-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathkeyring.go
117 lines (94 loc) · 2.41 KB
/
keyring.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
package main
import (
"fmt"
"log"
"crypto/ecdsa"
"crypto/rsa"
"crypto/dsa"
"crypto/ed25519"
"golang.org/x/crypto/ssh"
"golang.org/x/crypto/ssh/agent"
)
var ErrKeyringOperationDenied = fmt.Errorf("keyring operation denied")
type TrustedKeyring struct {
agent.Agent
}
func (kr *TrustedKeyring) Add(key agent.AddedKey) error {
var err error
var sshPublicKey ssh.PublicKey
var keyType string
switch pkey := key.PrivateKey.(type) {
case *ecdsa.PrivateKey:
p := pkey.Public()
sshPublicKey, err = ssh.NewPublicKey(p)
if err != nil {
return err
}
keyType = "ECDSA"
case *rsa.PrivateKey:
p := pkey.Public()
sshPublicKey, err = ssh.NewPublicKey(p)
if err != nil {
return err
}
keyType = "RSA"
case *dsa.PrivateKey:
sshPublicKey, err = ssh.NewPublicKey(pkey.PublicKey)
if err != nil {
return err
}
keyType = "DSA"
case *ed25519.PrivateKey:
p := pkey.Public()
sshPublicKey, err = ssh.NewPublicKey(p)
if err != nil {
return err
}
keyType = "ED25519"
}
log.Printf("Identity added: %s %s (%s)\n", ssh.FingerprintSHA256(sshPublicKey), key.Comment, keyType)
return kr.Agent.Add(key)
}
type SignOnlyKeyring struct {
agent.Agent
}
func (kr *SignOnlyKeyring) Add(key agent.AddedKey) error {
return ErrKeyringOperationDenied
}
func (kr *SignOnlyKeyring) Remove(key ssh.PublicKey) error {
return ErrKeyringOperationDenied
}
func (kr *SignOnlyKeyring) RemoveAll() error {
return ErrKeyringOperationDenied
}
func (kr *SignOnlyKeyring) Lock(passphrase []byte) error {
return ErrKeyringOperationDenied
}
func (kr *SignOnlyKeyring) Unlock(passphrase []byte) error {
return ErrKeyringOperationDenied
}
type NoopKeyring struct{}
func (kr *NoopKeyring) List() ([]*agent.Key, error) {
return nil, ErrKeyringOperationDenied
}
func (kr *NoopKeyring) Sign(key ssh.PublicKey, data []byte) (*ssh.Signature, error) {
return nil, ErrKeyringOperationDenied
}
func (kr *NoopKeyring) Add(key agent.AddedKey) error {
return ErrKeyringOperationDenied
}
func (kr *NoopKeyring) Remove(key ssh.PublicKey) error {
return ErrKeyringOperationDenied
}
func (kr *NoopKeyring) RemoveAll() error {
return ErrKeyringOperationDenied
}
func (kr *NoopKeyring) Lock(passphrase []byte) error {
return ErrKeyringOperationDenied
}
func (kr *NoopKeyring) Unlock(passphrase []byte) error {
return ErrKeyringOperationDenied
}
func (kr *NoopKeyring) Signers() ([]ssh.Signer, error) {
return nil, ErrKeyringOperationDenied
}