Security News
Maven Central Adds Sigstore Signature Validation
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
Openssl-ts is a modern openssl wrapper written in typescript with 0 dependencies.
This library is not responsible of doing any filesystem operations (read/write). It just handles the openssl calls.
Output from openssl should be handled by the caller (you).
This project has been testing with Node >= v8.17 and with openssl >= 1.1.1m
Using npm:
npm install openssl-ts
or using the Yarn package manager:
yarn add openssl-ts
The signature is pretty simple:
First parameter is an array of strings (openssl arguments). The second parameter is an optional object with the following properties:
opensslPath: path to the openssl executable.
You can override this by using the OPENSSL_PATH
environment variable as well.
Default: openssl
(must be in the PATH)
stdin: buffer to be passed to openssl as stdin
This would be like using cat
and piping the input to openssl.
example: cat private.key | openssl rsa -check
Why would you want to do this? Simple, sometimes you have the content already on ram and you want to pass it to openssl without the need to first write it to a file.
Notice: cat
is not being used to pipe the input to openssl.
import { openssl } from 'openssl-ts';
const output = await openssl(['genrsa', '-out', 'private.key', '2048']);
// output is a Buffer
console.log(output.toString());
/*
Generating RSA private key, 2048 bit long modulus (2 primes)
................................................+++++
...........+++++
e is 65537 (0x010001)
*/
// if you want the private.key content, you should read the file from the filesystem
import { openssl } from 'openssl-ts';
const output = await openssl(['genrsa', '2048']);
// output is a Buffer
console.log(output.toString());
/*
Generating RSA private key, 2048 bit long modulus (2 primes)
....................................................................+++++
.............................+++++
e is 65537 (0x010001)
-----BEGIN RSA PRIVATE KEY-----
MIIEowIBAAKCAQEAoNKO2MDD9TzZ9KpSJ7JAuIWDhTY5qZJGbgUltnUKqTts+A7s
...
-----END RSA PRIVATE KEY-----
*/
// if you want just the key you must parse the output
import { openssl } from 'openssl-ts';
const output = await openssl(['rsa', '-in', 'private.key', '-check']);
// output is a Buffer
console.log(output.toString());
/*
RSA key ok
writing RSA key
-----BEGIN RSA PRIVATE KEY-----
....
-----END RSA PRIVATE KEY-----
*/
import { openssl } from 'openssl-ts';
const buffer = readFileSync('private.key');
const output = await openssl(['rsa', 'check'], {
stdin: buffer,
});
// output is a Buffer
console.log(output.toString());
/*
RSA key ok
writing RSA key
-----BEGIN RSA PRIVATE KEY-----
....
-----END RSA PRIVATE KEY-----
*/
Running all test:
yarn test
Running with coverage:
yarn test:cov
You can use the NODE_DEBUG
environment variable to enable debugging.
Example:
NODE_DEBUG=openssl node yourscript.js
This will print the openssl command that will be executed and its parameters.
FAQs
An openssl wrapper written in TypeScript
The npm package openssl-ts receives a total of 0 weekly downloads. As such, openssl-ts popularity was classified as not popular.
We found that openssl-ts demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
Security News
CISOs are racing to adopt AI for cybersecurity, but hurdles in budgets and governance may leave some falling behind in the fight against cyber threats.
Research
Security News
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.