holgerfriedrich commented on code in PR #2927:
URL: https://github.com/apache/karaf/pull/2927#discussion_r4057200066


##########
jaas/modules/src/main/java/org/apache/karaf/jaas/modules/publickey/PublickeyLoginModule.java:
##########
@@ -239,6 +247,23 @@ public static boolean equals(PublicKey key, String 
storedKey) throws FailedLogin
                 PublicKey generatedPublicKey = 
keyFactory.generatePublic(keySpec);
 
                 return key.equals(generatedPublicKey);
+            } else if (ED25519_IDENTIFIER.equals(identifier)) {
+                // OpenSSH stores an ed25519 key as the raw 32 bytes of the 
compressed point.
+                // The key implementation depends on the registered provider 
(for instance
+                // BouncyCastle), so compare the X.509 encodings instead of 
the key objects.
+                int size = dis.readInt();
+                if (size != ED25519_KEY_LENGTH) {
+                    return false;
+                }
+                byte[] bytes = new byte[size];
+                dis.readFully(bytes);
+
+                KeyFactory keyFactory = KeyFactory.getInstance("Ed25519");
+                KeySpec publicKeySpec = new 
X509EncodedKeySpec(x509Ed25519(bytes));
+                PublicKey generatedPublicKey = 
keyFactory.generatePublic(publicKeySpec);
+
+                byte[] encoded = key.getEncoded();
+                return encoded != null && Arrays.equals(encoded, 
generatedPublicKey.getEncoded());

Review Comment:
   ok, done as requested



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to