-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathcreate_encryption_key.py
84 lines (67 loc) · 2.31 KB
/
create_encryption_key.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
import os
import sys
import json
from cryptography.fernet import Fernet
import logging
def setup_logging():
logging.basicConfig(
level=logging.INFO,
format="%(asctime)s — %(levelname)s — %(message)s",
)
return logging.getLogger()
logger = setup_logging()
def generate_key():
"""
Generates a Fernet encryption key.
"""
key = Fernet.generate_key()
return key
def save_key(key, file_path):
"""
Saves the encryption key to a file with restricted permissions.
"""
try:
with open(file_path, "wb") as key_file:
key_file.write(key)
logger.info(f"Encryption key saved to '{file_path}'.")
except Exception as e:
logger.error(f"Failed to save encryption key: {e}")
sys.exit(1)
def main():
# Define the key file path
key_file = "encryption_key.key"
# Check if the key file already exists to prevent overwriting
if os.path.exists(key_file):
logger.error(
f"Encryption key file '{key_file}' already exists. Generation aborted to prevent overwriting."
)
sys.exit(1)
# Generate the encryption key
logger.info("Generating encryption key...")
key = generate_key()
# Save the key to the file
save_key(key, key_file)
# Optionally, set file permissions (Windows and Unix/Linux)
try:
if os.name == "nt":
# On Windows, use the built-in `icacls` tool to restrict permissions
os.system(f'icacls "{key_file}" /inheritance:r /grant:r "%USERNAME%:F"')
logger.info(
f"File permissions set to allow only the current user to access '{key_file}'."
)
else:
# On Unix/Linux, set the file permission to read/write for the user only
os.chmod(key_file, 0o600)
logger.info(
f"File permissions set to read/write for the user only on '{key_file}'."
)
except Exception as e:
logger.error(f"Failed to set file permissions: {e}")
sys.exit(1)
# Display the key to the user (optional and should be handled securely)
logger.info("Encryption key generation complete.")
print(
f"Your encryption key has been saved to '{key_file}'. Please keep it secure and do not share it."
)
if __name__ == "__main__":
main()