]> Sergey Matveev's repositories - tofuproxy.git/blobdiff - x509.go
Ability to choose ECDSA/EdDSA algorithms
[tofuproxy.git] / x509.go
diff --git a/x509.go b/x509.go
index 6c3923257759e4dd80846f6240400781afac59da..f18b2195dbd9c4acffefb1a356aebe7a6027f6b2 100644 (file)
--- a/x509.go
+++ b/x509.go
@@ -21,6 +21,7 @@ package tofuproxy
 import (
        "crypto"
        "crypto/ecdsa"
+       "crypto/ed25519"
        "crypto/elliptic"
        "crypto/rand"
        "crypto/x509"
@@ -31,15 +32,16 @@ import (
        "time"
 )
 
-type Keypair struct {
+type X509Keypair struct {
        cert *x509.Certificate
        prv  crypto.PrivateKey
 }
 
 var (
-       hostCerts  = make(map[string]*Keypair)
+       hostCerts  = make(map[string]*X509Keypair)
        hostCertsM sync.Mutex
        Serial     *big.Int
+       X509Algo   string
 )
 
 func init() {
@@ -52,16 +54,33 @@ func init() {
        }
 }
 
-func newKeypair(
+func NewKeypair(ai string) (pub, prv any) {
+       switch ai {
+       case "ecdsa":
+               prvEcdsa, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
+               if err != nil {
+                       log.Fatalln(err)
+               }
+               prv = prvEcdsa
+               pub = prvEcdsa.Public()
+       case "eddsa":
+               var err error
+               pub, prv, err = ed25519.GenerateKey(rand.Reader)
+               if err != nil {
+                       log.Fatalln(err)
+               }
+       default:
+               log.Fatalln("unknown algorithm specified")
+       }
+       return
+}
+
+func newX509Keypair(
        host string,
        caCert *x509.Certificate,
        caPrv crypto.PrivateKey,
-) *Keypair {
-       prv, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
-       if err != nil {
-               log.Fatalln(err)
-       }
-       pub := prv.Public()
+) *X509Keypair {
+       pub, prv := NewKeypair(X509Algo)
        notBefore := time.Now()
        notAfter := notBefore.Add(24 * time.Hour)
        Serial = Serial.Add(Serial, big.NewInt(1))
@@ -82,5 +101,5 @@ func newKeypair(
        if err != nil {
                log.Fatalln(err)
        }
-       return &Keypair{cert, prv}
+       return &X509Keypair{cert, prv}
 }