SkPublicKeyEncoder

Builds OpenSSH SK public-key wire blobs.

The output is the byte sequence that appears in authorized_keys (base64-encoded after the algorithm name) and in the public key blob field of SSH publickey auth requests.

Format per OpenSSH PROTOCOL.u2f ยง3.1:

sk-ssh-ed25519@openssh.com:
string "sk-ssh-ed25519@openssh.com"
string rawEd25519PublicKey (32 bytes)
string application (e.g. "ssh:")

sk-ecdsa-sha2-nistp256@openssh.com:
string "sk-ecdsa-sha2-nistp256@openssh.com"
string "nistp256"
string ecPoint (uncompressed SEC1: 0x04 || X(32) || Y(32), 65 bytes)
string application

Functions

Link copied to clipboard
fun encode(algorithm: SkAlgorithm, rawKey: ByteArray, application: String): ByteArray

Build the SK public-key wire blob.