Class
SSHAgentPrivateKey
A private key implementation that delegates signing operations to the SSH agent.
class SSHAgentPrivateKey
Overview
This class provides a private key interface that delegates all cryptographic operations to the SSH agent, ensuring that private key material never leaves the agent’s security boundary. It maintains a reference to the agent key and communicates with the agent for signature generation operations.
The implementation provides a compatible interface with NIOSSH authentication mechanisms whilst leveraging the SSH agent for all private key operations. This approach maintains the security benefits of agent-based authentication where sensitive cryptographic material remains protected within the agent.
Security Benefits
By delegating to the SSH agent, this implementation ensures:
-
Private keys never leave the agent’s security boundary
-
Agent-specific policies and constraints are respected
-
Hardware security modules can be used if supported by the agent
-
Key usage can be audited and controlled by the agent
Agent Integration
The class communicates with the SSH agent using the standard SSH agent protocol, sending signing requests and receiving signatures. All protocol details are handled transparently, providing a simple interface for authentication use.
Topics
Initializers
Creates a new SSH agent-backed private key.
Instance Properties
The public key corresponding to this private key.
Instance Methods
Signs data using the SSH agent.
See Also
Signing Support
Creates an SSH agent-backed NIOSSH private key.
Requests a signature from the SSH agent for the specified data and key.