Commit e55a4bd
Consolidate cryptographic keys: use ed25519 master key for both JWT and ECDH
This commit refactors the key management to use a single ed25519 master
key for both JWT signing and ECDH key exchange:
Changes:
- Created keyservice package to manage the master ed25519 key
- Implemented ed25519 to x25519 key derivation following RFC 7748
- Private key: hash ed25519 seed and apply Curve25519 clamping
- Public key: convert Edwards curve point to Montgomery curve
- Updated JWT service to accept keys instead of managing its own
- Updated app.go to use keyservice for both JWT and cryptocodec
- Removed duplicate key generation functions (generateKeyPair, getKeyPair, etc.)
- Removed separate storage keys:
- Old: tavern_jwt_ed25519_private_key (JWT only)
- Old: tavern_encryption_private_key (ECDH only)
- New: tavern_master_ed25519_key (both JWT and derived ECDH)
Benefits:
- Single source of truth for cryptographic keys
- Ed25519 master key enables both signing (JWT) and ECDH (x25519)
- Simpler key management with one persistent key
- Maintains backward compatibility with existing x25519 ECDH protocol1 parent f3d6147 commit e55a4bd
3 files changed
+202
-162
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
6 | | - | |
7 | | - | |
8 | | - | |
9 | 5 | | |
10 | 6 | | |
11 | 7 | | |
| |||
35 | 31 | | |
36 | 32 | | |
37 | 33 | | |
| 34 | + | |
38 | 35 | | |
39 | 36 | | |
40 | 37 | | |
41 | | - | |
42 | 38 | | |
43 | 39 | | |
44 | 40 | | |
| |||
423 | 419 | | |
424 | 420 | | |
425 | 421 | | |
426 | | - | |
427 | | - | |
428 | | - | |
429 | | - | |
430 | | - | |
431 | | - | |
432 | | - | |
433 | | - | |
434 | | - | |
435 | | - | |
436 | | - | |
437 | | - | |
438 | | - | |
439 | | - | |
440 | | - | |
441 | | - | |
442 | | - | |
443 | | - | |
444 | | - | |
445 | | - | |
446 | | - | |
447 | | - | |
448 | | - | |
449 | | - | |
450 | | - | |
451 | | - | |
452 | | - | |
453 | | - | |
454 | | - | |
455 | | - | |
456 | | - | |
457 | | - | |
458 | | - | |
459 | | - | |
460 | | - | |
461 | | - | |
462 | | - | |
463 | | - | |
464 | | - | |
465 | | - | |
466 | | - | |
467 | | - | |
468 | | - | |
469 | | - | |
470 | | - | |
471 | | - | |
472 | | - | |
473 | | - | |
474 | | - | |
475 | | - | |
476 | | - | |
477 | | - | |
478 | | - | |
479 | | - | |
480 | | - | |
481 | | - | |
482 | | - | |
483 | | - | |
484 | | - | |
485 | | - | |
486 | | - | |
487 | | - | |
488 | | - | |
489 | | - | |
490 | | - | |
491 | | - | |
492 | | - | |
493 | | - | |
494 | | - | |
495 | | - | |
496 | | - | |
497 | | - | |
498 | | - | |
499 | | - | |
500 | | - | |
501 | | - | |
502 | | - | |
503 | | - | |
504 | | - | |
505 | 422 | | |
506 | 423 | | |
507 | 424 | | |
| |||
525 | 442 | | |
526 | 443 | | |
527 | 444 | | |
528 | | - | |
| 445 | + | |
| 446 | + | |
529 | 447 | | |
| 448 | + | |
530 | 449 | | |
531 | 450 | | |
532 | | - | |
533 | 451 | | |
534 | | - | |
535 | | - | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
536 | 462 | | |
537 | 463 | | |
538 | 464 | | |
539 | 465 | | |
540 | 466 | | |
541 | 467 | | |
542 | 468 | | |
543 | | - | |
| 469 | + | |
544 | 470 | | |
545 | 471 | | |
546 | 472 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
6 | | - | |
7 | 5 | | |
8 | | - | |
9 | | - | |
10 | 6 | | |
11 | 7 | | |
12 | 8 | | |
13 | | - | |
14 | 9 | | |
15 | 10 | | |
16 | 11 | | |
| |||
26 | 21 | | |
27 | 22 | | |
28 | 23 | | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
34 | 28 | | |
35 | 29 | | |
36 | | - | |
37 | | - | |
38 | | - | |
39 | | - | |
40 | | - | |
41 | | - | |
42 | | - | |
43 | | - | |
44 | | - | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
50 | | - | |
51 | | - | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | | - | |
56 | | - | |
57 | | - | |
58 | | - | |
59 | | - | |
60 | | - | |
61 | | - | |
62 | | - | |
63 | | - | |
64 | | - | |
65 | | - | |
66 | | - | |
67 | | - | |
68 | | - | |
69 | | - | |
70 | | - | |
71 | | - | |
72 | | - | |
73 | | - | |
74 | | - | |
75 | | - | |
76 | | - | |
77 | | - | |
78 | | - | |
79 | 30 | | |
80 | 31 | | |
81 | 32 | | |
| |||
129 | 80 | | |
130 | 81 | | |
131 | 82 | | |
132 | | - | |
133 | | - | |
134 | | - | |
135 | | - | |
136 | | - | |
137 | | - | |
138 | | - | |
139 | | - | |
140 | | - | |
141 | | - | |
142 | | - | |
143 | | - | |
144 | | - | |
145 | | - | |
146 | | - | |
147 | | - | |
148 | | - | |
149 | | - | |
150 | | - | |
151 | | - | |
0 commit comments