aboutsummaryrefslogtreecommitdiff
path: root/load_private_key.go
blob: dcb145e3cbe1d241c8f825747139340e49e4075f (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
package main

import (
	"fmt"
	"os"

	"git.zero-knowledge.org/gibheer/pki"
)

func loadPrivateKey(path string) (pki.PrivateKey, error) {
	if path == "" {
		return nil, fmt.Errorf("no path given")
	}
	var err error
	file, err := os.Open(path)
	if err != nil {
		return nil, err
	}
	defer file.Close()
	info, err := file.Stat()
	if err != nil {
		return nil, err
	}
	if info.Mode().Perm().String()[4:] != "------" {
		return nil, fmt.Errorf("private key must not be readable for group or world")
	}

	pems, err := parseFile(file)
	if err != nil {
		return nil, fmt.Errorf("could not load private key: %s", err)
	}
	if len(pems) > 1 {
		return nil, fmt.Errorf("more than one object in file")
	}

	for key, parts := range pems {
		if len(parts) > 1 {
			return nil, fmt.Errorf("more than one object found")
		}
		switch key {
		case pki.PemLabelRsa:
			return pki.LoadPrivateKeyRsa(parts[0])
		case pki.PemLabelEd25519:
			return pki.LoadPrivateKeyEd25519(parts[0])
		case pki.PemLabelEcdsa:
			return pki.LoadPrivateKeyEcdsa(parts[0])
		}
	}
	return nil, fmt.Errorf("no private key found in file '%s'", path)
}