Skip to main content

Python CLI to share secret files via github with symmetric encryption ed25519.

Project description

symmetric-secret-share

Python CLI to share secret files via github with symmetric encryption ed25519.

  • IMPORTANT: The secret files should be git-ignored to avoid oblivious leakage.
  • Temporarily supports only text files (only tested with .env).
  • Best used to store/share secrets and configurations.
  • Key should be a 32-byte long string, meanly, 32 ASCII, 16 two-byte UTF-8 or 8 four-byte UTF-8 characters.
  • (FAQ) If you share with GitHub (like the example), please notice that there's a 5 minutes cool-down on refreshing. Detail However, GitHub Gist seems doesn't have this cool-down limitation.

Use

  1. Install CLI: pip3 install symmetric-secret-share.
  2. Check the Tutorial Chapter and sss --help.
  3. Recommended: set up a global key chain with sss key, or you would have to input a key every time.
  4. Get a config like $REPO_ROOT/tests/injection/sss.json. The JSON-schema in $schema of this file will help you write the config file.

inject

  1. Get a config file like $REPO_ROOT/tests/injection/sss.json.

  2. Run CLI

    sss inject [-k TEXT] CONFIG_PATH
    

share

  1. Run CLI

    sss share [-k TEXT] CONFIG_PATH
    

key

  1. Run CLI

    sss key [-c/f/g] # -g: generate one key, -c: clear key chain, -f: force
    
  2. Upload the generated file to GitHub (or other platforms).

  3. Update the config file if needed.

Security

  • There are 256**32==1,15e+77 keys of 32 of ASCII (one-byte utf-8 string).
  • To generate ASCII key, you can use sss key --generate.
  • To generate two-byte utf-8 string, a possibility is to use onlineutf8tools

Contribute

Tutorial

In this tutorial, all commands are assumed to be run under the $REPO_ROOT. We are going to use these concepts and variables:

  • key chain: A file to share key, initialized with sss key.
  • key: This key contains 32 characters..
  • URL: https://raw.githubusercontent.com/PabloLION/symmetric-secret-share/main/tests/example.encrypted.

We are going to play with the folder test/injection, with the sss.json file inside it. To share your own file, a new config file should be created.

Setup a local key chain

sss key # create/edit
sss key -c # clear all keys

load files from URL

These code will generate a test/injection/target.env like test/example.env

sss inject ./tests/injection/sss.json # use key from initial key chain
sss inject -k "This key contains 32 characters." ./tests/injection/sss.json
sss inject ./tests/injection/sss.json -k "I'm a string with 32 characters." # fail

share files

Need to upload manually #TODO These code will generate a test/injection/target.encrypted

sss share ./tests/injection/sss.json # use key from initial key chain
sss share -k "This key contains 32 characters." ./tests/injection/sss.json

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

symmetric-secret-share-0.0.8.tar.gz (11.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

symmetric_secret_share-0.0.8-py3-none-any.whl (12.4 kB view details)

Uploaded Python 3

File details

Details for the file symmetric-secret-share-0.0.8.tar.gz.

File metadata

  • Download URL: symmetric-secret-share-0.0.8.tar.gz
  • Upload date:
  • Size: 11.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.1.12 CPython/3.10.1 Darwin/21.2.0

File hashes

Hashes for symmetric-secret-share-0.0.8.tar.gz
Algorithm Hash digest
SHA256 a93877c7a2e544d5e00d4fcf6417756e5310df1d6a643f9afac91e4e830bf48b
MD5 aa3121eb38184a57f1394b918fb55cbf
BLAKE2b-256 9999a9e083e9e68c8ce4749fb12a7bcc7b8747d6c98c33f8d5e67ec3800e0f0d

See more details on using hashes here.

File details

Details for the file symmetric_secret_share-0.0.8-py3-none-any.whl.

File metadata

File hashes

Hashes for symmetric_secret_share-0.0.8-py3-none-any.whl
Algorithm Hash digest
SHA256 f62bdb6393b5abd24b069f109efc091bb57ebb4d8936d07f9b31488901d7ec29
MD5 cad51a619db433f0e33661ee513de9fb
BLAKE2b-256 7041aeffa916c25fbadf401fd5ed2c25aa4e987a076eb40ebba4205cb4c01c7c

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page