From b13a0c9e1a76a19701d394243ac7f1496580e6fb Mon Sep 17 00:00:00 2001 From: jgough Date: Wed, 27 Sep 2023 09:32:56 +0100 Subject: [PATCH 1/3] Add keyvault for key management AB#8503 --- azkeys/keyvault.go | 260 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 260 insertions(+) create mode 100644 azkeys/keyvault.go diff --git a/azkeys/keyvault.go b/azkeys/keyvault.go new file mode 100644 index 0000000..e1985f2 --- /dev/null +++ b/azkeys/keyvault.go @@ -0,0 +1,260 @@ +package azkeys + +/** + * KeyVault implements the azure keyvault API: + * + * https://learn.microsoft.com/en-us/rest/api/keyvault/ + */ + +import ( + "context" + "encoding/base64" + "fmt" + "strings" + + "github.com/Azure/azure-sdk-for-go/services/keyvault/2016-10-01/keyvault" + "github.com/Azure/go-autorest/autorest" + "github.com/rkvst/go-rkvstcommon/logger" +) + +// KeyVault is the azure keyvault client for interacting with keyvault keys +type KeyVault struct { + Name string + Authorizer autorest.Authorizer // optional, nil for production +} + +// NewKeyVault creates a new keyvault client +func NewKeyVault(keyvaultURL string) *KeyVault { + kv := KeyVault{ + Name: keyvaultURL, + } + + return &kv +} + +// GetKeyByKID gets the key by its KID +func (kv *KeyVault) GetKeyByKID( + ctx context.Context, kid string, +) (keyvault.KeyBundle, error) { + + log := logger.Sugar.FromContext(ctx) + defer log.Close() + + log.Infof("GetLatestKey: %s %s", kv.Name, kid) + + kvClient, err := NewKvClient(kv.Authorizer) + if err != nil { + return keyvault.KeyBundle{}, err + } + + keyName := GetKeyName(kid) + keyVersion := GetKeyVersion(kid) + + key, err := kvClient.GetKey(ctx, kv.Name, keyName, keyVersion) + if err != nil { + return keyvault.KeyBundle{}, fmt.Errorf("failed to read key: %w", err) + } + + return key, nil + +} + +// GetLatestKey returns the identified key +func (kv *KeyVault) GetLatestKey( + ctx context.Context, keyID string, +) (keyvault.KeyBundle, error) { + + log := logger.Sugar.FromContext(ctx) + defer log.Close() + + log.Infof("GetLatestKey: %s %s", kv.Name, keyID) + + kvClient, err := NewKvClient(kv.Authorizer) + if err != nil { + return keyvault.KeyBundle{}, err + } + + key, err := kvClient.GetKey(ctx, kv.Name, keyID, "") + if err != nil { + return keyvault.KeyBundle{}, fmt.Errorf("failed to read key: %w", err) + } + + return key, nil +} + +// GetKeyVersions returns all the keys for all the versions of the identified key. +// +// The keys returned are the public half of the asymetric keys +func (kv *KeyVault) GetKeyVersionsKeys( + ctx context.Context, keyID string, +) ([]keyvault.KeyBundle, error) { + + log := logger.Sugar.FromContext(ctx) + defer log.Close() + + log.Infof("GetKeyVersions: %s %s", kv.Name, keyID) + + kvClient, err := NewKvClient(kv.Authorizer) + if err != nil { + return []keyvault.KeyBundle{}, err + } + + pageLimit := int32(1) + keyVersions, err := kvClient.GetKeyVersions(ctx, kv.Name, keyID, &pageLimit) + if err != nil { + return []keyvault.KeyBundle{}, fmt.Errorf("failed to read key: %w", err) + } + + keyVersionValues := keyVersions.Values() + + keys, err := kv.getKeysFromVersions(ctx, keyVersionValues) + if err != nil { + log.Infof("failed to get key versions keys: %v", err) + return []keyvault.KeyBundle{}, err + } + + for keyVersions.NotDone() { + err := keyVersions.NextWithContext(ctx) + if err != nil { + log.Infof("failed to get key versions: %v", err) + return []keyvault.KeyBundle{}, err + } + + keyVersionValues = keyVersions.Values() + + nextKeys, err := kv.getKeysFromVersions(ctx, keyVersionValues) + if err != nil { + log.Infof("failed to get next key versions keys: %v", err) + return []keyvault.KeyBundle{}, err + } + + keys = append(keys, nextKeys...) + } + + return keys, nil +} + +// getKeysFromVersions gets the keys from the given key versions +func (kv *KeyVault) getKeysFromVersions(ctx context.Context, keyVersions []keyvault.KeyItem) ([]keyvault.KeyBundle, error) { + + log := logger.Sugar.FromContext(ctx) + defer log.Close() + + log.Infof("getKeysFromVersions") + + keys := []keyvault.KeyBundle{} + + for _, keyVersionValue := range keyVersions { + + // if we don't have a kid we can't find the key + if keyVersionValue.Kid == nil { + continue + } + + key, err := kv.GetKeyByKID(ctx, *keyVersionValue.Kid) + if err != nil { + return []keyvault.KeyBundle{}, fmt.Errorf("failed get key version: %w", err) + } + + keys = append(keys, key) + } + + return keys, nil +} + +// GetKeyVersion gets the version of the given key +func GetKeyVersion(kid string) string { + + // the kid is comprised of the {name}/{version} + kidParts := strings.Split(kid, "/") + + // get the version part + return kidParts[len(kidParts)-1] + +} + +// GetKeyName gets the name of the given key +func GetKeyName(kid string) string { + + // the kid is comprised of the {name}/{version} + kidParts := strings.Split(kid, "/") + + // get the name part + return kidParts[len(kidParts)-2] +} + +// Sign signs a given payload +func (kv *KeyVault) Sign( + ctx context.Context, + payload []byte, + keyID string, + keyVersion string, + algorithm keyvault.JSONWebKeySignatureAlgorithm, +) ([]byte, error) { + + log := logger.Sugar.FromContext(ctx) + defer log.Close() + + log.Infof("Sign: %s %s", kv.Name, keyID) + + kvClient, err := NewKvClient(kv.Authorizer) + if err != nil { + return []byte{}, err + } + + payloadStr := base64.URLEncoding.EncodeToString(payload) + + logger.Sugar.Infof("Payload Str: %v", payloadStr) + + params := keyvault.KeySignParameters{ + Algorithm: algorithm, + Value: &payloadStr, + } + + signatureb64, err := kvClient.Sign(ctx, kv.Name, keyID, keyVersion, params) + if err != nil { + return []byte{}, fmt.Errorf("failed toado sign payl: %w", err) + } + + logger.Sugar.Infof("SignatureB64: %v", *signatureb64.Result) + signature, err := base64.URLEncoding.DecodeString(*signatureb64.Result) + return signature, err + +} + +// Verify verifies a given payload +func (kv *KeyVault) Verify( + ctx context.Context, + signature []byte, + digest []byte, + keyID string, + keyVersion string, + algorithm keyvault.JSONWebKeySignatureAlgorithm, +) (bool, error) { + + log := logger.Sugar.FromContext(ctx) + defer log.Close() + + log.Infof("Verify: %s %s", kv.Name, keyID) + + kvClient, err := NewKvClient(kv.Authorizer) + if err != nil { + return false, err + } + + signatureStr := base64.URLEncoding.EncodeToString(signature) + digestStr := base64.URLEncoding.EncodeToString(digest) + + params := keyvault.KeyVerifyParameters{ + Algorithm: algorithm, + Signature: &signatureStr, + Digest: &digestStr, + } + + result, err := kvClient.Verify(ctx, kv.Name, keyID, keyVersion, params) + if err != nil { + return false, fmt.Errorf("failed to verify payload: %w", err) + } + return *result.Value, err + +} From 77d47dcf881bf44abadaa66af73682c08eae18d2 Mon Sep 17 00:00:00 2001 From: jgough Date: Wed, 27 Sep 2023 09:39:38 +0100 Subject: [PATCH 2/3] fixup --- azkeys/keyvault_test.go | 67 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 67 insertions(+) create mode 100644 azkeys/keyvault_test.go diff --git a/azkeys/keyvault_test.go b/azkeys/keyvault_test.go new file mode 100644 index 0000000..ce26ce5 --- /dev/null +++ b/azkeys/keyvault_test.go @@ -0,0 +1,67 @@ +package azkeys + +import ( + "testing" + + "github.com/stretchr/testify/assert" +) + +// TestGetKeyVersion tests: +// +// 1. with a valid keyvault KID we get the key version back successfully +func TestGetKeyVersion(t *testing.T) { + type args struct { + kid string + } + tests := []struct { + name string + args args + expected string + }{ + { + name: "positive", + args: args{ + kid: "https://example.vault.azure.net/keys/my-key/6eee6743b34e4291807565af6b756bac", + }, + expected: "6eee6743b34e4291807565af6b756bac", + }, + } + for _, test := range tests { + t.Run(test.name, func(t *testing.T) { + + actual := GetKeyVersion(test.args.kid) + + assert.Equal(t, test.expected, actual) + }) + } +} + +// TestGetKeyName tests: +// +// 1. with a valid keyvault KID we get the key name back successfully +func TestGetKeyName(t *testing.T) { + type args struct { + kid string + } + tests := []struct { + name string + args args + expected string + }{ + { + name: "positive", + args: args{ + kid: "https://example.vault.azure.net/keys/my-key/6eee6743b34e4291807565af6b756bac", + }, + expected: "my-key", + }, + } + for _, test := range tests { + t.Run(test.name, func(t *testing.T) { + + actual := GetKeyName(test.args.kid) + + assert.Equal(t, test.expected, actual) + }) + } +} From 4c9bb3d60b978a79278d56a3d9ca59b2da9e6e0d Mon Sep 17 00:00:00 2001 From: jgough Date: Wed, 27 Sep 2023 09:43:15 +0100 Subject: [PATCH 3/3] fixup --- azkeys/keyvault.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/azkeys/keyvault.go b/azkeys/keyvault.go index e1985f2..5c24643 100644 --- a/azkeys/keyvault.go +++ b/azkeys/keyvault.go @@ -59,7 +59,7 @@ func (kv *KeyVault) GetKeyByKID( } -// GetLatestKey returns the identified key +// GetLatestKey returns the latest version of the identified key func (kv *KeyVault) GetLatestKey( ctx context.Context, keyID string, ) (keyvault.KeyBundle, error) { @@ -82,7 +82,7 @@ func (kv *KeyVault) GetLatestKey( return key, nil } -// GetKeyVersions returns all the keys for all the versions of the identified key. +// GetKeyVersionsKeys returns all the keys, for all the versions of the identified key. // // The keys returned are the public half of the asymetric keys func (kv *KeyVault) GetKeyVersionsKeys(