-
-
Notifications
You must be signed in to change notification settings - Fork 12
/
Copy pathauth_pkcs11.go
100 lines (83 loc) · 2.09 KB
/
auth_pkcs11.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
// Copyright (c) 2021 Blacknon. All rights reserved.
// Use of this source code is governed by an MIT license
// that can be found in the LICENSE file.
//go:build cgo
// +build cgo
package sshlib
import (
"errors"
"os"
"github.com/miekg/pkcs11"
"golang.org/x/crypto/ssh"
)
// CreateAuthMethodPKCS11 return []ssh.AuthMethod generated from pkcs11 token.
// PIN is required to generate a AuthMethod from a PKCS 11 token.
// Not available if cgo is disabled.
//
// WORNING: Does not work if multiple tokens are stuck at the same time.
func CreateAuthMethodPKCS11(provider, pin string) (auth []ssh.AuthMethod, err error) {
signers, err := CreateSignerPKCS11(provider, pin)
if err != nil {
return
}
for _, signer := range signers {
auth = append(auth, ssh.PublicKeys(signer))
}
return
}
// CreateSignerPKCS11 returns []ssh.Signer generated from PKCS11 token.
// PIN is required to generate a Signer from a PKCS 11 token.
// Not available if cgo is disabled.
//
// WORNING: Does not work if multiple tokens are stuck at the same time.
func CreateSignerPKCS11(provider, pin string) (signers []ssh.Signer, err error) {
// get absolute path
provider = getAbsPath(provider)
// Check exist provider
if _, err = os.Stat(provider); errors.Is(err, os.ErrNotExist) {
return
}
ctx := pkcs11.New(provider)
err = ctx.Initialize()
if err != nil {
ctx.Destroy()
ctx.Finalize()
return
}
slots, err := ctx.GetSlotList(true)
if err != nil {
ctx.Destroy()
ctx.Finalize()
return
}
c11array := []*C11{}
for _, slot := range slots {
tokenInfo, err := ctx.GetTokenInfo(slot)
if err != nil {
continue
}
c := &C11{
Label: tokenInfo.Label,
PIN: pin,
}
c11array = append(c11array, c)
}
// for loop
for _, c11 := range c11array {
err := c11.CreateCtx(ctx)
if err != nil {
// TODO: errorをなにかしらの形で返す
continue
}
sigs, err := c11.GetSigner()
if err != nil {
// TODO: errorをなにかしらの形で返す
continue
}
for _, sig := range sigs {
signer, _ := ssh.NewSignerFromSigner(sig)
signers = append(signers, signer)
}
}
return
}