Versions in this module Expand all Collapse all v5 v5.4.40 Sep 22, 2026 v5.4.39 Sep 21, 2026 Changes in this version + const ModuleName + var ErrPrivateKeyNotFound = errors.New("private key not found") + var ErrUnsupportedSigningKey = errors.New("signing key algorithm not supported") + func EciesDecrypt(privateKey *ecdsa.PrivateKey, cipherText []byte) ([]byte, error) + func EciesEncrypt(publicKey *ecdsa.PublicKey, plainText []byte) ([]byte, error) + func EncryptJWE(payload []byte, protectedHeaders map[string]interface{}, publicKey interface{}) (message string, err error) + func JWTKidAlg(tokenString string) (string, jwa.SignatureAlgorithm, error) + func NewMemoryStorage() spi.Storage + func ParseJWS(token []byte, f PublicKeyFunc) (payload []byte, err error) + func ParseJWT(tokenString string, f PublicKeyFunc, options ...jwt.ParseOption) (jwt.Token, error) + func SignatureAlgorithm(key crypto.PublicKey) (jwa.SignatureAlgorithm, error) + func Thumbprint(key jwk.Key) (string, error) + type Config struct + External external.Config + Storage string + Vault vault.Config + func DefaultCryptoConfig() Config + type Crypto struct + func NewCryptoInstance() *Crypto + func NewMemoryCryptoInstance() *Crypto + func NewTestCryptoInstance(storage spi.Storage) *Crypto + func (client *Crypto) CheckHealth() map[string]core.Health + func (client *Crypto) Config() interface{} + func (client *Crypto) Configure(config core.ServerConfig) error + func (client *Crypto) Decrypt(ctx context.Context, kid string, cipherText []byte) ([]byte, error) + func (client *Crypto) DecryptJWE(ctx context.Context, message string) (body []byte, headers map[string]interface{}, err error) + func (client *Crypto) EncryptJWE(ctx context.Context, payload []byte, headers map[string]interface{}, ...) (string, error) + func (client *Crypto) Exists(ctx context.Context, kid string) bool + func (client *Crypto) List(ctx context.Context) []string + func (client *Crypto) Name() string + func (client *Crypto) New(ctx context.Context, namingFunc KIDNamingFunc) (Key, error) + func (client *Crypto) Resolve(ctx context.Context, kid string) (Key, error) + func (client *Crypto) SignJWS(ctx context.Context, payload []byte, headers map[string]interface{}, ...) (string, error) + func (client *Crypto) SignJWT(ctx context.Context, claims map[string]interface{}, ...) (string, error) + type Decrypter interface + Decrypt func(ctx context.Context, kid string, ciphertext []byte) ([]byte, error) + type JWTSigner interface + DecryptJWE func(ctx context.Context, message string) (body []byte, headers map[string]interface{}, err error) + EncryptJWE func(ctx context.Context, payload []byte, headers map[string]interface{}, ...) (string, error) + SignJWS func(ctx context.Context, payload []byte, headers map[string]interface{}, ...) (string, error) + SignJWT func(ctx context.Context, claims map[string]interface{}, ...) (string, error) + type KIDNamingFunc func(key crypto.PublicKey) (string, error) + func ErrorNamingFunc(err error) KIDNamingFunc + func StringNamingFunc(name string) KIDNamingFunc + type Key interface + KID func() string + Public func() crypto.PublicKey + func NewEphemeralKey(namingFunc KIDNamingFunc) (Key, error) + func NewTestKey(kid string) Key + type KeyCreator interface + New func(ctx context.Context, namingFunc KIDNamingFunc) (Key, error) + type KeyResolver interface + Exists func(ctx context.Context, kid string) bool + List func(ctx context.Context) []string + Resolve func(ctx context.Context, kid string) (Key, error) + type KeyStore interface + type MockDecrypter struct + func NewMockDecrypter(ctrl *gomock.Controller) *MockDecrypter + func (m *MockDecrypter) Decrypt(ctx context.Context, kid string, ciphertext []byte) ([]byte, error) + func (m *MockDecrypter) EXPECT() *MockDecrypterMockRecorder + type MockDecrypterMockRecorder struct + func (mr *MockDecrypterMockRecorder) Decrypt(ctx, kid, ciphertext interface{}) *gomock.Call + type MockJWTSigner struct + func NewMockJWTSigner(ctrl *gomock.Controller) *MockJWTSigner + func (m *MockJWTSigner) DecryptJWE(ctx context.Context, message string) ([]byte, map[string]interface{}, error) + func (m *MockJWTSigner) EXPECT() *MockJWTSignerMockRecorder + func (m *MockJWTSigner) EncryptJWE(ctx context.Context, payload []byte, headers map[string]interface{}, ...) (string, error) + func (m *MockJWTSigner) SignJWS(ctx context.Context, payload []byte, headers map[string]interface{}, ...) (string, error) + func (m *MockJWTSigner) SignJWT(ctx context.Context, claims, headers map[string]interface{}, key interface{}) (string, error) + type MockJWTSignerMockRecorder struct + func (mr *MockJWTSignerMockRecorder) DecryptJWE(ctx, message interface{}) *gomock.Call + func (mr *MockJWTSignerMockRecorder) EncryptJWE(ctx, payload, headers, publicKey interface{}) *gomock.Call + func (mr *MockJWTSignerMockRecorder) SignJWS(ctx, payload, headers, key, detached interface{}) *gomock.Call + func (mr *MockJWTSignerMockRecorder) SignJWT(ctx, claims, headers, key interface{}) *gomock.Call + type MockKey struct + func NewMockKey(ctrl *gomock.Controller) *MockKey + func (m *MockKey) EXPECT() *MockKeyMockRecorder + func (m *MockKey) KID() string + func (m *MockKey) Public() crypto.PublicKey + type MockKeyCreator struct + func NewMockKeyCreator(ctrl *gomock.Controller) *MockKeyCreator + func (m *MockKeyCreator) EXPECT() *MockKeyCreatorMockRecorder + func (m *MockKeyCreator) New(ctx context.Context, namingFunc KIDNamingFunc) (Key, error) + type MockKeyCreatorMockRecorder struct + func (mr *MockKeyCreatorMockRecorder) New(ctx, namingFunc interface{}) *gomock.Call + type MockKeyMockRecorder struct + func (mr *MockKeyMockRecorder) KID() *gomock.Call + func (mr *MockKeyMockRecorder) Public() *gomock.Call + type MockKeyResolver struct + func NewMockKeyResolver(ctrl *gomock.Controller) *MockKeyResolver + func (m *MockKeyResolver) EXPECT() *MockKeyResolverMockRecorder + func (m *MockKeyResolver) Exists(ctx context.Context, kid string) bool + func (m *MockKeyResolver) List(ctx context.Context) []string + func (m *MockKeyResolver) Resolve(ctx context.Context, kid string) (Key, error) + type MockKeyResolverMockRecorder struct + func (mr *MockKeyResolverMockRecorder) Exists(ctx, kid interface{}) *gomock.Call + func (mr *MockKeyResolverMockRecorder) List(ctx interface{}) *gomock.Call + func (mr *MockKeyResolverMockRecorder) Resolve(ctx, kid interface{}) *gomock.Call + type MockKeyStore struct + func NewMockKeyStore(ctrl *gomock.Controller) *MockKeyStore + func (m *MockKeyStore) Decrypt(ctx context.Context, kid string, ciphertext []byte) ([]byte, error) + func (m *MockKeyStore) DecryptJWE(ctx context.Context, message string) ([]byte, map[string]interface{}, error) + func (m *MockKeyStore) EXPECT() *MockKeyStoreMockRecorder + func (m *MockKeyStore) EncryptJWE(ctx context.Context, payload []byte, headers map[string]interface{}, ...) (string, error) + func (m *MockKeyStore) Exists(ctx context.Context, kid string) bool + func (m *MockKeyStore) List(ctx context.Context) []string + func (m *MockKeyStore) New(ctx context.Context, namingFunc KIDNamingFunc) (Key, error) + func (m *MockKeyStore) Resolve(ctx context.Context, kid string) (Key, error) + func (m *MockKeyStore) SignJWS(ctx context.Context, payload []byte, headers map[string]interface{}, ...) (string, error) + func (m *MockKeyStore) SignJWT(ctx context.Context, claims, headers map[string]interface{}, key interface{}) (string, error) + type MockKeyStoreMockRecorder struct + func (mr *MockKeyStoreMockRecorder) Decrypt(ctx, kid, ciphertext interface{}) *gomock.Call + func (mr *MockKeyStoreMockRecorder) DecryptJWE(ctx, message interface{}) *gomock.Call + func (mr *MockKeyStoreMockRecorder) EncryptJWE(ctx, payload, headers, publicKey interface{}) *gomock.Call + func (mr *MockKeyStoreMockRecorder) Exists(ctx, kid interface{}) *gomock.Call + func (mr *MockKeyStoreMockRecorder) List(ctx interface{}) *gomock.Call + func (mr *MockKeyStoreMockRecorder) New(ctx, namingFunc interface{}) *gomock.Call + func (mr *MockKeyStoreMockRecorder) Resolve(ctx, kid interface{}) *gomock.Call + func (mr *MockKeyStoreMockRecorder) SignJWS(ctx, payload, headers, key, detached interface{}) *gomock.Call + func (mr *MockKeyStoreMockRecorder) SignJWT(ctx, claims, headers, key interface{}) *gomock.Call + type MockexportableKey struct + func NewMockexportableKey(ctrl *gomock.Controller) *MockexportableKey + func (m *MockexportableKey) EXPECT() *MockexportableKeyMockRecorder + func (m *MockexportableKey) KID() string + func (m *MockexportableKey) Public() crypto.PublicKey + func (m *MockexportableKey) Signer() crypto.Signer + type MockexportableKeyMockRecorder struct + func (mr *MockexportableKeyMockRecorder) KID() *gomock.Call + func (mr *MockexportableKeyMockRecorder) Public() *gomock.Call + func (mr *MockexportableKeyMockRecorder) Signer() *gomock.Call + type PublicKeyFunc func(kid string) (crypto.PublicKey, error) + type TestKey struct + Kid string + PrivateKey crypto.Signer + func (t TestKey) KID() string + func (t TestKey) Private() crypto.PrivateKey + func (t TestKey) Public() crypto.PublicKey + func (t TestKey) Signer() crypto.Signer Other modules containing this package github.com/nuts-foundation/nuts-node github.com/nuts-foundation/nuts-node/v6