peer-to-peer encrypted streams using public key cryptography and signing
Create encrypted peer-to-peer streams using public key cryptography and signing.
No certificates, no authorities. Each side of the connection has the same kind of keys so it doesn't matter which side initiates the connection.
First generate some public/private keypairs with rsa-json:
$ rsa-json > a.json$ rsa-json > b.json
var secure = require'secure-peer';var peer = securerequire'./a.json';var through = require'through';var net = require'net';var server = netcreateServervar sec = peerstreampipethroughthisemit'data' StringbuftoUpperCase;pipestream;;secpiperawStreampipesec;;serverlisten5000;
var secure = require'secure-peer';var peer = securerequire'./b.json';var net = require'net';var rawStream = netconnect5000;var sec = peerstreampipeprocessstdout;streamend'beep boop\n';;secpiperawStreampipesec;secon'identify'// you can asynchronously verify that the key matches the known value hereidaccept;;
For extra security, you should keep a file around with known hosts to verify
that the public key you receive on the first connection doesn't change later
on like how
Maintaining a known hosts file is outside the scope of this module.
var secure = require'secure-peer'
Return a function to create streams given the
keys.private should be a private PEM string and
keys.public should be a
public PEM string.
You can generate keypairs with rsa-json.
Create a new duplex stream
Emitted when the secure connection has been established successfully.
stream.id is the identify object from the
Emitted when the connection identifies with its public key,
Each listener must call either
The connection won't be accepted until all listeners call
id.accept(). If any
id.reject(), the connection will be aborted.
Accept the connection. This function must be called for every listener on the
'identify' event for the connection to succeed.
Reject the connection. The connection will not succeed even if
called in another listener.
Emitted when the remote side provides a signed header.payload json string signed with its private key in header.hash.
With npm do:
npm install secure-peer