Has anyone used sftp with Lucee and a private key?...
# lucee
b
Has anyone used sftp with Lucee and a private key? I'm trying to figure out what format the private key file needs to be in. Just getting a vague "invalid key" exception
z
Which version? We updated the jsch to a fork
j
Would love to have better logging for ftp connections
q
Should be PEM encoded (base64). At least that's what I've been using for my stuff on 5.3.x
Do note -- the permissions on the file need to be correct. I think it will throw a "invalid key" error if you are doing anything other than 600 on linux based machines.
z
🎯 1
b
@quetwo Your answer was correct. We had the wrong format of key. The limited support for newer key formats is a real drag in what is a pretty common Java library (jsch). This is the same lib used by jGit which I use in CommandBox and it screws with people trying to use private keys for SSH git auth as well. I would have thought the Java community would do better at tracking new key formats as I've been hitting this for many years now.
z
is there a way to prevalidate they key in lucee?
b
I don't really know why you'd want to do that. Then you'd be duplicating logic in the jsch library and when it updated, Lucee would be out of date
Really, if the jsch library error messages were more useful, it would have been easier. I've dealt with jsch's terribly vague errors for years in CommandBox's jGit usage
q
PEM is the industry standard for key management. .P12 is the weird microsoft binary format that you are either converting from or two. JKS is extra weird because it's a binary format AND it's specific to the Java version you are on.
but yeah, jsch is kinda dumb for error messages. But security projects like dumb messages because of "security".
(I say that as a contributor to a bunch of apache security libraries. they REALLY hate verbose errors because it can 'help the bad guy out')
z
or hide bugs.... catch 22
q
None of my bugs are ever as big as Heartbleed.
z
one needs life goals!!!
q
One of my life goals is to end up in the New York Times. I guess something like would be the easiest path.
b
@quetwo PEM may be the standard, but most people who do a quick Google on how to create a private key on Windows will end up using Putty's keytool, and if you just click through the default settings there, you don't get a key format that any Jsch-powered tool will accept 😕
Actually, I think the last client who ran into this just used
ssh-keygen.exe
and it spit out something they couldn't use right away
Of course, just running
Copy code
ssh-keygen.exe -t rsa -m PEM
isn't too hard, but if I had a dollar every time I had to explain to a CommandBox user why their Git SSH auth wouldn't work after they cranked out a default private key, I'd have at least 20 dollars, lol
And, of course, the error is entirely unhelpful, just a generic "auth failure" or something.
q
Personally, I live in the openssl world.. The PuTTY tools were always.... weird.