Skip to content

openpgpkey

Extracted into the signing module

This package was extracted from go-tool-base. It now lives in the standalone, independently-versioned signing module at gitlab.com/phpboyscout/go/signing/openpgpkey (v0.1.0). go-tool-base consumes it as an ordinary dependency.

The gtb CLI behaviour is unchanged, only the Go import path moved. The change is relevant to anyone writing Go against the package.

How gtb uses it

Mints an ASCII-armored OpenPGP public key from any crypto.Signer whose Public() returns *rsa.PublicKey, so an opaque HSM-backed signer (AWS KMS, GCP KMS, YubiKey) works without the private key ever leaving the HSM. Inside the gtb binary it backs gtb keys mint, gtb keys generate (RSA path), gtb keys wkd (Web Key Directory tree generation), and the DetachSign half of gtb sign (the per-release checksums.txt β†’ checksums.txt.sig step). The full API reference, algorithm/version details, reproducibility notes, and worked examples live in the signing module documentation and on pkg.go.dev.

For the operator-facing recipes, see: