Method
sign(_:)
Signs data using the SSH agent.
func sign<DataBytes>(_ data: DataBytes) async throws -> Data where DataBytes : DataProtocol, DataBytes : Sendable
Parameters
data-
The data to be signed
Return Value
A signature compatible with NIOSSH authentication
Discussion
This method delegates the signing operation to the SSH agent, ensuring that private key material never needs to be exposed to the client application. The agent performs the cryptographic operation within its secure environment and returns the resulting signature.
The signing process respects any key constraints or policies configured within the SSH agent, including usage limitations, time restrictions, and destination constraints. The agent determines the appropriate signing algorithm based on the key type and any provided preferences.
Protocol Handling
The method handles the SSH agent protocol details transparently:
-
Constructs properly formatted signing requests
-
Manages communication with the agent
-
Processes signature responses and error conditions
-
Converts agent signatures to NIOSSH-compatible format
Different key types (RSA, Ed25519, ECDSA) are handled appropriately, with the agent determining the specific cryptographic operations needed.