forked from gravitational/teleport
-
Notifications
You must be signed in to change notification settings - Fork 0
/
sshca.go
44 lines (34 loc) · 1.63 KB
/
sshca.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
/*
Copyright 2017 Gravitational, Inc.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
// Package sshca specifies interfaces for SSH certificate authorities
package sshca
import (
"github.com/gravitational/teleport/lib/services"
)
// Authority implements minimal key-management facility for generating OpenSSH
// compatible public/private key pairs and OpenSSH certificates
type Authority interface {
// GenerateKeyPair generates new keypair
GenerateKeyPair(passphrase string) (privKey []byte, pubKey []byte, err error)
// GetNewKeyPairFromPool returns new keypair from pre-generated in memory pool
GetNewKeyPairFromPool() (privKey []byte, pubKey []byte, err error)
// GenerateHostCert takes the private key of the CA, public key of the new host,
// along with metadata (host ID, node name, cluster name, roles, and ttl) and generates
// a host certificate.
GenerateHostCert(certParams services.HostCertParams) ([]byte, error)
// GenerateUserCert generates user certificate, it takes pkey as a signing
// private key (user certificate authority)
GenerateUserCert(certParams services.UserCertParams) ([]byte, error)
// Close will close the key-management facility.
Close()
}