File
Blob: pki/client.go
| 1 | package pki |
| 2 | |
| 3 | import ( |
| 4 | "crypto/ed25519" |
| 5 | "crypto/sha256" |
| 6 | "encoding/base64" |
| 7 | |
| 8 | "go.miragespace.co/specter/spec/pki" |
| 9 | "go.miragespace.co/specter/spec/pow" |
| 10 | "go.miragespace.co/specter/spec/protocol" |
| 11 | ) |
| 12 | |
| 13 | func CreateRequest(privKey ed25519.PrivateKey) (*protocol.CertificateRequest, error) { |
| 14 | proof, err := generatePKIProof(privKey) |
| 15 | if err != nil { |
| 16 | return nil, err |
| 17 | } |
| 18 | |
| 19 | return &protocol.CertificateRequest{ |
| 20 | Proof: proof, |
| 21 | }, nil |
| 22 | } |
| 23 | |
| 24 | func CreateRenewalRequest(privKey ed25519.PrivateKey, currentCertDer []byte) (*protocol.CertificateRenewalRequest, error) { |
| 25 | proof, err := generatePKIProof(privKey) |
| 26 | if err != nil { |
| 27 | return nil, err |
| 28 | } |
| 29 | |
| 30 | return &protocol.CertificateRenewalRequest{ |
| 31 | Proof: proof, |
| 32 | CurrentCertDer: currentCertDer, |
| 33 | }, nil |
| 34 | } |
| 35 | |
| 36 | func generatePKIProof(privKey ed25519.PrivateKey) (*protocol.ProofOfWork, error) { |
| 37 | return pow.GenerateSolution(privKey, pow.Parameters{ |
| 38 | Difficulty: pki.HashcashDifficulty, |
| 39 | Expires: pki.HashcashExpires, |
| 40 | GetSubject: func(pubKey ed25519.PublicKey) string { |
| 41 | h := sha256.New() |
| 42 | h.Write(pubKey) |
| 43 | return base64.URLEncoding.EncodeToString(h.Sum(nil)) |
| 44 | }, |
| 45 | }) |
| 46 | } |