linux support - #40
Conversation
| @@ -0,0 +1,305 @@ | |||
| package secretservice | |||
There was a problem hiding this comment.
We should probably use
// +build linux
for this.
There was a problem hiding this comment.
You can use dbus on OSX if you want to, is it ok to leave it off? In the client this package will only be imported under +build linux
| // variables and methods are not exported or easily accessible. | ||
| // Note that this protocol is NOT authenticated, NOT secure against malleation | ||
| // and is NOT CCA2-secure. It is only meant to hide the D-Bus messages from any | ||
| // system services that may be logging everything. |
There was a problem hiding this comment.
Could you add some unit tests for these functions? If a lot of this is borrowed from crypto/ssh, are there tests from that package that we can also borrow?
| type authenticationMode string | ||
|
|
||
| const AuthenticationPlain authenticationMode = "plain" | ||
| const AuthenticationDHIETF1024SHA256AES128CBCPKCS7 authenticationMode = "dh-ietf1024-sha256-aes128-cbc-pkcs7" |
There was a problem hiding this comment.
this is quite a constant name... AuthenticationEncrypted? AuthenticationDH?
|
|
||
| switch mode { | ||
| case AuthenticationPlain: | ||
| sessionAlgorithmInput = dbus.MakeVariant("") |
There was a problem hiding this comment.
What does AuthenticationPlain mean? Is the secret stored in plaintext? If so, can we not support that mode?
There was a problem hiding this comment.
The secret is encrypted with the user's keyring password (configured whenever the user set up their keyring). This is just for encrypting the communication between keybase and the keyring, since it's possible something might be logging dbus message history. That's why it doesn't need to be authenticated. I can still remove it if you think it's a good idea though.
There was a problem hiding this comment.
That's fine, just making sure we weren't supporting a plaintext storage system.
| return new(big.Int).Exp(theirPublic, myPrivate, group.p), nil | ||
| } | ||
|
|
||
| func RFC2409SecondOakleyGroup() *dhGroup { |
There was a problem hiding this comment.
golint is going to complain that RFC2409SecondOakleyGroup is exported but is not returning an exported type.
| AESKey []byte | ||
| } | ||
|
|
||
| func NewService() (*SecretService, error) { |
There was a problem hiding this comment.
It would be great to have tests for this too. I assume they will only work on linux, so add
// +build linux
to the test file.
There was a problem hiding this comment.
I can add tests but I don't think they'll work in CI since the system needs to have a keyring running, is that ok?
a921bee to
db4baae
Compare
|
ok @patrickxb, added tests. keyring integration tests are skipped in CI |
Addresses keybase/client#16564.