Sk Signature Blob
Packs an SK assertion into the OpenSSH SK signature wire format.
The output is what callers should return from org.connectbot.sshlib.AuthHandler.onSignatureRequest for an SK public key. The library writes it verbatim into the SSH publickey USERAUTH_REQUEST packet's signature field.
Format per OpenSSH PROTOCOL.u2f §3.2:
sk-ssh-ed25519@openssh.com:
string "sk-ssh-ed25519@openssh.com"
string rawEd25519Signature (64 bytes)
byte flags
uint32 counter
sk-ecdsa-sha2-nistp256@openssh.com:
string "sk-ecdsa-sha2-nistp256@openssh.com"
string sig_material (mpint r || mpint s, RFC 5656)
byte flags
uint32 counterFor ECDSA-P256, pack accepts the DER SEQUENCE { INTEGER r, INTEGER s } format that CTAP2 returns and converts it to mpint r || mpint s internally.
The flags and counter parameters of pack come from the CTAP2 GetAssertion response. Per OpenSSH PROTOCOL.u2f §3.2, the FIDO2 device sets flags = SK_USER_PRESENCE_REQUIRED (0x01) if user presence was tested and | SK_USER_VERIFICATION_REQUIRED (0x04) if user verification was also tested; counter is the device's monotonic signature counter.