summaryrefslogtreecommitdiff
path: root/doc/keys.md
blob: 0ecb3895a1a410dfb6b1b9076cc2c4da5397d5c4 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
# `arti keys`

`arti keys` is a command line utility for managing keystores and their content. In the
future, we will extend `arti keys` with additional functionality, for example multiple formatting
options for the output.

Like the other `arti` subcommands, it has an optional `--config` option for
specifying the TOML configuration file. Using the correct configuration file is
important, because the keystores that `arti keys` interacts with are relative to the
state directory, which you might have overridden in the configuration.

> `arti keys` is an experimental subcommand.
> To use it, you will need to compile `arti` with the experimental `onion-service-cli-extra` feature.

## Listing keystores

`arti keys list-keystores` lists all the configured keystores:

```
$ arti -c keys.toml keys list-keystores
 Keystores:

 - "arti"


```


## Listing the content of keystores

The command `arti keys list` is used for listing the content of keystores.

By default the command displays the content of all the keystores. If the
flag `--keystore-id` is provided, only the content of the specified
keystore will be displayed.

This command provides a way of listing both recognized and unrecognized entries.

- Recognized: keys that present a valid path.
- Unrecognized: keys that are in a valid location but do not present a
valid filename.
- Unrecognized paths: filesystem objects that should not be in the state directory.

Some of the information displayed by `keys list` can be used as input for other
commands. For instance: "Location", is the raw identifier of the entry; and
"Keystore ID", the identifier, of the keystore. These can be used together
with `arti keys-raw remove-by-id`.

Example usage:

<details>
<summary>With `-k`:</summary>

```ignore
$ arti -c keys.toml keys list -k arti
 ===== Keystore entries =====


 Keystore ID: arti
 Role: ks_hsc_desc_enc
 Summary: Descriptor decryption key
 KeystoreItemType: X25519StaticKeypair
 Location: client/mnyizjj7m3hpcr7i5afph3zt7maa65johyu2ruis6z7cmnjmaj3h6tad/ks_hsc_desc_enc.x25519_private
 Extra info:
 - hs_id: mnyizjj7m3hpcr7i5afph3zt7maa65johyu2ruis6z7cmnjmaj3h6tad.onion

 --------------------------------------------------------------------------------

 Keystore ID: arti
 Unrecognized path: herba-spontanea/ks_hs_id.ed25519_expanded_private

 --------------------------------------------------------------------------------

 Keystore ID: arti
 Role: ks_hs_id
 Summary: Long-term identity keypair
 KeystoreItemType: Ed25519ExpandedKeypair
 Location: hss/allium-cepa/ks_hs_id.ed25519_expanded_private
 Extra info:
 - nickname: allium-cepa

 --------------------------------------------------------------------------------

 Unrecognized entry
 Keystore ID: arti
 Location: hss/allium-cepa/Ks_hs_id.ed25519_expanded_private
 Error: Key has invalid path: hss/allium-cepa/Ks_hs_id.ed25519_expanded_private

 --------------------------------------------------------------------------------


```
</details>

<details>
<summary>Default behavior</summary>

```ignore
$ arti -c keys.toml keys list
 ===== Keystore entries =====


 Keystore ID: arti
 Role: ks_hsc_desc_enc
 Summary: Descriptor decryption key
 KeystoreItemType: X25519StaticKeypair
 Location: client/mnyizjj7m3hpcr7i5afph3zt7maa65johyu2ruis6z7cmnjmaj3h6tad/ks_hsc_desc_enc.x25519_private
 Extra info:
 - hs_id: mnyizjj7m3hpcr7i5afph3zt7maa65johyu2ruis6z7cmnjmaj3h6tad.onion

 --------------------------------------------------------------------------------

 Keystore ID: arti
 Unrecognized path: herba-spontanea/ks_hs_id.ed25519_expanded_private

 --------------------------------------------------------------------------------

 Keystore ID: arti
 Role: ks_hs_id
 Summary: Long-term identity keypair
 KeystoreItemType: Ed25519ExpandedKeypair
 Location: hss/allium-cepa/ks_hs_id.ed25519_expanded_private
 Extra info:
 - nickname: allium-cepa

 --------------------------------------------------------------------------------

 Unrecognized entry
 Keystore ID: arti
 Location: hss/allium-cepa/Ks_hs_id.ed25519_expanded_private
 Error: Key has invalid path: hss/allium-cepa/Ks_hs_id.ed25519_expanded_private

 --------------------------------------------------------------------------------

 CTor service key
 Hidden service nickname: allium-cepa
 Keystore ID: ctor
 KeystoreItemType: Ed25519ExpandedKeypair
 Location: hs_ed25519_secret_key

 --------------------------------------------------------------------------------

 Unrecognized entry
 Keystore ID: ctor
 Location: hostname
 Error: Key hostname is malformed

 --------------------------------------------------------------------------------

 CTor service key
 Hidden service nickname: allium-cepa
 Keystore ID: ctor
 KeystoreItemType: Ed25519PublicKey
 Location: hs_ed25519_public_key

 --------------------------------------------------------------------------------

```
</details>

> The `hostname` file of a CTor keystore is represented as an unrecognized entry.


## Validate the integrity of keystores

The command `arti keys check-integrity` performs a validity check on keystores.
It detects and reports unrecognized entries and paths, as well as malformed or
expired keys. Such entries can be removed if requested.

By default, the command displays invalid entries from all keystores. If the
`--keystore-id` flag is provided, only the invalid elements of the specified
keystore are displayed. When the `--sweep` flag is used, you will be
prompted to remove the detected invalid elements. If the `--batch` flag
is used in conjunction with `-s`, invalid elements are removed without a prompt.

The output consists of two sections: invalid keystore entries and expired entries.

Some keys are time-bound and may expire. Expired entries correspond to keys
associated with time periods (obtained from a consensus document) for which the
owning service is not publishing descriptors. An internet connection is required
to retrieve the consensus document and verify the validity of these keys.

Example usage:

<details>
<summary>Default behavior</summary>

```ignore
$ arti keys check-integrity
 ===== Invalid keystore entries =====


 Unrecognized entry
 Keystore ID: arti
 Location: hss/allium-cepa/erba-spontanea
 Error: Key has invalid path: hss/allium-cepa/erba-spontanea

 --------------------------------------------------------------------------------

 Unrecognized path asdf/allium-cepa/ks_hs_blind_id+20242_1440_43200.ed25519_expanded_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_sid+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae.ed25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_sid+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53.ed25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_hss_ntor+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de.x25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_sid+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de.ed25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_hss_ntor+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae.x25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_hss_ntor+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53.x25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ks_hs_blind_id+20241_1440_43200.ed25519_expanded_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ks_hs_desc_sign+20242_1440_43200.ed25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ks_hs_desc_sign+20241_1440_43200.ed25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ks_hs_id.ed25519_expanded_private

 --------------------------------------------------------------------------------
 Unrecognized entry
 Keystore ID: ctor
 Location: hostname
 Error: Key hostname is malformed

 --------------------------------------------------------------------------------

 ===== Expired keystore entries =====


 Keystore ID: arti
 Role: ks_hs_desc_sign
 Summary: Descriptor signing key
 KeystoreItemType: Ed25519Keypair
 Location: hss/allium-cepa/ks_hs_desc_sign+20300_1440_43200.ed25519_private
 Extra info:
 - nickname: allium-cepa
 - period: #20300 2025-07-31T12:00:00Z..+24:00

 --------------------------------------------------------------------------------
 Keystore ID: arti
 Role: ks_hs_desc_sign
 Summary: Descriptor signing key
 KeystoreItemType: Ed25519Keypair
 Location: hss/allium-cepa/ks_hs_desc_sign+20299_1440_43200.ed25519_private
 Extra info:
 - nickname: allium-cepa
 - period: #20299 2025-07-30T12:00:00Z..+24:00

 --------------------------------------------------------------------------------
 Keystore ID: arti
 Role: ks_hs_blind_id
 Summary: Blinded signing keypair
 KeystoreItemType: Ed25519ExpandedKeypair
 Location: hss/allium-cepa/ks_hs_blind_id+20300_1440_43200.ed25519_expanded_private
 Extra info:
 - nickname: allium-cepa
 - period: #20300 2025-07-31T12:00:00Z..+24:00

 --------------------------------------------------------------------------------
 Keystore ID: arti
 Role: ks_hs_blind_id
 Summary: Blinded signing keypair
 KeystoreItemType: Ed25519ExpandedKeypair
 Location: hss/allium-cepa/ks_hs_blind_id+20299_1440_43200.ed25519_expanded_private
 Extra info:
 - nickname: allium-cepa
 - period: #20299 2025-07-30T12:00:00Z..+24:00

 --------------------------------------------------------------------------------
```
</details>

<details>
<summary>With `-k` and `-s`</summary>

```ignore
$ arti keys check-integrity -k arti -s
 ===== Invalid keystore entries =====


 Unrecognized entry
 Keystore ID: arti
 Location: hss/allium-cepa/erba-spontanea
 Error: Key has invalid path: hss/allium-cepa/erba-spontanea

 --------------------------------------------------------------------------------

 Unrecognized path asdf/allium-cepa/ks_hs_blind_id+20242_1440_43200.ed25519_expanded_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_sid+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae.ed25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_sid+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53.ed25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_hss_ntor+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de.x25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_sid+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de.ed25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_hss_ntor+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae.x25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ipts/k_hss_ntor+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53.x25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ks_hs_blind_id+20241_1440_43200.ed25519_expanded_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ks_hs_desc_sign+20242_1440_43200.ed25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ks_hs_desc_sign+20241_1440_43200.ed25519_private

 --------------------------------------------------------------------------------
 Unrecognized path asdf/allium-cepa/ks_hs_id.ed25519_expanded_private

 --------------------------------------------------------------------------------
 Unrecognized entry
 Keystore ID: ctor
 Location: hostname
 Error: Key hostname is malformed

 --------------------------------------------------------------------------------

 ===== Expired keystore entries =====


 Keystore ID: arti
 Role: ks_hs_desc_sign
 Summary: Descriptor signing key
 KeystoreItemType: Ed25519Keypair
 Location: hss/allium-cepa/ks_hs_desc_sign+20300_1440_43200.ed25519_private
 Extra info:
 - nickname: allium-cepa
 - period: #20300 2025-07-31T12:00:00Z..+24:00

 --------------------------------------------------------------------------------
 Keystore ID: arti
 Role: ks_hs_desc_sign
 Summary: Descriptor signing key
 KeystoreItemType: Ed25519Keypair
 Location: hss/allium-cepa/ks_hs_desc_sign+20299_1440_43200.ed25519_private
 Extra info:
 - nickname: allium-cepa
 - period: #20299 2025-07-30T12:00:00Z..+24:00

 --------------------------------------------------------------------------------
 Keystore ID: arti
 Role: ks_hs_blind_id
 Summary: Blinded signing keypair
 KeystoreItemType: Ed25519ExpandedKeypair
 Location: hss/allium-cepa/ks_hs_blind_id+20300_1440_43200.ed25519_expanded_private
 Extra info:
 - nickname: allium-cepa
 - period: #20300 2025-07-31T12:00:00Z..+24:00

 --------------------------------------------------------------------------------
 Keystore ID: arti
 Role: ks_hs_blind_id
 Summary: Blinded signing keypair
 KeystoreItemType: Ed25519ExpandedKeypair
 Location: hss/allium-cepa/ks_hs_blind_id+20299_1440_43200.ed25519_expanded_private
 Extra info:
 - nickname: allium-cepa
 - period: #20299 2025-07-30T12:00:00Z..+24:00

 --------------------------------------------------------------------------------

Remove all invalid entries? (type yes or no):

```
</details>

> With this and other interactive commands, logs can be intrusive and disrupt the
> tool's workflow. In such cases, it is recommended to disable logging, either in
> the configuration file or using these flags:
>
> ```bash
> arti -o logging.console="off" -o logging.files='[{path = "file.log", filter = "info"}]' keys check-integrity
> ```