Linux cesa-www-main 6.1.0-49-cloud-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.174-1 (2026-05-26) x86_64
Apache/2.4.68 (Debian)
Server IP : 10.218.0.2 & Your IP : 216.73.216.28
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
usr /
lib /
google-cloud-sdk /
lib /
surface /
kms /
Delete
Unzip
Name
Size
Permission
Date
Action
__pycache__
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
autokey_config
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
ekm_config
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
ekm_connections
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
import_jobs
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
inventory
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
kaj_config
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
kaj_enrollment
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
key_handles
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
keyrings
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
keys
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
locations
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
operations
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
retired_resources
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
single_tenant_hsm
[ DIR ]
drwxr-xr-x
2026-06-08 18:08
__init__.py
1.96
KB
-rw-r--r--
1980-01-01 08:00
asymmetric_decrypt.py
4.82
KB
-rw-r--r--
1980-01-01 08:00
asymmetric_sign.py
7.92
KB
-rw-r--r--
1980-01-01 08:00
decapsulate.py
4.84
KB
-rw-r--r--
1980-01-01 08:00
decrypt.py
8.46
KB
-rw-r--r--
1980-01-01 08:00
encrypt.py
8.34
KB
-rw-r--r--
1980-01-01 08:00
mac_sign.py
5.12
KB
-rw-r--r--
1980-01-01 08:00
mac_verify.py
5.49
KB
-rw-r--r--
1980-01-01 08:00
raw_decrypt.py
9.54
KB
-rw-r--r--
1980-01-01 08:00
raw_encrypt.py
11.01
KB
-rw-r--r--
1980-01-01 08:00
Save
Rename
# -*- coding: utf-8 -*- # # Copyright 2017 Google LLC. All Rights Reserved. # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. """Sign a user input file using an asymmetric-signing key.""" from apitools.base.py import exceptions as apitools_exceptions from googlecloudsdk.api_lib.cloudkms import base as cloudkms_base from googlecloudsdk.calliope import base from googlecloudsdk.calliope import exceptions from googlecloudsdk.command_lib.kms import crc32c from googlecloudsdk.command_lib.kms import e2e_integrity from googlecloudsdk.command_lib.kms import flags from googlecloudsdk.command_lib.kms import get_digest from googlecloudsdk.core import log from googlecloudsdk.core.util import files @base.DefaultUniverseOnly class AsymmetricSign(base.Command): r"""Sign a user input file using an asymmetric-signing key version. Creates a digital signature of the input file using the provided asymmetric-signing key version and saves the base64 encoded signature. The required flag `signature-file` indicates the path to store signature. By default, the command performs integrity verification on data sent to and received from Cloud KMS. Use `--skip-integrity-verification` to disable integrity verification. For the ML-DSA EXTERNAL-MU algorithms, the digest `external-mu` should be used that depends on the public key. This command will fetch the public key from KMS and compute the `external-mu` digest. Note that this requires `signer` permissions on the associated CryptoKeyVersion. ## EXAMPLES The following command will read the file '/tmp/my/file.to.sign', digest it with the digest algorithm 'sha256' and sign it using the asymmetric CryptoKey `dont-panic` Version 3, and save the signature in base64 format to '/tmp/my/signature'. $ {command} \ --location=us-central1 \ --keyring=hitchhiker \ --key=dont-panic \ --version=3 \ --digest-algorithm=sha256 \ --input-file=/tmp/my/file.to.sign \ --signature-file=/tmp/my/signature """ @staticmethod def Args(parser): flags.AddKeyResourceFlags(parser, 'to use for signing.') flags.AddCryptoKeyVersionFlag(parser, 'to use for signing') flags.AddDigestAlgorithmFlag(parser, 'The algorithm to digest the input.') flags.AddInputFileFlag(parser, 'to sign') flags.AddSignatureFileFlag(parser, 'to output') flags.AddSkipIntegrityVerification(parser) def _PerformIntegrityVerification(self, args): return not args.skip_integrity_verification def _SignOnDigest(self, args): return args.digest_algorithm is not None def _ReadBinaryFile(self, path, max_bytes): data = files.ReadBinaryFileContents(path) if len(data) > max_bytes: raise exceptions.BadFileException( 'The file [{0}] is larger than the maximum size of {1} bytes.'.format( path, max_bytes)) return data def _CreateAsymmetricSignRequestOnDigest(self, args): version_ref = flags.ParseCryptoKeyVersionName(args) try: digest = get_digest.GetDigest( args.digest_algorithm, args.input_file, key_version_ref=version_ref ) except EnvironmentError as e: raise exceptions.BadFileException( 'Failed to read input file [{0}]: {1}'.format(args.input_file, e)) messages = cloudkms_base.GetMessagesModule() req = messages.CloudkmsProjectsLocationsKeyRingsCryptoKeysCryptoKeyVersionsAsymmetricSignRequest( # pylint: disable=line-too-long name=version_ref.RelativeName()) if self._PerformIntegrityVerification(args): # args.digest_algorithm has been verified in get_digest.GetDigest() digest_crc32c = crc32c.Crc32c(getattr(digest, args.digest_algorithm)) req.asymmetricSignRequest = messages.AsymmetricSignRequest( digest=digest, digestCrc32c=digest_crc32c) else: req.asymmetricSignRequest = messages.AsymmetricSignRequest(digest=digest) return req def _CreateAsymmetricSignRequestOnData(self, args): """Returns an AsymmetricSignRequest for use with a data input. Populates an AsymmetricSignRequest with its data field populated by data read from args.input_file. dataCrc32c is populated if integrity verification is not skipped. Args: args: Input arguments. Returns: An AsymmetricSignRequest with data populated and dataCrc32c populated if integrity verification is not skipped. Raises: exceptions.BadFileException: An error occurred reading the input file. This can occur if the file can't be read or if the file is larger than 64 KiB. """ try: # The Asymmetric Sign API limits the data input to 64KiB. data = self._ReadBinaryFile(args.input_file, max_bytes=65536) except files.Error as e: raise exceptions.BadFileException( 'Failed to read input file [{0}]: {1}'.format(args.input_file, e)) messages = cloudkms_base.GetMessagesModule() req = messages.CloudkmsProjectsLocationsKeyRingsCryptoKeysCryptoKeyVersionsAsymmetricSignRequest( # pylint: disable=line-too-long name=flags.ParseCryptoKeyVersionName(args).RelativeName()) if self._PerformIntegrityVerification(args): data_crc32c = crc32c.Crc32c(data) req.asymmetricSignRequest = messages.AsymmetricSignRequest( data=data, dataCrc32c=data_crc32c) else: req.asymmetricSignRequest = messages.AsymmetricSignRequest(data=data) return req def _CreateAsymmetricSignRequest(self, args): if self._SignOnDigest(args): return self._CreateAsymmetricSignRequestOnDigest(args) else: return self._CreateAsymmetricSignRequestOnData(args) def _VerifyResponseIntegrityFields(self, req, resp, use_digest=True): """Verifies integrity fields in AsymmetricSignResponse.""" # Verify resource name. if req.name != resp.name: raise e2e_integrity.ResourceNameVerificationError( e2e_integrity.GetResourceNameMismatchErrorMessage( req.name, resp.name)) if use_digest: # digest_crc32c was verified server-side. if not resp.verifiedDigestCrc32c: raise e2e_integrity.ClientSideIntegrityVerificationError( e2e_integrity.GetRequestToServerCorruptedErrorMessage()) else: # data_crc32c was verified server-side. if not resp.verifiedDataCrc32c: raise e2e_integrity.ClientSideIntegrityVerificationError( e2e_integrity.GetRequestToServerCorruptedErrorMessage()) # Verify signature checksum. if not crc32c.Crc32cMatches(resp.signature, resp.signatureCrc32c): raise e2e_integrity.ClientSideIntegrityVerificationError( e2e_integrity.GetResponseFromServerCorruptedErrorMessage()) def Run(self, args): client = cloudkms_base.GetClientInstance() req = self._CreateAsymmetricSignRequest(args) try: resp = ( client.projects_locations_keyRings_cryptoKeys_cryptoKeyVersions .AsymmetricSign(req)) # Intercept INVALID_ARGUMENT errors related to checksum verification, to # present a user-friendly message. All other errors are surfaced as-is. except apitools_exceptions.HttpBadRequestError as error: e2e_integrity.ProcessHttpBadRequestError(error) if self._PerformIntegrityVerification(args): self._VerifyResponseIntegrityFields( req, resp, use_digest=self._SignOnDigest(args)) try: log.WriteToFileOrStdout( args.signature_file, resp.signature, overwrite=True, binary=True, private=True) except files.Error as e: raise exceptions.BadFileException(e)