1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
|
# `arti keys`
`arti keys` is a command line utility for managing keystores and their content. In the
future, we will extend `arti keys` with additional functionality, for example multiple formatting
options for the output.
Like the other `arti` subcommands, it has an optional `--config` option for
specifying the TOML configuration file. Using the correct configuration file is
important, because the keystores that `arti keys` interacts with are relative to the
state directory, which you might have overridden in the configuration.
> `arti keys` is an experimental subcommand.
> To use it, you will need to compile `arti` with the experimental `onion-service-cli-extra` feature.
## Listing keystores
`arti keys list-keystores` lists all the configured keystores:
```
$ arti -c keys.toml keys list-keystores
Keystores:
- "arti"
```
## Listing the content of keystores
The command `arti keys list` is used for listing the content of keystores.
By default the command displays the content of all the keystores. If the
flag `--keystore-id` is provided, only the content of the specified
keystore will be displayed.
This command provides a way of listing both recognized and unrecognized entries.
- Recognized: keys that present a valid path.
- Unrecognized: keys that are in a valid location but do not present a
valid filename.
- Unrecognized paths: filesystem objects that should not be in the state directory.
Some of the information displayed by `keys list` can be used as input for other
commands. For instance: "Location", is the raw identifier of the entry; and
"Keystore ID", the identifier, of the keystore. These can be used together
with `arti keys-raw remove-by-id`.
Example usage:
<details>
<summary>With `-k`:</summary>
```ignore
$ arti -c keys.toml keys list -k arti
===== Keystore entries =====
Keystore ID: arti
Role: ks_hsc_desc_enc
Summary: Descriptor decryption key
KeystoreItemType: X25519StaticKeypair
Location: client/mnyizjj7m3hpcr7i5afph3zt7maa65johyu2ruis6z7cmnjmaj3h6tad/ks_hsc_desc_enc.x25519_private
Extra info:
- hs_id: mnyizjj7m3hpcr7i5afph3zt7maa65johyu2ruis6z7cmnjmaj3h6tad.onion
--------------------------------------------------------------------------------
Keystore ID: arti
Unrecognized path: unrecognized-path-dir/ks_hs_id.ed25519_expanded_private
--------------------------------------------------------------------------------
Keystore ID: arti
Role: ks_hs_id
Summary: Long-term identity keypair
KeystoreItemType: Ed25519ExpandedKeypair
Location: hss/allium-cepa/ks_hs_id.ed25519_expanded_private
Extra info:
- nickname: allium-cepa
--------------------------------------------------------------------------------
Unrecognized entry
Keystore ID: arti
Location: hss/allium-cepa/Ks_hs_id.ed25519_expanded_private
Error: Key has invalid path: hss/allium-cepa/Ks_hs_id.ed25519_expanded_private
--------------------------------------------------------------------------------
```
</details>
<details>
<summary>Default behavior</summary>
```ignore
$ arti -c keys.toml keys list
===== Keystore entries =====
Keystore ID: arti
Role: ks_hsc_desc_enc
Summary: Descriptor decryption key
KeystoreItemType: X25519StaticKeypair
Location: client/mnyizjj7m3hpcr7i5afph3zt7maa65johyu2ruis6z7cmnjmaj3h6tad/ks_hsc_desc_enc.x25519_private
Extra info:
- hs_id: mnyizjj7m3hpcr7i5afph3zt7maa65johyu2ruis6z7cmnjmaj3h6tad.onion
--------------------------------------------------------------------------------
Keystore ID: arti
Unrecognized path: unrecognized-path-dir/ks_hs_id.ed25519_expanded_private
--------------------------------------------------------------------------------
Keystore ID: arti
Role: ks_hs_id
Summary: Long-term identity keypair
KeystoreItemType: Ed25519ExpandedKeypair
Location: hss/allium-cepa/ks_hs_id.ed25519_expanded_private
Extra info:
- nickname: allium-cepa
--------------------------------------------------------------------------------
Unrecognized entry
Keystore ID: arti
Location: hss/allium-cepa/Ks_hs_id.ed25519_expanded_private
Error: Key has invalid path: hss/allium-cepa/Ks_hs_id.ed25519_expanded_private
--------------------------------------------------------------------------------
CTor service key
Hidden service nickname: allium-cepa
Keystore ID: ctor
KeystoreItemType: Ed25519ExpandedKeypair
Location: hs_ed25519_secret_key
--------------------------------------------------------------------------------
Unrecognized entry
Keystore ID: ctor
Location: hostname
Error: Key hostname is malformed
--------------------------------------------------------------------------------
CTor service key
Hidden service nickname: allium-cepa
Keystore ID: ctor
KeystoreItemType: Ed25519PublicKey
Location: hs_ed25519_public_key
--------------------------------------------------------------------------------
```
</details>
> The `hostname` file of a CTor keystore is represented as an unrecognized entry.
## Validate the integrity of keystores
The command `arti keys check-integrity` performs a validity check on keystores.
It detects and reports unrecognized entries and paths, as well as malformed or
expired keys. Such entries can be removed if requested.
By default, the command displays invalid entries from all keystores. If the
`--keystore-id` flag is provided, only the invalid elements of the specified
keystore are displayed. When the `--sweep` flag is used, you will be
prompted to remove the detected invalid elements. If the `--batch` flag
is used in conjunction with `-s`, invalid elements are removed without a prompt.
The output displays invalid entries grouped by keystores and indicates whether no
invalid entries are found in a given keystore.
Some keys are time-bound and may expire. Expired entries correspond to keys
associated with time periods (obtained from a consensus document) for which the
owning service is not publishing descriptors. An internet connection is required
to retrieve the consensus document and verify the validity of these keys.
Example usage:
<details>
<summary>Default behavior</summary>
```ignore
$ arti keys check-integrity
Found problems in keystores: arti, ctor.
Invalid keystore entries in keystore arti:
hss/allium-cepa/Ks_hs_blind_id+20241_1440_43200.ed25519_expanded_private
Error: Key has invalid path: hss/allium-cepa/Ks_hs_blind_id+20241_1440_43200.ed25519_expanded_private
hss/allium-cepa/ks_hs_id.ed25519_expanded_private
Error: Failed to parse OpenSSH with type Ed25519ExpandedKeypair
asdf/allium-cepa/ks_hs_blind_id+20242_1440_43200.ed25519_expanded_private
Error: Unrecognized path: asdf/allium-cepa/ks_hs_blind_id+20242_1440_43200
asdf/allium-cepa/ipts/k_sid+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae.ed25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_sid+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae
asdf/allium-cepa/ipts/k_sid+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53.ed25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_sid+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53
asdf/allium-cepa/ipts/k_hss_ntor+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de.x25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_hss_ntor+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de
asdf/allium-cepa/ipts/k_sid+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de.ed25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_sid+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de
asdf/allium-cepa/ipts/k_hss_ntor+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae.x25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_hss_ntor+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae
asdf/allium-cepa/ipts/k_hss_ntor+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53.x25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_hss_ntor+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53
asdf/allium-cepa/ks_hs_blind_id+20241_1440_43200.ed25519_expanded_private
Error: Unrecognized path: asdf/allium-cepa/ks_hs_blind_id+20241_1440_43200
asdf/allium-cepa/ks_hs_desc_sign+20242_1440_43200.ed25519_private
Error: Unrecognized path: asdf/allium-cepa/ks_hs_desc_sign+20242_1440_43200
asdf/allium-cepa/ks_hs_desc_sign+20241_1440_43200.ed25519_private
Error: Unrecognized path: asdf/allium-cepa/ks_hs_desc_sign+20241_1440_43200
asdf/allium-cepa/ks_hs_id.ed25519_expanded_private
Error: Unrecognized path: asdf/allium-cepa/ks_hs_id
hss/allium-cepa/ks_hs_desc_sign+20300_1440_43200.ed25519_private
Error: The entry is expired.
hss/allium-cepa/ks_hs_desc_sign+20299_1440_43200.ed25519_private
Error: The entry is expired.
hss/allium-cepa/ks_hs_blind_id+20300_1440_43200.ed25519_expanded_private
Error: The entry is expired.
hss/allium-cepa/ks_hs_blind_id+20299_1440_43200.ed25519_expanded_private
Error: The entry is expired.
Invalid keystore entries in keystore ctor:
hostname
Error: Key hostname is malformed
```
</details>
<details>
<summary>With `-k` and `-s`</summary>
```ignore
$ arti keys check-integrity -k arti -s
Found problems in keystore: arti.
Invalid keystore entries in keystore arti:
hss/allium-cepa/Ks_hs_blind_id+20241_1440_43200.ed25519_expanded_private
Error: Key has invalid path: hss/allium-cepa/Ks_hs_blind_id+20241_1440_43200.ed25519_expanded_private
hss/allium-cepa/ks_hs_id.ed25519_expanded_private
Error: Failed to parse OpenSSH with type Ed25519ExpandedKeypair
asdf/allium-cepa/ks_hs_blind_id+20242_1440_43200.ed25519_expanded_private
Error: Unrecognized path: asdf/allium-cepa/ks_hs_blind_id+20242_1440_43200
asdf/allium-cepa/ipts/k_sid+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae.ed25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_sid+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae
asdf/allium-cepa/ipts/k_sid+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53.ed25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_sid+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53
asdf/allium-cepa/ipts/k_hss_ntor+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de.x25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_hss_ntor+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de
asdf/allium-cepa/ipts/k_sid+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de.ed25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_sid+bf2c5fb26446e00877757a126fcdf48fa460021497d46aac1afa78ef380003de
asdf/allium-cepa/ipts/k_hss_ntor+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae.x25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_hss_ntor+4a487c4a6e5b666a64e748848146e621e2a096f3e18f110696e42d16e11374ae
asdf/allium-cepa/ipts/k_hss_ntor+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53.x25519_private
Error: Unrecognized path: asdf/allium-cepa/ipts/k_hss_ntor+6674c2d98191e632ff20c030e6f73ec4c7fec10e17d63d86a4f974e7da18ac53
asdf/allium-cepa/ks_hs_blind_id+20241_1440_43200.ed25519_expanded_private
Error: Unrecognized path: asdf/allium-cepa/ks_hs_blind_id+20241_1440_43200
asdf/allium-cepa/ks_hs_desc_sign+20242_1440_43200.ed25519_private
Error: Unrecognized path: asdf/allium-cepa/ks_hs_desc_sign+20242_1440_43200
asdf/allium-cepa/ks_hs_desc_sign+20241_1440_43200.ed25519_private
Error: Unrecognized path: asdf/allium-cepa/ks_hs_desc_sign+20241_1440_43200
asdf/allium-cepa/ks_hs_id.ed25519_expanded_private
Error: Unrecognized path: asdf/allium-cepa/ks_hs_id
hss/allium-cepa/ks_hs_desc_sign+20300_1440_43200.ed25519_private
Error: The entry is expired.
hss/allium-cepa/ks_hs_desc_sign+20299_1440_43200.ed25519_private
Error: The entry is expired.
hss/allium-cepa/ks_hs_blind_id+20300_1440_43200.ed25519_expanded_private
Error: The entry is expired.
hss/allium-cepa/ks_hs_blind_id+20299_1440_43200.ed25519_expanded_private
Error: The entry is expired.
Remove all invalid entries? (type yes or no):
```
</details>
<details>
<summary>If no invalid entry is encountered</summary>
```ignore
$ arti keys check-integrity -k arti
arti: OK.
```
</details>
> With this and other interactive commands, logs can be intrusive and disrupt the
> tool's workflow. In such cases, it is recommended to disable logging, either in
> the configuration file or using these flags:
>
> ```bash
> arti -o logging.console="off" -o logging.files='[{path = "file.log", filter = "info"}]' keys check-integrity
> ```
|