Installing Phoenix adds a phoenix command (also available as
python -m phoenix).
$ phoenix --help
usage: phoenix [-h] [--version] {keygen,encrypt,decrypt,info,params,playground} ...
Every command exits with status 0 on success and 1 on failure, printing
phoenix: error: … to standard error.
phoenix keygen$ phoenix keygen -o alice
public key: alice.pub
private key: alice.key (keep this secret)
| Option | Meaning |
|---|---|
-o, --out NAME |
Write NAME.pub and NAME.key (default phoenix) |
-p, --params SET |
Parameter set (default phoenix677) |
-f, --force |
Overwrite existing files |
Both files are PEM-style text. The private key is created with mode 0600.
Without --force, keygen refuses to overwrite either file, so you cannot
destroy a key by re-running a command from your history.
phoenix encrypt$ phoenix encrypt -k alice.pub -i note.txt -o note.phx
| Option | Meaning |
|---|---|
-k, --key FILE |
Recipient’s public key (required) |
-i, --input FILE |
Plaintext; - or omitted reads standard input |
-o, --output FILE |
Destination; - or omitted writes standard output |
-a, --armor |
Write base64 text instead of binary |
--aad TEXT |
Associated data to authenticate alongside the message |
The whole input is read into memory and sealed as one message.
phoenix decrypt$ phoenix decrypt -k alice.key -i note.phx
meet me at the old bridge
| Option | Meaning |
|---|---|
-k, --key FILE |
Your private key (required) |
-i, --input FILE |
Sealed message, binary or armored (detected automatically) |
-o, --output FILE |
Destination; defaults to standard output |
--aad TEXT |
The associated data given when encrypting |
Nothing is written unless the message authenticates:
$ phoenix decrypt -k alice.key -i note.phx --aad wrong
phoenix: error: message authentication failed
$ phoenix decrypt -k alice.pub -i note.phx
phoenix: error: expected a phoenix private key, got a phoenix public key
encrypt and decrypt default to standard input and output, so they compose:
$ tar cz project/ | phoenix encrypt -k alice.pub > project.tgz.phx
$ phoenix decrypt -k alice.key < project.tgz.phx | tar xz
$ echo hi | phoenix encrypt -k alice.pub --armor
-----BEGIN PHOENIX MESSAGE-----
UEhOWAEDAqUDAAAIAAB/AH8Afysum8M2jo2tREb8iputqGK7qZhPHJjD3G7PHeNjG7xkP1R5WdG9
...
phoenix infoDescribes a key or sealed message without needing any key:
$ phoenix info note.phx
type: sealed message
parameters: phoenix677 (N=677, p=3, q=2048, df=127, dg=127, dr=127)
size: 992 bytes
plaintext: 26 bytes
Note what this shows: the plaintext length is visible to anyone holding the ciphertext. Pad your messages if their length is sensitive.
phoenix params$ phoenix params
name N p q df dg dr pk bytes ct bytes
phoenix509 509 3 2048 127 127 127 719 700
phoenix677 677 3 2048 127 127 127 950 931 (default)
phoenix821 821 3 4096 255 255 255 1251 1232
toy 7 3 41 2 2 2 25 6
phoenix playgroundStarts the local web playground.
| Option | Meaning |
|---|---|
--port N |
Port to listen on (default 8765) |
--no-browser |
Do not open a browser window |