Sign and verify manifests in Go with OpenPGP instead of running gpg (closes #181)
check / check (push) Waiting to run
check / check (push) Waiting to run
mfer ran the gpg binary to sign, export keys and verify, so it failed wherever gpg is missing. It now uses github.com/ProtonMail/go-crypto/openpgp. --sign-key and MFER_SIGN_KEY name a file holding one version 4 OpenPGP secret key; a protected key's passphrase comes from MFER_SIGN_KEY_PASSPHRASE or a terminal prompt. gen and freshen check that the key can sign before they read any file. Verification keeps the rules of the --require-signature fix: one primary key in the embedded block, counted from its packets, exactly one signature, made by that key or a subkey, and signer equal to its fingerprint. The embedded block may hold no DSA key and no secret key, and an armored field must be one well-formed block. Model: opus-5-5
This commit was merged in pull request #183.
This commit is contained in:
@@ -257,8 +257,9 @@ are now tracked only in the [issues](https://git.eeqj.de/sneak/mfer/issues).
|
||||
|
||||
- Should the manifest signature format be GnuPG signatures, or those from
|
||||
OpenBSD's signify (of which there is a good
|
||||
[golang implementation](https://github.com/frankbraun/gosignify))? Still open,
|
||||
as question 10 on [issue 82](https://git.eeqj.de/sneak/mfer/issues/82).
|
||||
[golang implementation](https://github.com/frankbraun/gosignify))? Settled
|
||||
under question 10 on [issue 82](https://git.eeqj.de/sneak/mfer/issues/82):
|
||||
OpenPGP signatures, which mfer makes and checks itself without running `gpg`.
|
||||
|
||||
- Should the on-disk serialization format be proto3 or json? Settled: it is
|
||||
proto3, see `docs/FORMAT.md` and `mfer/mf.proto`.
|
||||
@@ -296,6 +297,17 @@ are now tracked only in the [issues](https://git.eeqj.de/sneak/mfer/issues).
|
||||
- leaves out hidden files unless given `--include-dotfiles`, and symlinks
|
||||
unless given `--follow-symlinks`, which lists each symlink to a file under
|
||||
its own name with the contents of the file it points to
|
||||
- `mfer gen --sign-key key.asc` / `mfer freshen --sign-key key.asc`
|
||||
- signs the manifest with the OpenPGP secret key in `key.asc`, armored or
|
||||
binary, as `gpg --export-secret-keys` writes it; `MFER_SIGN_KEY` names the
|
||||
file too. mfer signs it itself and does not need `gpg`. A file holding
|
||||
more than one key is refused, and a key held only on a smartcard cannot
|
||||
sign. The key must be a version 4 key, whose 40-character fingerprint is
|
||||
what `--require-signature` takes, and not a DSA key. A key that cannot
|
||||
sign, because it has expired or been revoked or its passphrase is wrong,
|
||||
stops `gen` and `freshen` before they read any file
|
||||
- takes a protected key's passphrase from `MFER_SIGN_KEY_PASSPHRASE`, or
|
||||
else asks for it at the terminal
|
||||
- `mfer fetch https://example.com/stuff/`
|
||||
- fetches `/stuff/index.mf` and downloads all files listed in manifest into
|
||||
the current directory, or the one given with `--dest`, and assures
|
||||
|
||||
Reference in New Issue
Block a user