Sk Auth Helpers
Convenience entry points for wiring SK keys into the org.connectbot.sshlib.AuthHandler flow.
Typical caller flow (caller owns the CTAP2 stack):
// 1. From your stored SK key data, build an AuthPublicKey:
val authKey = SkAuthHelpers.buildAuthPublicKey(
algorithm = SkAlgorithm.ED25519,
rawKey = storedRawEd25519PubKey, // 32 bytes
application = "ssh:", // RP id the credential is bound to
)
// 2. Return it from AuthHandler.onPublicKeysNeeded():
override suspend fun onPublicKeysNeeded() = listOf(authKey)
// 3. In AuthHandler.onSignatureRequest(), call your CTAP2 stack with
// clientDataHash = SHA-256(dataToSign), then return SkSignatureBlob.pack(...).
override suspend fun onSignatureRequest(key: AuthPublicKey, dataToSign: ByteArray): ByteArray {
val clientDataHash = sha256(dataToSign)
val assertion = myCtap2.getAssertion(rpId = "ssh:", credentialId = ..., clientDataHash)
return SkSignatureBlob.pack(
algorithm = SkAlgorithm.ED25519,
rawSignature = assertion.signature, // raw 64 bytes for Ed25519, DER for ECDSA-P256
flags = assertion.flags, // 0x01 = UP, |0x04 if UV
counter = assertion.counter,
)
}Content copied to clipboard
Functions
Link copied to clipboard
fun buildAuthPublicKey(algorithm: SkAlgorithm, rawKey: ByteArray, application: String): AuthPublicKey
Build an AuthPublicKey for an SK credential, suitable for returning from org.connectbot.sshlib.AuthHandler.onPublicKeysNeeded.