1<?php
2
3if (PHP_SAPI !== 'cli') {
4 exit(1);
5}
6
7$outputRoot = rtrim((string)($argv[1] ?? ''), '/\\');
8$publicKeyFile = (string)($argv[2] ?? '');
9$privateKeyFile = $outputRoot . '/.signing/private.pem';
10$options = array(
11 'config' => __DIR__ . '/openssl.cnf',
12 'private_key_bits' => 3072,
13 'private_key_type' => OPENSSL_KEYTYPE_RSA,
14);
15
16if ($outputRoot === '' || $publicKeyFile === '' || (is_file($privateKeyFile) && filesize($privateKeyFile) > 0)) {
17 fwrite(STDERR, "Invalid key destination or an existing private key.\n");
18 exit(1);
19}
20
21$key = openssl_pkey_new($options);
22if ($key === false || !openssl_pkey_export($key, $privatePem, null, $options)) {
23 fwrite(STDERR, "OpenSSL could not generate the private key.\n");
24 exit(1);
25}
26$details = openssl_pkey_get_details($key);
27if (!is_array($details) || file_put_contents($privateKeyFile, $privatePem, LOCK_EX) === false || file_put_contents($publicKeyFile, $details['key'], LOCK_EX) === false) {
28 fwrite(STDERR, "The signing keys could not be saved.\n");
29 exit(1);
30}
31
32echo $privateKeyFile . PHP_EOL;
33echo $publicKeyFile . PHP_EOL;
34