go_chacha20poly1305_openssh/README.md

30 lines
1.7 KiB
Markdown
Raw Normal View History

2022-05-02 04:15:31 -04:00
# cc20p1305ssh
2022-05-02 04:01:29 -04:00
2022-05-02 04:15:31 -04:00
A Golang library variant of ChaCha20-Poly1305 that OpenSSH uses ("chacha20-poly1305@openssh.com").
Note that this module *only* supports the OpenSSH variant.
## Why is this necessary?
Because Golang.org/x/crypto [removes functionality](https://github.com/golang/go/issues/36646) (even for [very common tech](https://github.com/golang/go/issues/44226)) and thinks OpenSSH is a "weird" use case.
I *really, really* hope this library is [no longer necessary](https://github.com/golang/go/issues/57699) by the time I'm done writing it, but based on my past experiences with core Golang devs, my expectations are extremely low.
2022-05-02 04:15:31 -04:00
They have no decent support for OpenSSH keys or lower-level operations. And guess what -- sometimes you need lower-level functionality. Who knew?
2022-06-05 06:52:27 -04:00
So now because I'm just a single individual, bug fixes will probably lag behind upstream. All because Golang.org/x/crypto decided the OpenSSH variant was "too weird".
But, of course, not "weird" enough to [not support the *wire* protocol](https://go.googlesource.com/crypto/+/master/ssh/cipher.go#647) for SSH. Just the key encryption. Because of course. And not publicly exposed either. Because of course.
## Why is the name so ugly?
I couldn't think of a better one and I wanted something notably distinct from stdlib-x.
2022-05-02 04:15:31 -04:00
## Why don't you expose the rest of ChaCha20/Poly1305/ChaCha20-Poly1305?
* To keep code light (and thus easier to debug, audit, etc.)
* Because otherwise the module name is inaccurate
* Because OpenSSH has their own specific variant
2023-01-08 17:31:09 -05:00
* Which means we can handle SSH-specific functionality if needed
2022-05-02 04:15:31 -04:00
* Because Golang/x/crypto has made it painfully clear that if you want something that deviates from what they think is "best practice", you need to do it yourself