Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
cli-jwk-to-pem
Advanced tools
Convert a json web key to a PEM for use by OpenSSL or crypto
.
npm install jwk-to-pem-cli -g
Usage: jwk-to-pem [options]
CLI to convert jwk to pem
Options:
-V, --version output the version number
--jwk <type> The JSON Web Key in string format that you want to convert to PEM.
-p, --public Outputs the PEM as a public key. If this flag is provided, the command will convert the JWK to a PEM format for a public key. (default: false)
-h, --help display help for command
jwk-to-pem --jwk '{"kty":"RSA","n":"jp....tOg0l7H0OhpG7Ey2RuO8"}'
Output:
-----BEGIN PRIVATE KEY-----
MIIEvAIBADANBgkqhkiG9w0BAQEFAASCBKYwggSiAgEAAoIBAQCOmKau+pJqxgip
******
6nsdbpCh30e1qUmDK6lvKcv8TYQo2Z3+kNiLg+8jx7bKxIMA5ETdLGoc/RQ0CGqC
++06DSXsfQ6GkbsTLZG47w==
-----END PRIVATE KEY-----
npm install jwk-to-pem --save
var jwkToPem = require('jwk-to-pem'),
jwt = require('jsonwebtoken');
var jwk = { kty: 'EC', crv: 'P-256', x: '...', y: '...' },
pem = jwkToPem(jwk);
jwt.verify(token, pem);
key type | support level |
---|---|
RSA | all RSA keys |
EC | P-256, P-384, and P-521 curves |
jwkToPem(Object jwk[, Object options])
-> String
The first parameter should be an Object representing the jwk, it may be public or private. By default, either of the two will be made into a public PEM. The call will throw if the input jwk is malformed or does not represent a valid key.
Boolean
(false)You may optionally specify that you would like a private PEM. This can be done
by passing true
to the private
option. The call will throw if the necessary
private parameters are not available.
Fork the repository. Committing directly against this repository is highly discouraged.
Make your modifications in a branch, updating and writing new unit tests
as necessary in the spec
directory.
Ensure that all tests pass with npm test
rebase
your changes against master. Do not merge.
Submit a pull request to this repository. Wait for tests to run and someone to chime in.
This repository is configured with EditorConfig and ESLint rules.
FAQs
Convert a JSON Web Key to a PEM
The npm package cli-jwk-to-pem receives a total of 9 weekly downloads. As such, cli-jwk-to-pem popularity was classified as not popular.
We found that cli-jwk-to-pem demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.