ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
ssh_rsa.h File Reference

SSH RSA host-key layer: NVS-backed host key, host-key signing, and "ssh-rsa" blob encoding. More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

SSH RSA host-key layer: NVS-backed host key, host-key signing, and "ssh-rsa" blob encoding.

This is the SSH-specific wrapper around the shared RSA primitive (crypto/rsa): it owns the device's RSA-2048 host key, loaded from NVS, signs handshake data with it, and serializes the public key into the RFC 4253 / RFC 8332 "ssh-rsa" blob. The protocol-agnostic RSASSA-PKCS1-v1.5 math (verify, sign, PKCS#1 encoding, modexp) is ::Rsa in crypto/rsa, whose modular multiply is the arm a part with an RSA accelerator takes; peers' signatures are verified through the same namespace.

═══════════════════════════════════════════════════════════════════════════ SECURITY MODEL - PRIVATE KEY LIFETIME ═══════════════════════════════════════════════════════════════════════════ The RSA-2048 private key MUST NEVER live in static or global memory. The private exponent is a secure-pool borrow (mmgr/secure.h), the DER it was walked out of is released and wiped before the load returns, and ::RsaNs::sign wipes its own temporaries. The signature scheme is PKCS#1 v1.5 (RFC 8017 §8.2), "rsa-sha2-256" / "rsa-sha2-512" (RFC 8332) - only the hash and its DigestInfo OID differ.

NVS: the private key is a PKCS#8 DER in namespace "ssh_host_key" / key "priv_der"; n, e and d are walked out of it here.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file ssh_rsa.h.