keymaster
Package keymaster is a generated protocol buffer package.
Package keymaster is a generated protocol buffer package.
proto/keytransparency_v1_types
Package keytransparency_v1_types is a generated protocol buffer package.
Package keytransparency_v1_types is a generated protocol buffer package.
proto/monitor_v1_types
Package monitor_v1_types is a generated protocol buffer package.
Package monitor_v1_types is a generated protocol buffer package.
impl
authorization
Package authorization contains the authorization module implementation.
Package authorization contains the authorization module implementation.
config
Package config has utilities for loading configuration files from disk.
Package config has utilities for loading configuration files from disk.
monitor
Package monitor contains an implementation of a Monitor server which can be queried for monitoring results.
Package monitor contains an implementation of a Monitor server which can be queried for monitoring results.
mutation
Package mutation implements the mutations service a monitor can query.
Package mutation implements the mutations service a monitor can query.
proto/keytransparency_v1_service
Package keytransparency_v1_service is a generated protocol buffer package.
Package keytransparency_v1_service is a generated protocol buffer package.
proto/monitor_v1_service
Package monitor_v1_service is a generated protocol buffer package.
Package monitor_v1_service is a generated protocol buffer package.
proto/mutation_v1_service
Package mutation_v1_service is a generated protocol buffer package.
Package mutation_v1_service is a generated protocol buffer package.
proto/sequencer_v1_service
Package sequencer_v1_service is a generated protocol buffer package.
Package sequencer_v1_service is a generated protocol buffer package.
sql/mutations
Package mutations defines operations to write and read mutations to and from the database.
Package mutations defines operations to write and read mutations to and from the database.
sql/testutil
Package testutil contains test supporting functionality for 'impl/sql/...'.
Package testutil contains test supporting functionality for 'impl/sql/...'.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL