holgerfriedrich commented on code in PR #2927:
URL: https://github.com/apache/karaf/pull/2927#discussion_r4057279245


##########
jaas/modules/src/main/java/org/apache/karaf/jaas/modules/publickey/PublickeyLoginModule.java:
##########
@@ -239,6 +247,23 @@ public static boolean equals(PublicKey key, String 
storedKey) throws FailedLogin
                 PublicKey generatedPublicKey = 
keyFactory.generatePublic(keySpec);
 
                 return key.equals(generatedPublicKey);
+            } else if (ED25519_IDENTIFIER.equals(identifier)) {
+                // OpenSSH stores an ed25519 key as the raw 32 bytes of the 
compressed point.
+                // The key implementation depends on the registered provider 
(for instance
+                // BouncyCastle), so compare the X.509 encodings instead of 
the key objects.
+                int size = dis.readInt();
+                if (size != ED25519_KEY_LENGTH) {
+                    return false;
+                }
+                byte[] bytes = new byte[size];
+                dis.readFully(bytes);
+
+                KeyFactory keyFactory = KeyFactory.getInstance("Ed25519");

Review Comment:
   Thanks, interesting background. See my comment on lift to JDK 21 below.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to