From 680ae1be88d22f2eb5d6f16a58acda4e5927ed72 Mon Sep 17 00:00:00 2001 From: J08nY Date: Fri, 18 Aug 2017 16:48:46 +0200 Subject: Refactor merging of new key signatures out of `key` command. --- src/mailman_pgp/utils/pgp.py | 45 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+) (limited to 'src/mailman_pgp/utils') diff --git a/src/mailman_pgp/utils/pgp.py b/src/mailman_pgp/utils/pgp.py index be97a75..05721b4 100644 --- a/src/mailman_pgp/utils/pgp.py +++ b/src/mailman_pgp/utils/pgp.py @@ -179,3 +179,48 @@ def key_usable(key, flags_required): if bool(verified): return False return flags_required.issubset(key_flags(key)) + + +@public +def key_merge(privkey, new_key, signer_key): + """ + + :param privkey: + :type privkey: pgpy.PGPKey + :param new_key: + :type new_key: pgpy.PGPKey + """ + if privkey.pubkey.key_material != new_key.key_material: + raise ValueError('You sent a wrong key.') + + uid_map = {} + for uid in privkey.userids: + for uid_other in new_key.userids: + if uid == uid_other: + uid_map[uid] = uid_other + + if len(uid_map) == 0: + raise ValueError('No signed UIDs found.') + + uid_sigs = {} + for uid, uid_other in uid_map.items(): + for sig in uid_other.signatures: + if sig in uid.signatures: + continue + if sig.signer != signer_key.fingerprint.keyid: + continue + # sig is a new signature, not currenctly on uid, ans seems to + # be made by the pgp_address.key + try: + verification = signer_key.verify(uid, sig) + if bool(verification): + uid_sigs.setdefault(uid, []).append(sig) + except PGPError: + pass + + if len(uid_sigs) == 0: + raise ValueError('No new certifications found.') + + for uid, sigs in uid_sigs.items(): + for sig in sigs: + uid |= sig -- cgit v1.2.3-70-g09d2