keys¶
Signing key management for the local Ed25519 keypair that signs artifacts, dossiers and approval tokens.
Today the group has one subcommand, keys rotate. For where the keys live and how to verify a signature, see Key management.
keys rotate¶
Generate a new keypair, archive the old one and print the new public key fingerprint.
| Option | Default | Description |
|---|---|---|
--output / -o | human | human or json. |
What it does:
- Copies
~/.opencomplai/signing.keytosigning.key.prev(mode0600) andsigning.pubtosigning.pub.prev. Only the most recent previous pair is kept; a second rotation overwrites it. - Writes a new
signing.keyandsigning.pub. - Stores the new
install_idin the local config. - Prints the new
install_id, the public key fingerprint (sha256:and the first 16 hex characters of the SHA-256 of the public key file) and the path of the archived private key.
With --output json the same facts are one object with status (rotated), new_install_id, public_key_fingerprint and archived_to.
The recommended cadence is every 90 days.
What to do afterwards¶
- Artifacts signed before the rotation do not verify against the new public key. Keep
signing.pub.previf you need to verify older files, and pass it as the public key toverify. - If this install is enrolled in the dashboard, update the enrolment with the new public key; see dashboard.
Exit codes¶
| Code | Meaning |
|---|---|
| 0 | Rotated. |
| 1 | The cryptography package is not installed. |
| 2 | No signing key exists yet. Run init first. |