3 * Copyright (c) 2020, Blue Static <https://www.bluestatic.org>
5 * This program is free software; you can redistribute it and/or modify it under the terms of the GNU
6 * General Public License as published by the Free Software Foundation; either version 2 of the
7 * License, or (at your option) any later version.
9 * This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without
10 * even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
11 * General Public License for more details.
13 * You should have received a copy of the GNU General Public License along with this program; if not,
14 * write to the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA
19 asn1-wrap-ed25519 takes a raw private key from signer-ed25519 and reencodes it as PEM PKCS8 (ASN.1).
21 The raw keys generated by signer-ed25519 are not compatible with the OpenSSL
22 command. By storing it in PKCS8, the keys can be used with openssl commands.
26 ./signer-ed25519 -new-key > out.key
27 ./asn1-wrap-ed25519 out.key > out-wrapped.key
43 keyPemData, err := ioutil.ReadFile(keyfile)
45 fmt.Fprintf(os.Stderr, "Failed to read key: %v\n", err)
49 keyPem, _ := pem.Decode(keyPemData)
51 fmt.Fprintf(os.Stderr, "Failed to decode PEM: %v\n", err)
55 key := ed25519.PrivateKey(keyPem.Bytes)
57 asn1Bytes, err := x509.MarshalPKCS8PrivateKey(key)
59 fmt.Fprintf(os.Stderr, "Failed to ASN.1 encode key: %v\n", err)
63 asn1Pem := &pem.Block{Type: "PRIVATE KEY", Bytes: asn1Bytes}
65 err = pem.Encode(os.Stdout, asn1Pem)
67 fmt.Println("Failed to PEM-encode ASN.1 key: %v\n", err)