Fix SSH public key format: use ssh.MarshalAuthorizedKey

Bug: raw ed25519.PublicKey bytes were stored directly instead of
OpenSSH authorized-key format (ssh-ed25519 AAAA... label).

Fixes:
- internal/sshmanager/fingerprint.go: GenerateKeyPair now uses
  ssh.NewPublicKey + ssh.MarshalAuthorizedKey
- internal/sshmanager/keys.go: EnsureServerKey uses same fix; also
  regenerates .pub file from private key if stored value is corrupt
- internal/sshmanager/fingerprint.go: add MarshalED25519PublicKey,
  PublicKeyFromPrivateKeyFile, RegeneratePublicKeyFromPrivateKeyFile
- internal/models/sshkey.go: add UpdatePublicKey
- internal/api/handlers_sshkeys.go: List+Get recover existing DB
  records with corrupt public keys by regenerating from private key
  file and updating the DB

Also adds golang.org/x/crypto/ssh dependency via go mod tidy.
This commit is contained in:
2026-07-08 00:30:57 -04:00
parent e322299dc3
commit 8d0117399c
9 changed files with 118 additions and 8 deletions
BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
+8 -5
View File
@@ -2,19 +2,22 @@ module github.com/syncserver
go 1.25.0
require (
github.com/go-chi/chi/v5 v5.1.0
github.com/golang-jwt/jwt/v5 v5.2.1
golang.org/x/crypto v0.31.0
gopkg.in/yaml.v3 v3.0.1
modernc.org/sqlite v1.53.0
)
require (
github.com/dustin/go-humanize v1.0.1 // indirect
github.com/go-chi/chi/v5 v5.1.0 // indirect
github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
github.com/google/uuid v1.6.0 // indirect
github.com/mattn/go-isatty v0.0.20 // indirect
github.com/ncruces/go-strftime v1.0.0 // indirect
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
golang.org/x/crypto v0.31.0 // indirect
golang.org/x/sys v0.44.0 // indirect
gopkg.in/yaml.v3 v3.0.1 // indirect
modernc.org/libc v1.73.4 // indirect
modernc.org/mathutil v1.7.1 // indirect
modernc.org/memory v1.11.0 // indirect
modernc.org/sqlite v1.53.0 // indirect
)
+33
View File
@@ -4,8 +4,12 @@ github.com/go-chi/chi/v5 v5.1.0 h1:acVI1TYaD+hhedDJ3r54HyA6sExp3HfXq7QWEEY/xMw=
github.com/go-chi/chi/v5 v5.1.0/go.mod h1:DslCQbL2OYiznFReuXYUmQ2hGd1aDpCnlMNITLSKoi8=
github.com/golang-jwt/jwt/v5 v5.2.1 h1:OuVbFODueb089Lh128TAcimifWaLhJwVflnrgM17wHk=
github.com/golang-jwt/jwt/v5 v5.2.1/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
github.com/google/pprof v0.0.0-20250317173921-a4b03ec1a45e h1:ijClszYn+mADRFY17kjQEVQ1XRhq2/JR1M3sGqeJoxs=
github.com/google/pprof v0.0.0-20250317173921-a4b03ec1a45e/go.mod h1:boTsfXsheKC2y+lKOCMpSfarhxDeIzfZG1jqGcPl3cA=
github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
github.com/hashicorp/golang-lru/v2 v2.0.7 h1:a+bsQ5rvGLjzHuww6tVxozPZFVghXaHOwFs4luLUK2k=
github.com/hashicorp/golang-lru/v2 v2.0.7/go.mod h1:QeFd9opnmA6QUJc5vARoKUSoFhyfM2/ZepoAG6RGpeM=
github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
github.com/ncruces/go-strftime v1.0.0 h1:HMFp8mLCTPp341M/ZnA4qaf7ZlsbTc+miZjCLOFAw7w=
@@ -14,17 +18,46 @@ github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo=
golang.org/x/crypto v0.31.0 h1:ihbySMvVjLAeSH1IbfcRTkD/iNscyz8rGzjF/E5hV6U=
golang.org/x/crypto v0.31.0/go.mod h1:kDsLvtWBEx7MV9tJOj9bnXsPbxwJQ6csT/x4KIN4Ssk=
golang.org/x/mod v0.36.0 h1:JJjpVx6myfUsUdAzZuOSTTmRE0PfZeNWzzvKrP7amb4=
golang.org/x/mod v0.36.0/go.mod h1:moc6ELqsWcOw5Ef3xVprK5ul/MvtVvkIXLziUOICjUQ=
golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4=
golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.44.0 h1:ildZl3J4uzeKP07r2F++Op7E9B29JRUy+a27EibtBTQ=
golang.org/x/sys v0.44.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/term v0.27.0 h1:WP60Sv1nlK1T6SupCHbXzSaN0b9wUmsPoRS9b61A23Q=
golang.org/x/term v0.27.0/go.mod h1:iMsnZpn0cago0GOrHO2+Y7u7JPn5AylBrcoWkElMTSM=
golang.org/x/tools v0.45.0 h1:18qN3FAooORvApf5XjCXgsuayZOEtXf6JK18I3+ONa8=
golang.org/x/tools v0.45.0/go.mod h1:LuUGqqaXcXMEFEruIVJVm5mgDD8vww/z/SR1gQ4uE/0=
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405 h1:yhCVgyC4o1eVCa2tZl7eS0r+SDo693bJlVdllGtEeKM=
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
modernc.org/cc/v4 v4.28.4 h1:Hd/4Es+MBj+/7hSdZaisNyu6bv3V0Dp2MdllyfqaH+c=
modernc.org/cc/v4 v4.28.4/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI=
modernc.org/ccgo/v4 v4.34.4 h1:OVnSOWQjVKOYkFxoHYB+qQmSHK5gqMqARM+K9DpR/Ws=
modernc.org/ccgo/v4 v4.34.4/go.mod h1:qdKqE8FNIYyysougB1RX9MxCzp5oJOcQXSobANJ4TuE=
modernc.org/fileutil v1.4.0 h1:j6ZzNTftVS054gi281TyLjHPp6CPHr2KCxEXjEbD6SM=
modernc.org/fileutil v1.4.0/go.mod h1:EqdKFDxiByqxLk8ozOxObDSfcVOv/54xDs/DUHdvCUU=
modernc.org/gc/v2 v2.6.5 h1:nyqdV8q46KvTpZlsw66kWqwXRHdjIlJOhG6kxiV/9xI=
modernc.org/gc/v2 v2.6.5/go.mod h1:YgIahr1ypgfe7chRuJi2gD7DBQiKSLMPgBQe9oIiito=
modernc.org/gc/v3 v3.1.3 h1:6QAplYyVO+KdPW3pGnqmJDUxtkec8ooEWvks/hhU3lc=
modernc.org/gc/v3 v3.1.3/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY=
modernc.org/goabi0 v0.2.0 h1:HvEowk7LxcPd0eq6mVOAEMai46V+i7Jrj13t4AzuNks=
modernc.org/goabi0 v0.2.0/go.mod h1:CEFRnnJhKvWT1c1JTI3Avm+tgOWbkOu5oPA8eH8LnMI=
modernc.org/libc v1.73.4 h1:+ra4Ui8ngyt8HDcO1FTDPWlkAh6yOdaO2yAoh8MddQA=
modernc.org/libc v1.73.4/go.mod h1:DXZ3eO8qMCNn2SnmTNCiC71nJ9Rcq3PsnpU6Vc4rWK8=
modernc.org/mathutil v1.7.1 h1:GCZVGXdaN8gTqB1Mf/usp1Y/hSqgI2vAGGP4jZMCxOU=
modernc.org/mathutil v1.7.1/go.mod h1:4p5IwJITfppl0G4sUEDtCr4DthTaT47/N3aT6MhfgJg=
modernc.org/memory v1.11.0 h1:o4QC8aMQzmcwCK3t3Ux/ZHmwFPzE6hf2Y5LbkRs+hbI=
modernc.org/memory v1.11.0/go.mod h1:/JP4VbVC+K5sU2wZi9bHoq2MAkCnrt2r98UGeSK7Mjw=
modernc.org/opt v0.2.0 h1:tGyef5ApycA7FSEOMraay9SaTk5zmbx7Tu+cJs4QKZg=
modernc.org/opt v0.2.0/go.mod h1:03fq9lsNfvkYSfxrfUhZCWPk1lm4cq4N+Bh//bEtgns=
modernc.org/sortutil v1.2.1 h1:+xyoGf15mM3NMlPDnFqrteY07klSFxLElE2PVuWIJ7w=
modernc.org/sortutil v1.2.1/go.mod h1:7ZI3a3REbai7gzCLcotuw9AC4VZVpYMjDzETGsSMqJE=
modernc.org/sqlite v1.53.0 h1:20WG8N9q4ji/dEqGk4uiI0c6OPjSeLTNYGFCc3+7c1M=
modernc.org/sqlite v1.53.0/go.mod h1:xoEpOIpGrgT48H5iiyt/YXPCZPEzlfmfFwtk8Lklw8s=
modernc.org/strutil v1.2.1 h1:UneZBkQA+DX2Rp35KcM69cSsNES9ly8mQWD71HKlOA0=
modernc.org/strutil v1.2.1/go.mod h1:EHkiggD70koQxjVdSBM3JKM7k6L0FbGE5eymy9i3B9A=
modernc.org/token v1.1.0 h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y=
modernc.org/token v1.1.0/go.mod h1:UGzOrNV1mAFSEB63lOFHIpNRUVMvYTc6yu1SMY/XTDM=
+12
View File
@@ -51,6 +51,12 @@ func (h *SSHKeyHandler) List(w http.ResponseWriter, r *http.Request) {
hasPriv = true
}
fp, _ := sshmanager.Fingerprint(k.PublicKey)
if fp == "" && hasPriv {
pubKey, newFP, _ := sshmanager.RegeneratePublicKeyFromPrivateKeyFile(k.PrivateKeyPath, k.Label)
repo.UpdatePublicKey(k.ID, pubKey)
k.PublicKey = pubKey
fp = newFP
}
out[i] = SSHKeyResponse{
ID: k.ID,
Label: k.Label,
@@ -151,6 +157,12 @@ func (h *SSHKeyHandler) Get(w http.ResponseWriter, r *http.Request) {
hasPriv = true
}
fp, _ := sshmanager.Fingerprint(k.PublicKey)
if fp == "" && hasPriv {
pubKey, newFP, _ := sshmanager.RegeneratePublicKeyFromPrivateKeyFile(k.PrivateKeyPath, k.Label)
repo.UpdatePublicKey(k.ID, pubKey)
k.PublicKey = pubKey
fp = newFP
}
writeJSON(w, SSHKeyResponse{
ID: k.ID,
Label: k.Label,
+5
View File
@@ -68,6 +68,11 @@ func (r *SSHKeyRepository) Delete(id int64) error {
return err
}
func (r *SSHKeyRepository) UpdatePublicKey(id int64, pubKey string) error {
_, err := r.db.Exec("UPDATE ssh_keys SET public_key = ? WHERE id = ?", pubKey, id)
return err
}
func (r *SSHKeyRepository) GetServerKey() (*SSHKey, error) {
var k SSHKey
err := r.db.QueryRow(
+41 -1
View File
@@ -11,8 +11,44 @@ import (
"os"
"path/filepath"
"strings"
"golang.org/x/crypto/ssh"
)
func MarshalED25519PublicKey(pub ed25519.PublicKey) (string, error) {
sshPubKey, err := ssh.NewPublicKey(pub)
if err != nil {
return "", err
}
return strings.TrimSpace(string(ssh.MarshalAuthorizedKey(sshPubKey))), nil
}
func RegeneratePublicKeyFromPrivateKeyFile(privPath, label string) (string, string, error) {
sshPubKey, err := PublicKeyFromPrivateKeyFile(privPath)
if err != nil {
return "", "", err
}
pubKey := sshPubKey + " " + label
fp, _ := Fingerprint(pubKey)
return pubKey, fp, nil
}
func PublicKeyFromPrivateKeyFile(privPath string) (string, error) {
data, err := os.ReadFile(privPath)
if err != nil {
return "", err
}
block, _ := pem.Decode(data)
if block == nil {
return "", fmt.Errorf("no PEM block in private key file")
}
signer, err := ssh.ParsePrivateKey(data)
if err != nil {
return "", fmt.Errorf("parsing private key: %w", err)
}
return strings.TrimSpace(string(ssh.MarshalAuthorizedKey(signer.PublicKey()))), nil
}
func Fingerprint(publicKey string) (string, error) {
pubKey := strings.TrimSpace(publicKey)
parts := strings.Fields(pubKey)
@@ -80,7 +116,11 @@ func GenerateKeyPair(label string, sshDir string) (privPath, pubPath, pubKey, fi
return "", "", "", "", fmt.Errorf("marshaling private key: %w", err)
}
pem.Encode(privFile, &pem.Block{Type: "PRIVATE KEY", Bytes: privBytes})
pubKey = fmt.Sprintf("%s %s", strings.TrimSpace(string(pub)), label)
sshPubKey, err := ssh.NewPublicKey(pub)
if err != nil {
return "", "", "", "", fmt.Errorf("wrapping public key: %w", err)
}
pubKey = strings.TrimSpace(string(ssh.MarshalAuthorizedKey(sshPubKey))) + " " + label
if err := os.WriteFile(pubPath, []byte(pubKey), 0644); err != nil {
return "", "", "", "", fmt.Errorf("writing public key: %w", err)
}
+19 -2
View File
@@ -9,6 +9,8 @@ import (
"os"
"path/filepath"
"strings"
"golang.org/x/crypto/ssh"
)
const ServerKeyLabel = "server"
@@ -39,7 +41,11 @@ func EnsureServerKey(sshDir string) (privPath, pubPath string, pubKey string, er
}
pem.Encode(privFile, &pem.Block{Type: "PRIVATE KEY", Bytes: privBytes})
pubKey = fmt.Sprintf("%s %s", strings.TrimSpace(string(pub)), "syncserver")
sshPubKey, err := ssh.NewPublicKey(pub)
if err != nil {
return "", "", "", fmt.Errorf("wrapping public key: %w", err)
}
pubKey = strings.TrimSpace(string(ssh.MarshalAuthorizedKey(sshPubKey))) + " syncserver"
if err := os.WriteFile(pubPath, []byte(pubKey), 0644); err != nil {
return "", "", "", fmt.Errorf("writing public key: %w", err)
}
@@ -52,7 +58,18 @@ func EnsureServerKey(sshDir string) (privPath, pubPath string, pubKey string, er
if err != nil {
return "", "", "", fmt.Errorf("reading public key: %w", err)
}
return privPath, pubPath, strings.TrimSpace(string(data)), nil
pubKey = strings.TrimSpace(string(data))
if _, err := Fingerprint(pubKey); err != nil {
sshPubKey, err := PublicKeyFromPrivateKeyFile(privPath)
if err != nil {
return "", "", "", fmt.Errorf("recovering public key: %w", err)
}
pubKey = sshPubKey + " syncserver"
if err := os.WriteFile(pubPath, []byte(pubKey), 0644); err != nil {
return "", "", "", fmt.Errorf("rewriting public key: %w", err)
}
}
return privPath, pubPath, pubKey, nil
}
func ReadPrivateKey(path string) ([]byte, error) {
Executable
BIN
View File
Binary file not shown.