Skip to content

fix(scripts): find an openssl that can do Ed25519 - #8

Merged
jeremiahsay merged 1 commit into
mainfrom
fix/rotate-key-openssl
Sep 10, 2026
Merged

jeremiahsay merged 1 commit into
mainfrom
fix/rotate-key-openssl

Conversation

@jeremiahsay

Copy link
Copy Markdown
Collaborator

macOS ships LibreSSL as /usr/bin/openssl, and it cannot generate Ed25519 keys. rotate-registry-key.sh called bare openssl, so on any machine where that one is first on PATH it would have produced an empty key and set a useless secret. It only worked here because Homebrew's OpenSSL 3.6.4 shadows it.

The script now probes candidates for a working Ed25519 keygen — bare openssl, then the two Homebrew openssl@3 paths — and tells you to brew install openssl@3 if none can, instead of failing three commands later.

The existing length checks would have caught it, but only after the secret was already set.

Verified: the resolver picks /opt/homebrew/bin/openssl and derives 64-char hex / 44-char base64. bash -n clean.

Credit where due — the old LAUNCH-MCP-DIRECTORIES.md runbook in the gateway repo already warned about this. I rediscovered it the hard way.

🤖 Generated with Claude Code

https://claude.ai/code/session_01V5hFP2B2vU4dUMYgM1NEVs

macOS ships LibreSSL as /usr/bin/openssl and it cannot generate Ed25519
keys. The script would have produced an empty key and set a useless
secret on any machine where that one is first on PATH — it only worked
here because Homebrew OpenSSL 3.6.4 shadows it.

It now probes candidates for an actual Ed25519 keygen and says what to
install if none can, instead of failing silently three commands later.

Resolver tested: picks /opt/homebrew/bin/openssl, derives 64-char hex and
44-char base64.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V5hFP2B2vU4dUMYgM1NEVs
@jeremiahsay
jeremiahsay merged commit bbb370d into main Sep 10, 2026
4 checks passed
@jeremiahsay
jeremiahsay deleted the fix/rotate-key-openssl branch September 10, 2026 11:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant