Skip to content

Accept any key that implements AS4PrivateKey, not only an RSAPrivateKey - #5

Merged
dbkosky merged 1 commit into
masterfrom
feat/external-signer-protocol
Sep 9, 2026
Merged

dbkosky merged 1 commit into
masterfrom
feat/external-signer-protocol

Conversation

@dbkosky

@dbkosky dbkosky commented Sep 9, 2026 •

Copy link
Copy Markdown
Owner

Add an AS4PrivateKey abstract base declaring sign and decrypt, the only two methods the library calls on a key.

Add AS4LocalPrivateKey, which wraps a cryptography key for the ordinary case.

Narrow AS4InternalCredentials.private_key to AS4PrivateKey, so an unwrapped key is now refused.

Wrap the key at every call site, including the tests, so they show what a caller writes.

Unblocks keys held in a KMS or HSM, which never exist as an rsa.RSAPrivateKey.

@dbkosky dbkosky changed the title Accept any key that can sign and decrypt, not only an RSAPrivateKey Private key signing via protocol Sep 9, 2026
@dbkosky
dbkosky force-pushed the feat/external-signer-protocol branch from 8866f17 to 4e85216 Compare September 9, 2026 21:48
@dbkosky dbkosky changed the title Private key signing via protocol Accept any key that implements AS4PrivateKey, not only an RSAPrivateKey Sep 9, 2026
@dbkosky
dbkosky force-pushed the feat/external-signer-protocol branch from 4e85216 to 69bc4fa Compare September 9, 2026 21:52
@dbkosky
dbkosky marked this pull request as ready for review September 9, 2026 21:53
@dbkosky
dbkosky merged commit 63b68b1 into master Sep 9, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant