rsasign

package
v1.2.5 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 19, 2026 License: Apache-2.0 Imports: 6 Imported by: 0

Documentation

Overview

Package rsasign computes RSASSA-PKCS1-v1_5 signatures over a SHA-256 digest, through crypto/rsa on host Go and through the OS on TinyGo builds.

It exists for binary size. Linking crypto/rsa and crypto/x509 into a TinyGo build costs about 588 KB, on a target where the whole HTTPS client is 272 KB on darwin; reaching the same operation through Security.framework costs about 131 KB. Speed is a side effect and not the point: TinyGo compiles the multi-precision inner loop from portable Go rather than assembly, because it sets the purego build tag, so a pure-Go signature takes 2.9 ms against 1.1 ms natively. At one signature per token lifetime neither number matters.

The only caller is cloud/google, which signs one JWT per hour. The surface is deliberately narrow: one algorithm, one direction, no verification. Verifying happens in tests, on host Go, where crypto/rsa is free.

key, err := rsasign.ParsePKCS8(pemBytes)
defer key.Close()
digest := sha256.Sum256(signingInput)
sig, err := key.SignPKCS1v15SHA256(digest[:])

Close releases the native handle. A Key that is dropped without it leaks one, the same obligation the TLS backends carry.

Because RSASSA-PKCS1-v1_5 is deterministic — no salt, no nonce — every backend must produce byte-identical signatures for the same key and message. That is what testdata pins, and it is the reason this is the one native backend in this repository verifiable without a live peer.

Index

Constants

View Source
const Backend = "crypto/rsa"

Backend identifies the RSA implementation selected by build constraints.

Variables

View Source
var (
	// ErrBadKey is returned for input that is not a usable PKCS#8 RSA key.
	ErrBadKey = errors.New("rsasign: not a PKCS#8 RSA private key")

	// ErrClosed is returned by a Key used after Close.
	ErrClosed = errors.New("rsasign: key is closed")

	// ErrBadDigest is returned for a digest that is not 32 bytes. Only SHA-256
	// is supported, so a wrong length is a caller mistake, not a variation.
	ErrBadDigest = errors.New("rsasign: digest must be 32 bytes")

	// ErrSignFailed is returned when a backend rejects an otherwise valid
	// request. It carries no detail because the native APIs report none worth
	// forwarding.
	ErrSignFailed = errors.New("rsasign: signing failed")

	// ErrPlatformNotSupported is returned on a build with no backend. It is
	// never a fallback to crypto/rsa: a silent fallback would satisfy the
	// no-crypto/rsa property on one build and break it on another.
	ErrPlatformNotSupported = errors.New("rsasign: no RSA backend for this platform")
)

Functions

This section is empty.

Types

type Key

type Key struct {
	// contains filtered or unexported fields
}

Key is a private key ready to sign. On this build it holds a parsed *rsa.PrivateKey; there is no native handle and Close is a formality kept so callers need not know which build they are on.

func ParsePKCS8

func ParsePKCS8(pemBytes []byte) (*Key, error)

ParsePKCS8 reads a PEM-wrapped PKCS#8 private key, the form a Google service account file carries, and prepares it for signing.

func (*Key) Bits

func (k *Key) Bits() int

Bits is the modulus size, which is also the signature length in bits.

func (*Key) Close

func (k *Key) Close() error

Close releases the key. It is safe to call more than once.

func (*Key) SignPKCS1v15SHA256

func (k *Key) SignPKCS1v15SHA256(digest []byte) ([]byte, error)

SignPKCS1v15SHA256 signs a 32-byte SHA-256 digest.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL