mirror of
https://github.com/edgelesssys/constellation.git
synced 2025-01-16 01:47:13 -05:00
2d8fcd9bf4
Co-authored-by: Malte Poll <mp@edgeless.systems> Co-authored-by: katexochen <katexochen@users.noreply.github.com> Co-authored-by: Daniel Weiße <dw@edgeless.systems> Co-authored-by: Thomas Tendyck <tt@edgeless.systems> Co-authored-by: Benedict Schlueter <bs@edgeless.systems> Co-authored-by: leongross <leon.gross@rub.de> Co-authored-by: Moritz Eckert <m1gh7ym0@gmail.com>
29 lines
802 B
Go
29 lines
802 B
Go
package kms
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
|
|
"github.com/edgelesssys/constellation/coordinator/util"
|
|
)
|
|
|
|
// ClusterKMS implements the kms.CloudKMS interface for in cluster key management.
|
|
type ClusterKMS struct {
|
|
masterKey []byte
|
|
}
|
|
|
|
// CreateKEK sets the CoordinatorKMS masterKey.
|
|
func (c *ClusterKMS) CreateKEK(ctx context.Context, keyID string, kek []byte) error {
|
|
c.masterKey = kek
|
|
return nil
|
|
}
|
|
|
|
// GetDEK derives a key from the KMS masterKey.
|
|
func (c *ClusterKMS) GetDEK(ctx context.Context, kekID string, dekID string, dekSize int) ([]byte, error) {
|
|
if len(c.masterKey) == 0 {
|
|
return nil, errors.New("master key not set for Constellation KMS")
|
|
}
|
|
// TODO: Choose a way to salt key derivation
|
|
return util.DeriveKey(c.masterKey, []byte("Constellation"), []byte("key"+dekID), uint(dekSize))
|
|
}
|