Accept any key that implements AS4PrivateKey, not only an RSAPrivateKey - #5
Merged
Merged
Conversation
dbkosky
force-pushed
the
feat/external-signer-protocol
branch
from
September 9, 2026 21:48
8866f17 to
4e85216
Compare
dbkosky
force-pushed
the
feat/external-signer-protocol
branch
from
September 9, 2026 21:52
4e85216 to
69bc4fa
Compare
dbkosky
marked this pull request as ready for review
September 9, 2026 21:53
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add an
AS4PrivateKeyabstract base declaringsignanddecrypt, the only two methods the library calls on a key.Add
AS4LocalPrivateKey, which wraps acryptographykey for the ordinary case.Narrow
AS4InternalCredentials.private_keytoAS4PrivateKey, so an unwrapped key is now refused.Wrap the key at every call site, including the tests, so they show what a caller writes.
Unblocks keys held in a KMS or HSM, which never exist as an
rsa.RSAPrivateKey.