A dead simple tool to sign files and verify digital signatures. https://jedisct1.github.io/minisign/
Find a file
2019-08-28 14:17:41 +02:00
share/man/man1 No need to manually move the secret key to ~/.minisign any more 2016-08-01 01:17:25 +02:00
src Progressively reduce the parameters on low memory 2019-08-28 14:17:41 +02:00
.gitignore Use Findsodium.cmake, add the ability to statically link the library 2019-06-01 11:21:52 +02:00
.travis.yml cmake... 2019-06-01 15:53:44 +02:00
CMakeLists.txt Move up 2019-07-23 21:24:12 +02:00
LICENSE 2018 2017-12-31 19:18:28 +01:00
README.md Remove Minisign-py 2019-07-26 10:25:02 +02:00

Minisign

Minisign is a dead simple tool to sign files and verify signatures.

For more information, please refer to the Minisign documentation

Tarballs and pre-compiled binaries can be verified with the following public key:

RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3

Compilation / installation

Dependencies:

Compilation:

$ mkdir build
$ cd build
$ cmake ..
$ make
# make install

Alternative configuration for static binaries:

$ cmake .. -D STATIC_LIBSODIUM=1

or:

$ cmake .. -D BUILD_STATIC_EXECUTABLES=1

Minisign is also available in Homebrew:

$ brew install minisign

Minisign is also available in Scoop on Windows:

$ scoop install minisign

Minisign is also available in chocolatey on Windows:

$ choco install minisign

Additional tools, libraries and implementations

  • minisign-misc is a very nice set of workflows and scripts for macOS to verify and sign files with minisign.
  • go-minisign is a small module in Go to verify Minisign signatures.
  • rust-minisign is a Minisign library written in pure Rust, that can be embedded in other applications.
  • rsign2 is a reimplementation of the command-line tool in Rust.
  • minisign-verify is a small Rust crate to verify Minisign signatures.
  • minisign-net is a .NET library to handle and create Minisign signatures.
  • minisign a Javascript implementation.
  • WebAssembly implementations of rsign2 and minisign-cli are available on WAPM.

Signature determinism

This implementation uses deterministic signatures, unless libsodium was compiled with the ED25519_NONDETERMINISTIC macro defined. This adds random noise to the computation of EdDSA nonces.

Other implementations can choose to use non-deterministic signatures by default. They will remain fully interoperable with implementations using deterministic signatures.