holgerfriedrich commented on code in PR #2927:
URL: https://github.com/apache/karaf/pull/2927#discussion_r4057200066
##########
jaas/modules/src/main/java/org/apache/karaf/jaas/modules/publickey/PublickeyLoginModule.java:
##########
@@ -239,6 +247,23 @@ public static boolean equals(PublicKey key, String
storedKey) throws FailedLogin
PublicKey generatedPublicKey =
keyFactory.generatePublic(keySpec);
return key.equals(generatedPublicKey);
+ } else if (ED25519_IDENTIFIER.equals(identifier)) {
+ // OpenSSH stores an ed25519 key as the raw 32 bytes of the
compressed point.
+ // The key implementation depends on the registered provider
(for instance
+ // BouncyCastle), so compare the X.509 encodings instead of
the key objects.
+ int size = dis.readInt();
+ if (size != ED25519_KEY_LENGTH) {
+ return false;
+ }
+ byte[] bytes = new byte[size];
+ dis.readFully(bytes);
+
+ KeyFactory keyFactory = KeyFactory.getInstance("Ed25519");
+ KeySpec publicKeySpec = new
X509EncodedKeySpec(x509Ed25519(bytes));
+ PublicKey generatedPublicKey =
keyFactory.generatePublic(publicKeySpec);
+
+ byte[] encoded = key.getEncoded();
+ return encoded != null && Arrays.equals(encoded,
generatedPublicKey.getEncoded());
Review Comment:
ok, done as requested
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]