+ # The first field is keytype again.
+ if subfields[0] != sshkeytype:
+ raise KeyFormatError("""
+ outer and embedded key types do not match: '%s', '%s'
+ """ % (sshkeytype, subfields[1]))
+
+ # Translate key type string into something PuTTY can use, and
+ # munge the rest of the data.
+ if sshkeytype == "ssh-rsa":
+ keytype = "rsa2"
+ # The rest of the subfields we can treat as an opaque list
+ # of bignums (same numbers and order as stored by PuTTY).
+ keyparams = map (strtolong, subfields[1:])
+
+ elif sshkeytype == "ssh-dss":
+ keytype = "dss"
+ # Same again.
+ keyparams = map (strtolong, subfields[1:])
+
+ elif sshkeytype == "ecdsa-sha2-nistp256" \
+ or sshkeytype == "ecdsa-sha2-nistp384" \
+ or sshkeytype == "ecdsa-sha2-nistp521":
+ keytype = sshkeytype
+ # Have to parse this a bit.
+ if len(subfields) > 3:
+ raise KeyFormatError("too many subfields in blob")
+ (curvename, Q) = subfields[1:]
+ # First is yet another copy of the key name.
+ if not re.match("ecdsa-sha2-" + re.escape(curvename),
+ sshkeytype):
+ raise KeyFormatError("key type mismatch ('%s' vs '%s')"
+ % (sshkeytype, curvename))
+ # Second contains key material X and Y (hopefully).
+ # First a magic octet indicating point compression.
+ if struct.unpack("B", Q[0])[0] != 4:
+ # No-one seems to use this.
+ raise KeyFormatError("can't convert point-compressed ECDSA")
+ # Then two equal-length bignums (X and Y).
+ bnlen = len(Q)-1
+ if (bnlen % 1) != 0:
+ raise KeyFormatError("odd-length X+Y")
+ bnlen = bnlen / 2
+ (x,y) = Q[1:bnlen+1], Q[bnlen+1:2*bnlen+1]
+ keyparams = [curvename] + map (strtolong, [x,y])
+
+ elif sshkeytype == "ssh-ed25519":
+ # FIXME: these are always stored point-compressed, which
+ # requires actual maths
+ raise KeyFormatError("can't convert ssh-ed25519 yet, sorry")