wiki:KeySetup

Version 1 (modified by Nicolas, 17 years ago) (diff)

Converted by an automatic script

The encryption utility

The program lib/crypt_prog performs various encryption tasks.

crypt_prog is built by the standard build procedure on Unix systems. You can also build it on Windows (with Visual Studio 2003) using the project file win_build/crypt_prog.vcproj.

Creating encryption keys crypt_prog -genkey n private_keyfile public_keyfile Create a key pair with n bits (always use 1024). Write the keys in encoded ASCII form to the indicated files. The following commands generate the file upload and code signing key pairs. BOINC_KEY_DIR is the directory where the keys will be stored. The code signing private key should be stored only on a highly secure (e.g., a disconnected, physically secure) host.

crypt_prog -genkey 1024 BOINC_KEY_DIR/upload_private BOINC_KEY_DIR/upload_public
crypt_prog -genkey 1024 BOINC_KEY_DIR/code_sign_private BOINC_KEY_DIR/code_sign_public

Or, in the test/ directory, run

gen_keys.php

Generating signatures

crypt_prog -sign file private_keyfile Create a digital signature for the given file. Write it in encoded ASCII to stdout. crypt_prog -sign_string string private_keyfile Create a digital signature for the given string. Write it in encoded ASCII to stdout. crypt_prog -verify file signature_file public_keyfile Verify a signature for the given file. crypt_prog -test_crypt private_keyfile public_keyfile Perform an internal test, checking that encryption followed by decryption works.