Security Artifacts

Utilities Projects Requires: internet connection

Manage shared artifacts for this project such as device keys and certificates.

This is also where a Service Manager Service Key comes from — see Service Security..., which shows (None) until a key like this exists. See New Service Key below to create one.

On the toolbar, click Projects, then click MANAGE ARTIFACTS on the Security Artifacts card. The panel lists the project's shared keys, with each key's Type, its Creator, and IsLocal? — whether it's on this PC:

  1. New Device Key — an SSH key for locking a display. See Lock Target.
  2. New Application Key — a key for signing your packages. It's listed as a PackageSigningKey.
  3. New Service Key — a key for securing your services. See Service Security.
  4. Remove Key — deletes the selected key from the project.
  5. Import Key — see the note at the end of this page.
  6. Download Key — copies the selected key to this PC. It's only enabled while the key isn't on this PC.
The Security Artifacts panel, numbered
The Security Artifacts panel, numbered

New Device Key

Watch video walkthrough

  1. Click New Device Key.

    The New Device Key button
    The New Device Key button
  2. Create Device Key opens. The key is shared with the team, and saved in your .ssh folder.

    The Create Device Key dialog
    The Create Device Key dialog
  3. Type a name — here, DeviceDemoKey — then click Ok.

    The device key name entered
    The device key name entered
  4. The key is listed straight away as a DeviceKey, with IsLocal? showing True.

    The new device key in the list
    The new device key in the list
Note: A device key is saved in %USERPROFILE%\.ssh\Ahsoka\ as two files: the private key, named after the key with no extension, and a .pub public key. If a key with that name is already there, the toolkit shares that existing key instead of making a new one.
Note: Use letters and numbers only in key names — other characters are dropped from the shared name. If the project already has a key with that name, Duplicate Key appears instead.

New Application Key

Watch video walkthrough

  1. Click New Application Key.

    The New Application Key button
    The New Application Key button
  2. Create Application Certificate opens. The certificate is shared with the team, for signing your application packages.

    The Create Application Certificate dialog
    The Create Application Certificate dialog
  3. Type a name — here, AppDemokey — then click Ok.

    The application key name entered
    The application key name entered
  4. The key is listed straight away as a PackageSigningKey.

    The new application key in the list
    The new application key in the list
Note: This is the key you pick from the Signing Key list on the Packaging panel's Package Options. It's saved on this PC as AppDemokey.appcert, in %LOCALAPPDATA%\AhsokaData\AhsokaCerts\.

New Service Key

Watch video walkthrough

  1. Click New Service Key.

    The New Service Key button
    The New Service Key button
  2. Create Service Certificate opens. Its hint is the same as the application certificate's, about compiling applications, but a service key is for securing your services.

    The Create Service Certificate dialog
    The Create Service Certificate dialog
  3. Type a name — here, ServiceDemoKey — then click Ok. This makes a new key pair, saves it on this PC, and shares it with the project so any team member can use the same key.

    The service key name entered
    The service key name entered
  4. The key is listed straight away as a ServiceKey.

    The new service key in the list
    The new service key in the list
Note: This is the key you pick from the Service Key list under Service Security... on the Service Manager panel — see that section to put it to use. It's saved on this PC as ServiceDemoKey.servicecert, in %LOCALAPPDATA%\AhsokaData\AhsokaCerts\.
Note: Creating an application or service key always makes a new key pair, and replaces any local file with the same name.

Download Key

Watch video walkthrough

  1. Keys are shared with everyone on the project, but each one only works once it's on your own PC — for example, to connect to a display locked with a teammate's device key. Here, DeviceDemoKey shows IsLocal? False: it's in the project, but not on this PC. Click it to select it.

    DeviceDemoKey listed with IsLocal? False
    DeviceDemoKey listed with IsLocal? False
  2. Click Download Key.

    DeviceDemoKey selected, and the Download Key button
    DeviceDemoKey selected, and the Download Key button
  3. The key downloads straight away, with no dialog, and IsLocal? changes to True. A device key goes to your .ssh\Ahsoka folder, where the SSH Key File list on the SSH Connection tab picks it up the next time the toolkit starts.

    DeviceDemoKey now showing IsLocal? True
    DeviceDemoKey now showing IsLocal? True
Note: Download Key downloads whichever key is selected, so check the selected row first. Application and service keys download to %LOCALAPPDATA%\AhsokaData\AhsokaCerts\, as .appcert and .servicecert files.
Note: Remove Key asks Are you sure you want remove the selected key?, then deletes the key from the project for everyone. Application and service keys are deleted from this PC too; device key files are kept. A display locked with a removed device key still needs that key to connect, so keep a copy.
Note: Import Key doesn't bring in the key file you pick. If the project has no key with that name, it makes a brand-new key instead. To share a device key you already have, put it in .ssh\Ahsoka and click New Device Key with the same name — the toolkit shares that existing key.
Note: Click Return to go back to the Projects panel.