Skip to content
File

Blob: cmd/pki/ca/main.go

go80 lines
1package main
2 
3import (
4 "bytes"
5 "crypto/ed25519"
6 "crypto/rand"
7 "crypto/x509"
8 "crypto/x509/pkix"
9 "encoding/pem"
10 "flag"
11 "fmt"
12 "math/big"
13 "os"
14 "path/filepath"
15 "time"
16)
17 
18var (
19 caCommonName = flag.String("cn", "specter client ca", "CommonName of the client CA")
20 certsDir = flag.String("certs", "certs", "path to directory to store client-ca.crt and client-ca.key")
21)
22 
23func main() {
24 flag.Parse()
25 
26 caPubKey, caPrivKey, err := ed25519.GenerateKey(rand.Reader)
27 if err != nil {
28 panic(err)
29 }
30 
31 sn := new(big.Int).SetInt64(time.Now().UnixNano())
32 
33 cert := &x509.Certificate{
34 Subject: pkix.Name{
35 CommonName: *caCommonName,
36 },
37 SerialNumber: sn,
38 NotBefore: time.Now(),
39 NotAfter: time.Now().AddDate(10, 0, 0),
40 KeyUsage: x509.KeyUsageDigitalSignature | x509.KeyUsageCertSign | x509.KeyUsageCRLSign,
41 BasicConstraintsValid: true,
42 IsCA: true,
43 MaxPathLen: 0,
44 MaxPathLenZero: true,
45 }
46 
47 certBytes, err := x509.CreateCertificate(rand.Reader, cert, cert, caPubKey, caPrivKey)
48 if err != nil {
49 panic(err)
50 }
51 
52 certPEM := new(bytes.Buffer)
53 pem.Encode(certPEM, &pem.Block{
54 Type: "CERTIFICATE",
55 Bytes: certBytes,
56 })
57 
58 fmt.Printf("%+s\n", certPEM.Bytes())
59 err = os.WriteFile(filepath.Join(*certsDir, "client-ca.crt"), certPEM.Bytes(), 0644)
60 if err != nil {
61 panic(err)
62 }
63 
64 x509PrivKey, err := x509.MarshalPKCS8PrivateKey(caPrivKey)
65 if err != nil {
66 panic(err)
67 }
68 certPrivKeyPEM := new(bytes.Buffer)
69 pem.Encode(certPrivKeyPEM, &pem.Block{
70 Type: "PRIVATE KEY",
71 Bytes: x509PrivKey,
72 })
73 
74 fmt.Printf("%+s\n", certPrivKeyPEM.Bytes())
75 err = os.WriteFile(filepath.Join(*certsDir, "client-ca.key"), certPrivKeyPEM.Bytes(), 0644)
76 if err != nil {
77 panic(err)
78 }
79}