You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Golang将EC公钥转换为PGP公钥?

将EC公钥转换为PGP公钥(Golang实现)

核心结论

EC公钥完全可以转换为符合PGP标准的公钥,PGP协议支持ECDSA、Ed25519等椭圆曲线签名算法,完全适配yum/dnf的RPM GPG校验需求。

替代弃用opnpgp的方案

目前可使用ProtonMail/go-crypto下的openpgp分支(原opnpgp的维护继任版本)完成转换,核心步骤如下:

1. 解析EC公钥

先将PEM格式的EC公钥解析为Golang标准库的ecdsa.PublicKey对象:

import (
    "crypto/ecdsa"
    "crypto/x509"
    "encoding/pem"
    "errors"
)

func parseECPublicKey(pemData []byte) (*ecdsa.PublicKey, error) {
    block, _ := pem.Decode(pemData)
    if block == nil || block.Type != "PUBLIC KEY" {
        return nil, errors.New("无效的EC公钥PEM格式")
    }
    pub, err := x509.ParsePKIXPublicKey(block.Bytes)
    if err != nil {
        return nil, err
    }
    ecPub, ok := pub.(*ecdsa.PublicKey)
    if !ok {
        return nil, errors.New("输入的不是EC公钥")
    }
    return ecPub, nil
}

2. 封装为PGP公钥

将解析后的EC公钥封装为PGP实体,并导出ASCII格式的PGP公钥(yum/dnf要求的格式):

import (
    "bytes"
    "github.com/ProtonMail/go-crypto/openpgp"
    "github.com/ProtonMail/go-crypto/openpgp/packet"
)

func ecToPGPPublicKey(ecPub *ecdsa.PublicKey, userId string) ([]byte, error) {
    config := &packet.Config{
        DefaultHash: packet.HashSHA256, // 适配yum/dnf常用的哈希算法
    }

    // 创建PGP实体并设置用户ID
    entity, err := openpgp.NewEntity(userId, "", "", config)
    if err != nil {
        return nil, err
    }

    // 替换实体主密钥为目标EC公钥
    entity.PrimaryKey = packet.NewECDSAPublicKey(config.Now, ecPub)
    identity := entity.Identities[userId]
    identity.SelfSignature.PubKeyAlgo = packet.PubKeyAlgoECDSA
    identity.SelfSignature.Hash = config.DefaultHash

    // 导出ASCII格式PGP公钥
    var buf bytes.Buffer
    if err := entity.Serialize(&buf); err != nil {
        return nil, err
    }
    return buf.Bytes(), nil
}

3. 兼容性验证

转换后的PGP公钥可通过gpg --import导入,执行gpg --list-keys确认算法显示为ecdsa或对应椭圆曲线类型,随后即可将其放置到/etc/pki/rpm-gpg/目录下,配置yum/dnf进行校验。

关键注意事项

  • 确保EC公钥使用PGP支持的曲线(如P-256、P-384、Ed25519),yum/dnf对这些曲线均兼容。
  • 推荐使用SHA256作为哈希算法,避免出现校验不兼容问题。
  • 若需用对应EC私钥签名RPM,可使用同一库完成PGP格式签名,保持密钥体系一致。

内容的提问来源于stack exchange,提问作者KeepAsking

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 04:07:35