# Golang app to encrypt nginx config content.example.com.conf
# Uses 37b723a1207eac79af4acffa0b74b9f3 as encryption key
package main
import (
"crypto/aes"
"crypto/cipher"
"crypto/md5"
"crypto/rand"
"encoding/hex"
"fmt"
"io"
"io/ioutil"
"log"
"os"
)
func createHash(key string) string {
hasher := md5.New()
hasher.Write([]byte(key))
return hex.EncodeToString(hasher.Sum(nil))
}
func encrypt(data []byte, passphrase string) []byte {
block, _ := aes.NewCipher([]byte(createHash(passphrase)))
gcm, err := cipher.NewGCM(block)
if err != nil {
panic(err.Error())
}
nonce := make([]byte, gcm.NonceSize())
if _, err = io.ReadFull(rand.Reader, nonce); err != nil {
panic(err.Error())
}
ciphertext := gcm.Seal(nonce, nonce, data, nil)
return ciphertext
}
func decrypt(data []byte, passphrase string) []byte {
key := []byte(createHash(passphrase))
block, err := aes.NewCipher(key)
if err != nil {
panic(err.Error())
}
gcm, err := cipher.NewGCM(block)
if err != nil {
panic(err.Error())
}
nonceSize := gcm.NonceSize()
nonce, ciphertext := data[:nonceSize], data[nonceSize:]
plaintext, err := gcm.Open(nil, nonce, ciphertext, nil)
if err != nil {
panic(err.Error())
}
return plaintext
}
func encryptFile(filename string, data []byte, passphrase string) {
f, _ := os.Create(filename)
defer f.Close()
f.Write(encrypt(data, passphrase))
}
func decryptFile(filename string, passphrase string) []byte {
data, _ := ioutil.ReadFile(filename)
return decrypt(data, passphrase)
}
func main() {
fmt.Println("encrypting content.example.com.conf to cc.db")
data, err := ioutil.ReadFile("content.example.com.conf")
if err != nil {
log.Fatal(err)
}
encryptFile("cc.db", data, "37b723a1207eac79af4acffa0b74b9f3")
}