]> Sergey Matveev's repositories - tofuproxy.git/commitdiff
Use faster modern EdDSA-based certificates
authorSergey Matveev <stargrave@stargrave.org>
Sun, 19 Mar 2023 19:02:35 +0000 (22:02 +0300)
committerSergey Matveev <stargrave@stargrave.org>
Sun, 19 Mar 2023 19:04:24 +0000 (22:04 +0300)
cmd/certgen/main.go
x509.go

index fda7232ade82797ddd382ffbd47e2f5e2d22a79e..e9a5cb1367c75f93e12a5a191b69489d309d56a9 100644 (file)
@@ -19,8 +19,7 @@ along with this program.  If not, see <http://www.gnu.org/licenses/>.
 package main
 
 import (
-       "crypto/ecdsa"
-       "crypto/elliptic"
+       "crypto/ed25519"
        "crypto/rand"
        "crypto/x509"
        "crypto/x509/pkix"
@@ -38,11 +37,10 @@ func main() {
        flag.Parse()
        log.SetFlags(log.Lshortfile)
 
-       prv, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
+       pub, prv, err := ed25519.GenerateKey(rand.Reader)
        if err != nil {
                log.Fatalln(err)
        }
-       pub := prv.Public()
        notBefore := time.Now()
        notAfter := notBefore.Add(365 * 24 * time.Hour)
 
diff --git a/x509.go b/x509.go
index 6c3923257759e4dd80846f6240400781afac59da..4dafb908383eb894ef68348c8804c77da4363756 100644 (file)
--- a/x509.go
+++ b/x509.go
@@ -20,8 +20,7 @@ package tofuproxy
 
 import (
        "crypto"
-       "crypto/ecdsa"
-       "crypto/elliptic"
+       "crypto/ed25519"
        "crypto/rand"
        "crypto/x509"
        "crypto/x509/pkix"
@@ -57,11 +56,10 @@ func newKeypair(
        caCert *x509.Certificate,
        caPrv crypto.PrivateKey,
 ) *Keypair {
-       prv, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
+       pub, prv, err := ed25519.GenerateKey(rand.Reader)
        if err != nil {
                log.Fatalln(err)
        }
-       pub := prv.Public()
        notBefore := time.Now()
        notAfter := notBefore.Add(24 * time.Hour)
        Serial = Serial.Add(Serial, big.NewInt(1))