keys

package
v0.148.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 23 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func ParsePublicPEM

func ParsePublicPEM(pemBytes []byte) (crypto.PublicKey, error)

ParsePublicPEM parses a PKIX/SPKI, certificate or PKCS #1 RSA public key PEM under AuthKit's key policy: RSA of 2048-8192 bits, P-256/384/521 or Ed25519.

func PublicKeys

func PublicKeys(ks JWKS) (map[string]crypto.PublicKey, error)

PublicKeys is a JWKS's usable keys by kid ("default" for a key without one). Malformed, weak or unsupported keys are skipped; a set without a usable key is an error.

Types

type FileSource

type FileSource struct {
	// contains filtered or unexported fields
}

FileSource is the Source Watch returns: keys.json, reloaded when it changes on disk (re-rendered by Vault Agent), so a signing-key rotation needs no restart. Reads are lock-free. A malformed or unreadable file keeps the last good keys: a bad render never bricks signing (authkit #90).

func Watch

func Watch(path string) (*FileSource, error)

Watch loads <path>/keys.json, the envelope {active_key_id, active_private_key_pem, public_keys: {kid: pem}}, and re-reads it every 10s when it changed. It errors when path holds no valid keys.json. Close stops the watch; reloads are logged on slog.Default.

func (*FileSource) ActiveSigner

func (r *FileSource) ActiveSigner() Signer

func (*FileSource) Close

func (r *FileSource) Close()

Close stops the background poller. Safe to call multiple times; optional for process-lifetime sources (primarily for tests and clean shutdown).

func (*FileSource) PublicKeys

func (r *FileSource) PublicKeys() map[string]crypto.PublicKey

func (*FileSource) Reload

func (r *FileSource) Reload() error

Reload re-reads keys.json, validates it, and atomically swaps it in. On any read/parse/validation failure it KEEPS the current keystore and returns the error — it never serves a partial or empty key set.

type JWK

type JWK struct {
	Kty string `json:"kty"`
	Use string `json:"use,omitempty"`
	Kid string `json:"kid,omitempty"`
	Alg string `json:"alg,omitempty"`
	// RSA
	N string `json:"n,omitempty"`
	E string `json:"e,omitempty"`
	// EC / OKP
	Crv string `json:"crv,omitempty"`
	X   string `json:"x,omitempty"`
	Y   string `json:"y,omitempty"`
}

JWK is a JSON Web Key (RSA, EC or OKP).

func PublicJWK

func PublicJWK(pub crypto.PublicKey, kid, alg string) JWK

PublicJWK is pub as a JWK; an empty alg is the one the key signs with.

type JWKS

type JWKS struct {
	Keys []JWK `json:"keys"`
}

JWKS is a JSON Web Key Set.

type Signer

type Signer interface {
	// Algorithm is the JWS alg: RS256, ES256, ES384, ES512 or EdDSA.
	Algorithm() string
	// KID is the key id stamped into the header and published in the JWKS.
	KID() string
	// Public is the verification key.
	Public() crypto.PublicKey
	// Sign returns the JWS signature over signingInput (the encoded header
	// and payload joined by "."): PKCS #1 v1.5 for RS256, the fixed-width
	// R||S pair for ES*, and the raw signature for EdDSA.
	Sign(ctx context.Context, signingInput []byte) ([]byte, error)
}

Signer signs JWS signing input with one private key AuthKit never sees, so an HSM, KMS or Vault key implements it directly.

func SignerFromKey

func SignerFromKey(kid string, key crypto.Signer) (Signer, error)

SignerFromKey wraps key, an in-process private key or any crypto.Signer (a KMS client), as a Signer. The algorithm follows the key: RSA is RS256, P-256, P-384 and P-521 are ES256, ES384 and ES512, Ed25519 is EdDSA.

func SignerFromPEM

func SignerFromPEM(kid string, pemBytes []byte) (Signer, error)

SignerFromPEM builds a Signer from a PEM private key: PKCS #1 or PKCS #8 RSA, SEC 1 or PKCS #8 EC, or PKCS #8 Ed25519.

type Source

type Source interface {
	ActiveSigner() Signer
	PublicKeys() map[string]crypto.PublicKey
}

Source is a deployment's signing keys: the active signer, and the public keys its JWKS publishes (the active one and retired ones still verifying).

type Static

type Static struct {
	Active Signer
	Pubs   map[string]crypto.PublicKey
}

Static is a fixed Source.

func StaticFromPEM

func StaticFromPEM(activeKeyID, activePrivateKeyPEM string, publicKeysPEM map[string]string) (Static, error)

StaticFromPEM builds a Static source from the active signing key (kid and private-key PEM) plus verification-only public keys (kid to PEM, such as retired keys kept in the JWKS during rotation). It performs no I/O. An unparseable public key is an error: a verifier that silently drops a rotation key would reject every token it signed.

func (Static) ActiveSigner

func (s Static) ActiveSigner() Signer

func (Static) PublicKeys

func (s Static) PublicKeys() map[string]crypto.PublicKey

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL