crypto

package
v5.4.39 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 21, 2026 License: GPL-3.0 Imports: 30 Imported by: 0

Documentation

Overview

Package crypto is a generated GoMock package.

Index

Constants

View Source
const (
	// ModuleName contains the name of this module
	ModuleName = "Crypto"
)

Variables

View Source
var ErrPrivateKeyNotFound = errors.New("private key not found")

ErrPrivateKeyNotFound is returned when the private key doesn't exist

View Source
var ErrUnsupportedSigningKey = errors.New("signing key algorithm not supported")

ErrUnsupportedSigningKey is returned when an unsupported private key is used to sign. Currently only ecdsa and rsa keys are supported

Functions

func EciesDecrypt

func EciesDecrypt(privateKey *ecdsa.PrivateKey, cipherText []byte) ([]byte, error)

EciesDecrypt decrypts the `cipherText` using the Elliptic Curve Integrated Encryption Scheme

func EciesEncrypt

func EciesEncrypt(publicKey *ecdsa.PublicKey, plainText []byte) ([]byte, error)

EciesEncrypt encrypts the `plainText` using the Elliptic Curve Integrated Encryption Scheme

func EncryptJWE

func EncryptJWE(payload []byte, protectedHeaders map[string]interface{}, publicKey interface{}) (message string, err error)

func JWTKidAlg

func JWTKidAlg(tokenString string) (string, jwa.SignatureAlgorithm, error)

JWTKidAlg parses a JWT, does not validate it and returns the 'kid' and 'alg' headers

func NewMemoryStorage

func NewMemoryStorage() spi.Storage

func ParseJWS

func ParseJWS(token []byte, f PublicKeyFunc) (payload []byte, err error)

ParseJWS parses a JWS byte array object, validates and verifies it. This method returns the value of the payload as byte array, or an error if the parsing fails at any level.

func ParseJWT

func ParseJWT(tokenString string, f PublicKeyFunc, options ...jwt.ParseOption) (jwt.Token, error)

ParseJWT parses a token, validates and verifies it.

func SignatureAlgorithm

func SignatureAlgorithm(key crypto.PublicKey) (jwa.SignatureAlgorithm, error)

SignatureAlgorithm determines the jwa.SigningAlgorithm for ec/rsa/ed25519 keys.

func Thumbprint

func Thumbprint(key jwk.Key) (string, error)

Thumbprint generates a Nuts compatible thumbprint: Base58(SHA256(rfc7638-json))

Types

type Config

type Config struct {
	Storage  string          `koanf:"storage"`
	Vault    vault.Config    `koanf:"vault"`
	External external.Config `koanf:"external"`
}

Config holds the values for the crypto engine

func DefaultCryptoConfig

func DefaultCryptoConfig() Config

DefaultCryptoConfig returns a Config with a fs backend storage

type Crypto

type Crypto struct {
	// contains filtered or unexported fields
}

Crypto holds references to storage and needed config

func NewCryptoInstance

func NewCryptoInstance() *Crypto

NewCryptoInstance creates a new instance of the crypto engine.

func NewMemoryCryptoInstance

func NewMemoryCryptoInstance() *Crypto

NewMemoryCryptoInstance returns a new Crypto instance to be used for tests, storing keys in-memory.

func NewTestCryptoInstance

func NewTestCryptoInstance(storage spi.Storage) *Crypto

NewTestCryptoInstance returns a new Crypto instance to be used for tests, allowing to use of preconfigured storage.

func (*Crypto) CheckHealth

func (client *Crypto) CheckHealth() map[string]core.Health

func (*Crypto) Config

func (client *Crypto) Config() interface{}

func (*Crypto) Configure

func (client *Crypto) Configure(config core.ServerConfig) error

Configure loads the given configurations in the engine. Any wrong combination will return an error

func (*Crypto) Decrypt

func (client *Crypto) Decrypt(ctx context.Context, kid string, cipherText []byte) ([]byte, error)

Decrypt decrypts the `cipherText` with key `kid`

func (*Crypto) DecryptJWE

func (client *Crypto) DecryptJWE(ctx context.Context, message string) (body []byte, headers map[string]interface{}, err error)

DecryptJWE decrypts a message using the associated private key from the kid header.

func (*Crypto) EncryptJWE

func (client *Crypto) EncryptJWE(ctx context.Context, payload []byte, headers map[string]interface{}, publicKey interface{}) (string, error)

EncryptJWE encrypts a payload using the provided public key and key identifier.

func (*Crypto) Exists

func (client *Crypto) Exists(ctx context.Context, kid string) bool

Exists checks storage for an entry for the given legal entity and returns true if it exists

func (*Crypto) List

func (client *Crypto) List(ctx context.Context) []string

List returns the KIDs of the private keys that are present in the key store.

func (*Crypto) Name

func (client *Crypto) Name() string

func (*Crypto) New

func (client *Crypto) New(ctx context.Context, namingFunc KIDNamingFunc) (Key, error)

New generates a new key pair. Stores the private key, returns the public basicKey. It returns an error when a key with the resulting ID already exists.

func (*Crypto) Resolve

func (client *Crypto) Resolve(ctx context.Context, kid string) (Key, error)

func (*Crypto) SignJWS

func (client *Crypto) SignJWS(ctx context.Context, payload []byte, headers map[string]interface{}, key interface{}, detached bool) (string, error)

SignJWS creates a signed JWS using the indicated key and map of headers and payload as bytes.

func (*Crypto) SignJWT

func (client *Crypto) SignJWT(ctx context.Context, claims map[string]interface{}, headers map[string]interface{}, key interface{}) (string, error)

SignJWT creates a JWT from the given claims and signs it with the given key.

type Decrypter

type Decrypter interface {
	// Decrypt decrypts the `cipherText` with key `kid`
	// The context is used to pass audit information.
	// Note: decryption isn't audit logged, because:
	// - it involved very deep context passing,
	// - it's called by the system itself, not triggered by a user.
	// - to be removed in near future when we switch to multi-chains, which eliminates private TXs and thus encryption altogether.
	Decrypt(ctx context.Context, kid string, ciphertext []byte) ([]byte, error)
}

Decrypter is the interface to support decryption

type JWTSigner

type JWTSigner interface {
	// SignJWT creates a signed JWT using the indicated key and map of claims and additional headers.
	// The key can be its KID (key ID) or an instance of Key, the context is used to pass audit information.
	// The headers can be used to add/override headers in the JWT.
	// Returns ErrPrivateKeyNotFound when the private key is not present.
	SignJWT(ctx context.Context, claims map[string]interface{}, headers map[string]interface{}, key interface{}) (string, error)
	// SignJWS creates a signed JWS using the indicated key and map of headers and payload as bytes.
	// The detached boolean indicates if the body needs to be excluded from the response (detached mode).
	// The key can be its KID (key ID) or an instance of Key,
	// context is used to pass audit information.
	// Returns ErrPrivateKeyNotFound when the private key is not present.
	SignJWS(ctx context.Context, payload []byte, headers map[string]interface{}, key interface{}, detached bool) (string, error)

	// EncryptJWE encrypts a payload as bytes into a JWE message with the given key and kid.
	// The publicKey must be a public key
	// The kid must be the KeyID and will be placed in the header, if not set.
	EncryptJWE(ctx context.Context, payload []byte, headers map[string]interface{}, publicKey interface{}) (string, error)

	// DecryptJWE decrypts a message as bytes into a decrypted body and headers.
	// The corresponding private key must be located in the KeyID (kid) header.
	DecryptJWE(ctx context.Context, message string) (body []byte, headers map[string]interface{}, err error)
}

JWTSigner is the interface used to sign authorization tokens.

type KIDNamingFunc

type KIDNamingFunc func(key crypto.PublicKey) (string, error)

KIDNamingFunc is a function passed to New() which generates the kid for the pub/priv key

func ErrorNamingFunc

func ErrorNamingFunc(err error) KIDNamingFunc

func StringNamingFunc

func StringNamingFunc(name string) KIDNamingFunc

StringNamingFunc can be used to give a key a simple string name

type Key

type Key interface {
	// KID returns the unique ID for this key.
	KID() string
	// Public returns the public key.
	Public() crypto.PublicKey
}

Key is a helper interface that describes a private key in the crypto module, specifying its KID and public part.

func NewEphemeralKey

func NewEphemeralKey(namingFunc KIDNamingFunc) (Key, error)

NewEphemeralKey returns a Key for single use.

func NewTestKey

func NewTestKey(kid string) Key

type KeyCreator

type KeyCreator interface {
	// New generates a keypair and returns a Key. The context is used to pass audit information.
	// The KIDNamingFunc will provide the kid.
	New(ctx context.Context, namingFunc KIDNamingFunc) (Key, error)
}

KeyCreator is the interface for creating key pairs.

type KeyResolver

type KeyResolver interface {
	// Exists returns if the specified private key exists.
	// If an error occurs or the context is cancelled/expired, false is also returned
	Exists(ctx context.Context, kid string) bool
	// Resolve returns a Key for the given KID. ErrPrivateKeyNotFound is returned for an unknown KID.
	Resolve(ctx context.Context, kid string) (Key, error)
	// List returns the KIDs of the private keys that are present in the KeyStore.
	List(ctx context.Context) []string
}

KeyResolver is the interface for resolving keys.

type KeyStore

type KeyStore interface {
	Decrypter
	KeyCreator
	KeyResolver
	JWTSigner
}

KeyStore defines the functions for working with private keys.

type MockDecrypter

type MockDecrypter struct {
	// contains filtered or unexported fields
}

MockDecrypter is a mock of Decrypter interface.

func NewMockDecrypter

func NewMockDecrypter(ctrl *gomock.Controller) *MockDecrypter

NewMockDecrypter creates a new mock instance.

func (*MockDecrypter) Decrypt

func (m *MockDecrypter) Decrypt(ctx context.Context, kid string, ciphertext []byte) ([]byte, error)

Decrypt mocks base method.

func (*MockDecrypter) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

type MockDecrypterMockRecorder

type MockDecrypterMockRecorder struct {
	// contains filtered or unexported fields
}

MockDecrypterMockRecorder is the mock recorder for MockDecrypter.

func (*MockDecrypterMockRecorder) Decrypt

func (mr *MockDecrypterMockRecorder) Decrypt(ctx, kid, ciphertext interface{}) *gomock.Call

Decrypt indicates an expected call of Decrypt.

type MockJWTSigner

type MockJWTSigner struct {
	// contains filtered or unexported fields
}

MockJWTSigner is a mock of JWTSigner interface.

func NewMockJWTSigner

func NewMockJWTSigner(ctrl *gomock.Controller) *MockJWTSigner

NewMockJWTSigner creates a new mock instance.

func (*MockJWTSigner) DecryptJWE

func (m *MockJWTSigner) DecryptJWE(ctx context.Context, message string) ([]byte, map[string]interface{}, error)

DecryptJWE mocks base method.

func (*MockJWTSigner) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockJWTSigner) EncryptJWE

func (m *MockJWTSigner) EncryptJWE(ctx context.Context, payload []byte, headers map[string]interface{}, publicKey interface{}) (string, error)

EncryptJWE mocks base method.

func (*MockJWTSigner) SignJWS

func (m *MockJWTSigner) SignJWS(ctx context.Context, payload []byte, headers map[string]interface{}, key interface{}, detached bool) (string, error)

SignJWS mocks base method.

func (*MockJWTSigner) SignJWT

func (m *MockJWTSigner) SignJWT(ctx context.Context, claims, headers map[string]interface{}, key interface{}) (string, error)

SignJWT mocks base method.

type MockJWTSignerMockRecorder

type MockJWTSignerMockRecorder struct {
	// contains filtered or unexported fields
}

MockJWTSignerMockRecorder is the mock recorder for MockJWTSigner.

func (*MockJWTSignerMockRecorder) DecryptJWE

func (mr *MockJWTSignerMockRecorder) DecryptJWE(ctx, message interface{}) *gomock.Call

DecryptJWE indicates an expected call of DecryptJWE.

func (*MockJWTSignerMockRecorder) EncryptJWE

func (mr *MockJWTSignerMockRecorder) EncryptJWE(ctx, payload, headers, publicKey interface{}) *gomock.Call

EncryptJWE indicates an expected call of EncryptJWE.

func (*MockJWTSignerMockRecorder) SignJWS

func (mr *MockJWTSignerMockRecorder) SignJWS(ctx, payload, headers, key, detached interface{}) *gomock.Call

SignJWS indicates an expected call of SignJWS.

func (*MockJWTSignerMockRecorder) SignJWT

func (mr *MockJWTSignerMockRecorder) SignJWT(ctx, claims, headers, key interface{}) *gomock.Call

SignJWT indicates an expected call of SignJWT.

type MockKey

type MockKey struct {
	// contains filtered or unexported fields
}

MockKey is a mock of Key interface.

func NewMockKey

func NewMockKey(ctrl *gomock.Controller) *MockKey

NewMockKey creates a new mock instance.

func (*MockKey) EXPECT

func (m *MockKey) EXPECT() *MockKeyMockRecorder

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockKey) KID

func (m *MockKey) KID() string

KID mocks base method.

func (*MockKey) Public

func (m *MockKey) Public() crypto.PublicKey

Public mocks base method.

type MockKeyCreator

type MockKeyCreator struct {
	// contains filtered or unexported fields
}

MockKeyCreator is a mock of KeyCreator interface.

func NewMockKeyCreator

func NewMockKeyCreator(ctrl *gomock.Controller) *MockKeyCreator

NewMockKeyCreator creates a new mock instance.

func (*MockKeyCreator) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockKeyCreator) New

func (m *MockKeyCreator) New(ctx context.Context, namingFunc KIDNamingFunc) (Key, error)

New mocks base method.

type MockKeyCreatorMockRecorder

type MockKeyCreatorMockRecorder struct {
	// contains filtered or unexported fields
}

MockKeyCreatorMockRecorder is the mock recorder for MockKeyCreator.

func (*MockKeyCreatorMockRecorder) New

func (mr *MockKeyCreatorMockRecorder) New(ctx, namingFunc interface{}) *gomock.Call

New indicates an expected call of New.

type MockKeyMockRecorder

type MockKeyMockRecorder struct {
	// contains filtered or unexported fields
}

MockKeyMockRecorder is the mock recorder for MockKey.

func (*MockKeyMockRecorder) KID

func (mr *MockKeyMockRecorder) KID() *gomock.Call

KID indicates an expected call of KID.

func (*MockKeyMockRecorder) Public

func (mr *MockKeyMockRecorder) Public() *gomock.Call

Public indicates an expected call of Public.

type MockKeyResolver

type MockKeyResolver struct {
	// contains filtered or unexported fields
}

MockKeyResolver is a mock of KeyResolver interface.

func NewMockKeyResolver

func NewMockKeyResolver(ctrl *gomock.Controller) *MockKeyResolver

NewMockKeyResolver creates a new mock instance.

func (*MockKeyResolver) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockKeyResolver) Exists

func (m *MockKeyResolver) Exists(ctx context.Context, kid string) bool

Exists mocks base method.

func (*MockKeyResolver) List

func (m *MockKeyResolver) List(ctx context.Context) []string

List mocks base method.

func (*MockKeyResolver) Resolve

func (m *MockKeyResolver) Resolve(ctx context.Context, kid string) (Key, error)

Resolve mocks base method.

type MockKeyResolverMockRecorder

type MockKeyResolverMockRecorder struct {
	// contains filtered or unexported fields
}

MockKeyResolverMockRecorder is the mock recorder for MockKeyResolver.

func (*MockKeyResolverMockRecorder) Exists

func (mr *MockKeyResolverMockRecorder) Exists(ctx, kid interface{}) *gomock.Call

Exists indicates an expected call of Exists.

func (*MockKeyResolverMockRecorder) List

func (mr *MockKeyResolverMockRecorder) List(ctx interface{}) *gomock.Call

List indicates an expected call of List.

func (*MockKeyResolverMockRecorder) Resolve

func (mr *MockKeyResolverMockRecorder) Resolve(ctx, kid interface{}) *gomock.Call

Resolve indicates an expected call of Resolve.

type MockKeyStore

type MockKeyStore struct {
	// contains filtered or unexported fields
}

MockKeyStore is a mock of KeyStore interface.

func NewMockKeyStore

func NewMockKeyStore(ctrl *gomock.Controller) *MockKeyStore

NewMockKeyStore creates a new mock instance.

func (*MockKeyStore) Decrypt

func (m *MockKeyStore) Decrypt(ctx context.Context, kid string, ciphertext []byte) ([]byte, error)

Decrypt mocks base method.

func (*MockKeyStore) DecryptJWE

func (m *MockKeyStore) DecryptJWE(ctx context.Context, message string) ([]byte, map[string]interface{}, error)

DecryptJWE mocks base method.

func (*MockKeyStore) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockKeyStore) EncryptJWE

func (m *MockKeyStore) EncryptJWE(ctx context.Context, payload []byte, headers map[string]interface{}, publicKey interface{}) (string, error)

EncryptJWE mocks base method.

func (*MockKeyStore) Exists

func (m *MockKeyStore) Exists(ctx context.Context, kid string) bool

Exists mocks base method.

func (*MockKeyStore) List

func (m *MockKeyStore) List(ctx context.Context) []string

List mocks base method.

func (*MockKeyStore) New

func (m *MockKeyStore) New(ctx context.Context, namingFunc KIDNamingFunc) (Key, error)

New mocks base method.

func (*MockKeyStore) Resolve

func (m *MockKeyStore) Resolve(ctx context.Context, kid string) (Key, error)

Resolve mocks base method.

func (*MockKeyStore) SignJWS

func (m *MockKeyStore) SignJWS(ctx context.Context, payload []byte, headers map[string]interface{}, key interface{}, detached bool) (string, error)

SignJWS mocks base method.

func (*MockKeyStore) SignJWT

func (m *MockKeyStore) SignJWT(ctx context.Context, claims, headers map[string]interface{}, key interface{}) (string, error)

SignJWT mocks base method.

type MockKeyStoreMockRecorder

type MockKeyStoreMockRecorder struct {
	// contains filtered or unexported fields
}

MockKeyStoreMockRecorder is the mock recorder for MockKeyStore.

func (*MockKeyStoreMockRecorder) Decrypt

func (mr *MockKeyStoreMockRecorder) Decrypt(ctx, kid, ciphertext interface{}) *gomock.Call

Decrypt indicates an expected call of Decrypt.

func (*MockKeyStoreMockRecorder) DecryptJWE

func (mr *MockKeyStoreMockRecorder) DecryptJWE(ctx, message interface{}) *gomock.Call

DecryptJWE indicates an expected call of DecryptJWE.

func (*MockKeyStoreMockRecorder) EncryptJWE

func (mr *MockKeyStoreMockRecorder) EncryptJWE(ctx, payload, headers, publicKey interface{}) *gomock.Call

EncryptJWE indicates an expected call of EncryptJWE.

func (*MockKeyStoreMockRecorder) Exists

func (mr *MockKeyStoreMockRecorder) Exists(ctx, kid interface{}) *gomock.Call

Exists indicates an expected call of Exists.

func (*MockKeyStoreMockRecorder) List

func (mr *MockKeyStoreMockRecorder) List(ctx interface{}) *gomock.Call

List indicates an expected call of List.

func (*MockKeyStoreMockRecorder) New

func (mr *MockKeyStoreMockRecorder) New(ctx, namingFunc interface{}) *gomock.Call

New indicates an expected call of New.

func (*MockKeyStoreMockRecorder) Resolve

func (mr *MockKeyStoreMockRecorder) Resolve(ctx, kid interface{}) *gomock.Call

Resolve indicates an expected call of Resolve.

func (*MockKeyStoreMockRecorder) SignJWS

func (mr *MockKeyStoreMockRecorder) SignJWS(ctx, payload, headers, key, detached interface{}) *gomock.Call

SignJWS indicates an expected call of SignJWS.

func (*MockKeyStoreMockRecorder) SignJWT

func (mr *MockKeyStoreMockRecorder) SignJWT(ctx, claims, headers, key interface{}) *gomock.Call

SignJWT indicates an expected call of SignJWT.

type MockexportableKey

type MockexportableKey struct {
	// contains filtered or unexported fields
}

MockexportableKey is a mock of exportableKey interface.

func NewMockexportableKey

func NewMockexportableKey(ctrl *gomock.Controller) *MockexportableKey

NewMockexportableKey creates a new mock instance.

func (*MockexportableKey) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockexportableKey) KID

func (m *MockexportableKey) KID() string

KID mocks base method.

func (*MockexportableKey) Public

func (m *MockexportableKey) Public() crypto.PublicKey

Public mocks base method.

func (*MockexportableKey) Signer

func (m *MockexportableKey) Signer() crypto.Signer

Signer mocks base method.

type MockexportableKeyMockRecorder

type MockexportableKeyMockRecorder struct {
	// contains filtered or unexported fields
}

MockexportableKeyMockRecorder is the mock recorder for MockexportableKey.

func (*MockexportableKeyMockRecorder) KID

KID indicates an expected call of KID.

func (*MockexportableKeyMockRecorder) Public

Public indicates an expected call of Public.

func (*MockexportableKeyMockRecorder) Signer

Signer indicates an expected call of Signer.

type PublicKeyFunc

type PublicKeyFunc func(kid string) (crypto.PublicKey, error)

PublicKeyFunc defines a function that resolves a public key based on a kid

type TestKey

type TestKey struct {
	PrivateKey crypto.Signer
	Kid        string
}

TestKey is a Key impl for testing purposes

func (TestKey) KID

func (t TestKey) KID() string

func (TestKey) Private

func (t TestKey) Private() crypto.PrivateKey

func (TestKey) Public

func (t TestKey) Public() crypto.PublicKey

func (TestKey) Signer

func (t TestKey) Signer() crypto.Signer

Directories

Path Synopsis
api
v1
Package v1 provides primitives to interact with the openapi HTTP API.
Package v1 provides primitives to interact with the openapi HTTP API.
Package storage provides secret storage for the Crypto module.
Package storage provides secret storage for the Crypto module.
external
Package external provides primitives to interact with the openapi HTTP API.
Package external provides primitives to interact with the openapi HTTP API.
fs
spi
Package spi is a generated GoMock package.
Package spi is a generated GoMock package.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL