commit a48ca25841777916f6247cb6c5a17e505a5f1e90 Author: Pablo Ovelleiro Corral Date: Wed Mar 20 20:34:29 2024 +0100 initial commit diff --git a/go.mod b/go.mod new file mode 100644 index 0000000..5891455 --- /dev/null +++ b/go.mod @@ -0,0 +1,15 @@ +module gpg2age + +go 1.21.7 + +require ( + github.com/Mic92/ssh-to-age v0.0.0-20240304065525-796b05d6e3b3 + github.com/ProtonMail/go-crypto v1.0.0 + github.com/davecgh/go-spew v1.1.1 + golang.org/x/crypto v0.20.0 +) + +require ( + github.com/cloudflare/circl v1.3.3 // indirect + golang.org/x/sys v0.17.0 // indirect +) diff --git a/go.sum b/go.sum new file mode 100644 index 0000000..64ef460 --- /dev/null +++ b/go.sum @@ -0,0 +1,56 @@ +github.com/Mic92/ssh-to-age v0.0.0-20240304065525-796b05d6e3b3 h1:YT+DB0TTQ/Li1AQOAAP20k2kCT3XndzsprKgTg5GCIc= +github.com/Mic92/ssh-to-age v0.0.0-20240304065525-796b05d6e3b3/go.mod h1:M/OUOt0/3WI/tYzEYBhQNyU5OB1YStcJEkUaTDnjxJI= +github.com/ProtonMail/go-crypto v1.0.0 h1:LRuvITjQWX+WIfr930YHG2HNfjR1uOfyf5vE0kC2U78= +github.com/ProtonMail/go-crypto v1.0.0/go.mod h1:EjAoLdwvbIOoOQr3ihjnSoLZRtE8azugULFRteWMNc0= +github.com/bwesterb/go-ristretto v1.2.3/go.mod h1:fUIoIZaG73pV5biE2Blr2xEzDoMj7NFEuV9ekS419A0= +github.com/cloudflare/circl v1.3.3 h1:fE/Qz0QdIGqeWfnwq0RE0R7MI51s0M2E4Ga9kq5AEMs= +github.com/cloudflare/circl v1.3.3/go.mod h1:5XYMA4rFBvNIrhs50XuiBJ15vF2pZn4nnUKZrLbUZFA= +github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= +github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= +github.com/yuin/goldmark v1.4.13/go.mod h1:6yULJ656Px+3vBD8DxQVa3kxgyrAnzto9xy5taEt/CY= +golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= +golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= +golang.org/x/crypto v0.3.1-0.20221117191849-2c476679df9a/go.mod h1:hebNnKkNXi2UzZN1eVRvBB7co0a+JxK6XbPiWVs/3J4= +golang.org/x/crypto v0.7.0/go.mod h1:pYwdfH91IfpZVANVyUOhSIPZaFoJGxTFbZhFTx+dXZU= +golang.org/x/crypto v0.20.0 h1:jmAMJJZXr5KiCw05dfYK9QnqaqKLYXijU23lsEdcQqg= +golang.org/x/crypto v0.20.0/go.mod h1:Xwo95rrVNIoSMx9wa1JroENMToLWn3RNVrTBpLHgZPQ= +golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4= +golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= +golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= +golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg= +golang.org/x/net v0.0.0-20220722155237-a158d28d115b/go.mod h1:XRhObCWvk6IyKnWLug+ECip1KBveYUHfp+8e9klMJ9c= +golang.org/x/net v0.2.0/go.mod h1:KqCZLdyyvdV855qA2rE3GC2aiw5xGR5TEjj8smXukLY= +golang.org/x/net v0.6.0/go.mod h1:2Tu9+aMcznHK/AK1HMvgo6xiTLG5rD5rZLDS+rp2Bjs= +golang.org/x/net v0.8.0/go.mod h1:QVkue5JL9kW//ek3r6jTKnTFis1tRmNAW2P1shuFdJc= +golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.1.0/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= +golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.2.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.3.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.17.0 h1:25cE3gD+tdBA7lp7QfhuV+rJiE9YXTcS3VG1SqssI/Y= +golang.org/x/sys v0.17.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA= +golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= +golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8= +golang.org/x/term v0.2.0/go.mod h1:TVmDHMZPmdnySmBfhjOoOdhjzdE1h4u1VwSiw2l1Nuc= +golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k= +golang.org/x/term v0.6.0/go.mod h1:m6U89DPEgQRMq3DNkDClhWw02AUbt2daBVO4cn4Hv9U= +golang.org/x/term v0.17.0 h1:mkTF7LCd6WGJNL3K1Ad7kwxNfYAW6a8a8QqtMblp/4U= +golang.org/x/term v0.17.0/go.mod h1:lLRBjIVuehSbZlaOtGMbcMncT+aqLLLmKrsjNrUguwk= +golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= +golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= +golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ= +golang.org/x/text v0.4.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= +golang.org/x/text v0.7.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= +golang.org/x/text v0.8.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8= +golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= +golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= +golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc= +golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU= +golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= diff --git a/main.go b/main.go new file mode 100644 index 0000000..309c09f --- /dev/null +++ b/main.go @@ -0,0 +1,112 @@ +package main + +import ( + // "bytes" + "crypto/sha512" + "fmt" + "log" + "os" + + "github.com/ProtonMail/go-crypto/openpgp" + "github.com/ProtonMail/go-crypto/openpgp/armor" + "github.com/ProtonMail/go-crypto/openpgp/eddsa" + "github.com/ProtonMail/go-crypto/openpgp/packet" + "github.com/davecgh/go-spew/spew" + "golang.org/x/crypto/ssh" + + "strings" + + "crypto/ed25519" + "errors" + "reflect" + + // "filippo.io/edwards25519" + "github.com/Mic92/ssh-to-age/bech32" + "golang.org/x/crypto/curve25519" + // "golang.org/x/crypto/curve25519" +) + +func readEntity(keypath string) (*openpgp.Entity, error) { + f, err := os.Open(keypath) + if err != nil { + log.Println("Error opening file") + return nil, err + } + defer f.Close() + block, err := armor.Decode(f) + if err != nil { + log.Println("decoding") + return nil, err + } + return openpgp.ReadEntity(packet.NewReader(block.Body)) +} + +var ( + UnsupportedKeyType = errors.New("only ed25519 keys are supported") +) + +func ed25519PrivateKeyToCurve25519(pk ed25519.PrivateKey) ([]byte, error) { + h := sha512.New() + _, err := h.Write(pk.Seed()) + if err != nil { + return []byte{}, err + } + out := h.Sum(nil) + return out[:curve25519.ScalarSize], nil +} + +func SSHPrivateKeyToAge(sshKey, passphrase []byte) (*string, error) { + var ( + privateKey interface{} + err error + ) + if len(passphrase) > 0 { + privateKey, err = ssh.ParseRawPrivateKeyWithPassphrase(sshKey, passphrase) + } else { + privateKey, err = ssh.ParseRawPrivateKey(sshKey) + } + if err != nil { + return nil, fmt.Errorf("failed to parse ssh private key: %w", err) + } + + ed25519Key, ok := privateKey.(*ed25519.PrivateKey) + if !ok { + return nil, fmt.Errorf("got %s key type but: %w", reflect.TypeOf(privateKey), UnsupportedKeyType) + } + + bytes, err := ed25519PrivateKeyToCurve25519(*ed25519Key) //THIS + if err != nil { + return nil, err + } + + s, err := bech32.Encode("AGE-SECRET-KEY-", bytes) + if err != nil { + return nil, err + } + s = strings.ToUpper(s) + return &s, nil +} + +func main() { + + e, err := readEntity("test-key.asc") + if err != nil { + log.Fatal(err) + } + + log.Println(reflect.TypeOf(e.PrivateKey.PrivateKey)) + + castkey, ok := e.PrivateKey.PrivateKey.(*eddsa.PrivateKey) + if !ok { + log.Fatal("failed to cast") + } + spew.Dump(castkey) + + agekey, err := SSHPrivateKeyToAge(castkey.D, []byte{}) + + if err != nil { + log.Fatal(err) + } + log.Println(agekey) + +} diff --git a/test-key.asc b/test-key.asc new file mode 100644 index 0000000..28b6294 --- /dev/null +++ b/test-key.asc @@ -0,0 +1,15 @@ +-----BEGIN PGP PRIVATE KEY BLOCK----- + +lFgEZfs3+hYJKwYBBAHaRw8BAQdA84KtNLJxo2+ouxNljoM1WFWFgQ8p5OruK9wF +VciSD88AAQCk+SB8eNvB8Hlh5DZaDa6/CmIlVn4mUvtfEJiHeG2FOg8QtBR0ZXN0 +IDx0ZXN0QHRlc3QuY29tPoiZBBMWCgBBFiEEtlDulB3vc9KgkwiDlRKRhMfGt/wF +AmX7N/oCGwMFCQWjmoAFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQlRKR +hMfGt/xSBwEAqCZ8UZy757lz9ydWTM0DmlS6f2uCrnKZrtdl6R9Gr5UA/itADi8T +wvjQNE7AuNC8f4vTo6j5oyNn3EcirKewQ6oPnF0EZfs3+hIKKwYBBAGXVQEFAQEH +QDBidLlxD/45Qm/ptsndH9sO+KyJmTMFvDrEa8PuI1pAAwEIBwAA/2vJFIBIXPfo +J/uKbcYQtuFqkxhQIHXZCVz1u/bmlPLQEuqIfgQYFgoAJhYhBLZQ7pQd73PSoJMI +g5USkYTHxrf8BQJl+zf6AhsMBQkFo5qAAAoJEJUSkYTHxrf8oSMA/2kGBPEiL6lm +4lJnV4Sju5XlhQgtJ1gMoXQd90xHyyL1AP4h+cq+z6vDMV0epoIw85PU1aNlfKoE +551zUvwEsJa0Ag== +=UGWS +-----END PGP PRIVATE KEY BLOCK-----