Skip to main content

QUARA Creds

CLI usage

Display help

Several subcommands are available. The --help option is available at different levels:

# General help
pync --help
# cert command group help
pync cert --help
# cert sign subcommand help
pync cert sign --help

Initialize environment

  • Initialize with default configuration
pync init
  • Reset configuration
pync init --force
  • Configure authorities from a JSON file (either a path or an URL):
pync init --authorities https://example.com/authorities.json

Manage keypairs

  • Create a new keypair for current user:
pync key gen
  • Create a new keypair for a different user:
pync key gen -n test
  • List available keypairs
pync key list
  • Display a public key
pync key show -n test
  • Display a private key
pync key show -n test --private

Manager certificate authorities

  • List available authorities:
pync ca list
  • Show authorities details:
pync ca show
  • Show authorities certificates:
pync ca show --pem

Nebula certs examples

Create a new CA and a sign a new certificate

from quara.creds.nebula import (
    EncryptionKeyPair,
    SigningCAOptions,
    SigningOptions,
    sign_ca_certificate,
    sign_certificate,
    verify_certificate,
)

# Create a new CA
ca_keypair, ca_crt = sign_ca_certificate(options=SigningCAOptions(Name="test"))
# Create a new keypair for the certificate
enc_keypair = EncryptionKeyPair()
# Sign a new certificate
new_crt = sign_certificate(
    ca_key=ca_keypair,
    ca_crt=ca_crt,
    public_key=enc_keypair,
    options=SigningOptions(
        Name="test",
        Ip="10.100.100.10/24",
    ),
)
# Write files to disk
ca_crt.write_pem_file("ca.crt")
ca_keypair.write_private_key("ca.key")
new_crt.write_pem_file("node.crt")
enc_keypair.write_private_key("node.key")
enc_keypair.write_public_key("node.pub")
# Verify that the certificate is valid
verify_certificate(ca_crt=ca_crt, crt=new_crt)

This example generates 5 files:

  • ca.crt: The CA certificate created during the first step.
  • ca.key: The private key of the CA. The public key is also present within this file.
  • node.crt: The certificate created during the second step.
  • node.key: The private key associated with the certificate. Unlike CA private keys, the public key is not present within the file.
  • node.pub: The public key associated with the certificate. The public key is also embedded within the certificate.

Load an existing CA and sign a new certificate

from quara.creds.nebula import (
    Certificate,
    EncryptionKeyPair,
    SigningKeyPair,
    SigningOptions,
    sign_certificate,
    verify_certificate,
)

# Load CA certificate
ca_crt = Certificate.from_file("ca.crt")
# Load CA keypair
ca_keypair = SigningKeyPair.from_file("ca.key")
# Create a new keypair for the certificate
enc_keypair = EncryptionKeyPair()
# Sign a new certificate
new_crt = sign_certificate(
    ca_key=ca_keypair,
    ca_crt=ca_crt,
    public_key=enc_keypair,
    options=SigningOptions(
        Name="test",
        Ip="10.100.100.10/24",
    ),
)
# Write files to disk
new_crt.write_pem_file("node.crt")
enc_keypair.write_private_key("node.key")
enc_keypair.write_public_key("node.pub")
# Verify that the certificate is valid
verify_certificate(ca_crt=ca_crt, crt=new_crt)

In this case, only 3 files are created, as the CA certificate and the CA key already existed before.

Load an existing CA, an existing public key, and sign a new certificate

from quara.creds.nebula import (
    Certificate,
    PublicEncryptionKey,
    SigningKeyPair,
    SigningOptions,
    sign_certificate,
    verify_certificate,
)

# Load CA certificate
ca_crt = Certificate.from_file("ca.crt")
# Load CA keypair
ca_keypair = SigningKeyPair.from_file("ca.key")
# Load public key from file
pub_key = PublicEncryptionKey.from_file("node.pub")
# Sign a new certificate
new_crt = sign_certificate(
    ca_key=ca_keypair,
    ca_crt=ca_crt,
    public_key=pub_key,
    options=SigningOptions(
        Name="test",
        Ip="10.100.100.10/24",
    ),
)
# Write files to disk
new_crt.write_pem_file("node.crt")
# Verify that the certificate is valid
verify_certificate(ca_crt=ca_crt, crt=new_crt)

In this case, only the certificate file is written to disk, as all other information was known before issuing the certificate.

Metadata

Release files for quara-creds 0.10.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for quara-creds 0.10.2
File Size Uploaded
quara_creds-0.10.2.tar.gz 33.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for quara-creds 0.10.2
File Interpreter ABI Platform
quara_creds-0.10.2-py3-none-any.whl Python 3 none any Details

Total release size: 91.3 kB

Release files / quara_creds-0.10.2.tar.gz

Download URL quara_creds-0.10.2.tar.gz
Size 33.7 kB
Tags Source
SHA-256 checksum
How to use checksums
e9e7dd1862b76c9a0ead22f24e34bb7753aaf2a4cf04025b7dfba7e3b2683b7a
BLAKE2b-256 checksum
How to use checksums
52f96611a625db852c438f9533b29c7e9a43395e530dc39c17b78ffbaa028c90
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.2.2 CPython/3.8.10 Linux/5.10.16.3-microsoft-standard-WSL2

Release files / quara_creds-0.10.2-py3-none-any.whl

Download URL quara_creds-0.10.2-py3-none-any.whl
Size 57.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f7571f36e676205650e14177270b2f2fe6dbc811af8d89538ed19903718c679f
BLAKE2b-256 checksum
How to use checksums
e8aca18c7c57ed841e6e45803eb7f8db676ed34558b9726820a2f675d4b568f3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.2.2 CPython/3.8.10 Linux/5.10.16.3-microsoft-standard-WSL2

Release history Release notifications | RSS feed

This release

0.10.2 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page