
أداة تشفير بسيطة وحديثة وآمنة (ومكتبة Go) بمفاتيح واضحة وصغيرة، بدون خيارات تهيئة، وقابلية للتركيب على نمط يونكس.
age هي أداة تشفير ملفات بسيطة وحديثة وآمنة، وصيغة، ومكتبة Go.
تتميز بمفاتيح صغيرة وواضحة، ودعم ما بعد الكم، وعدم وجود خيارات إعداد، وقابلية تركيب على نمط UNIX.
$ age-keygen -o key.txt
Public key: age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p
$ tar cvz ~/data | age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p > data.tar.gz.age
$ age --decrypt -i key.txt data.tar.gz.age > data.tar.gz
📜 مواصفات الصيغة موجودة في age-encryption.org/v1. صُمم age بواسطة @benjojo و@FiloSottile.
🦀 يوجد تنفيذ بديل متوافق بلغة Rust في github.com/str4d/rage.
🌍 Typage هو تنفيذ بلغة TypeScript. يعمل في المتصفح، وNode.js، وDeno، وBun.
🔑 تُدعم رموز PIV للأجهزة مثل YubiKeys من خلال إضافة age-plugin-yubikey.
✨ لمزيد من الإضافات والتنفيذات والأدوات والتكاملات، اطّلع على قائمة awesome age.
💬 ينطق المؤلف الاسم [aɡe̞] بـ g قاسية، مثل GIF، ويُكتب دائمًا بأحرف صغيرة.
| Homebrew (macOS أو Linux) |
brew install age
|
| MacPorts |
port install age
|
| Windows |
winget install --id FiloSottile.age
|
| Alpine Linux v3.15+ |
apk add age
|
| Arch Linux |
pacman -S age
|
| Debian 12+ (Bookworm) |
apt install age
|
| Debian 11 (Bullseye) |
apt install age/bullseye-backports
(فعّل backports لإصدار age v1.0.0+)
|
| Fedora 33+ |
dnf install age
|
| Gentoo Linux |
emerge app-crypt/age
|
| Guix System |
guix package -i age
|
| NixOS / Nix |
nix-env -i age
|
| openSUSE Tumbleweed |
zypper install age
|
| Ubuntu 22.04+ |
apt install age
|
| Void Linux |
xbps-install age
|
| FreeBSD |
pkg install age (security/age)
|
| OpenBSD 6.7+ |
pkg_add age (security/age)
|
| Chocolatey (Windows) |
choco install age.portable
|
| Scoop (Windows) |
scoop bucket add extras && scoop install age
|
على Windows وLinux وmacOS وFreeBSD يمكنك استخدام الملفات الثنائية المُجمّعة مسبقًا.
إذا قمت بتنزيل الملفات الثنائية المُجمّعة مسبقًا، يمكنك التحقق من إثباتات Sigsum.
إذا كان نظامك يحتوي على إصدار مدعوم من Go، يمكنك البناء من المصدر.
go install filippo.io/age/cmd/...@latest
المساعدة من مُعبّئي الحزم الجدد مرحّب بها جدًا.
للحصول على التوثيق الكامل، اقرأ صفحة الدليل age(1).
Usage:
age [--encrypt] (-r RECIPIENT | -R PATH)... [--armor] [-o OUTPUT] [INPUT]
age [--encrypt] --passphrase [--armor] [-o OUTPUT] [INPUT]
age --decrypt [-i PATH]... [-o OUTPUT] [INPUT]
Options:
-e, --encrypt Encrypt the input to the output. Default if omitted.
-d, --decrypt Decrypt the input to the output.
-o, --output OUTPUT Write the result to the file at path OUTPUT.
-a, --armor Encrypt to a PEM encoded format.
-p, --passphrase Encrypt with a passphrase.
-r, --recipient RECIPIENT Encrypt to the specified RECIPIENT. Can be repeated.
-R, --recipients-file PATH Encrypt to recipients listed at PATH. Can be repeated.
-i, --identity PATH Use the identity file at PATH. Can be repeated.
--version Print the version.
INPUT defaults to standard input, and OUTPUT defaults to standard output.
If OUTPUT exists, it will be overwritten.
RECIPIENT can be an age public key generated by age-keygen ("age1...")
or an SSH public key ("ssh-ed25519 AAAA...", "ssh-rsa AAAA...").
Recipient files contain one or more recipients, one per line. Empty lines
and lines starting with "#" are ignored as comments. "-" may be used to
read recipients from standard input.
Identity files contain one or more secret keys ("AGE-SECRET-KEY-1..."),
one per line, or an SSH key. Empty lines and lines starting with "#" are
ignored as comments. Passphrase encrypted age files can be used as
identity files. Multiple key files can be provided, and any unused ones
will be ignored. "-" may be used to read identities from standard input.
When --encrypt is specified explicitly, -i can also be used to encrypt to an
identity file symmetrically, instead or in addition to normal recipients.
يمكن تشفير الملفات لمستلمين متعددين بتكرار -r/--recipient. سيتمكن كل مستلم من فك تشفير الملف.
$ age -o example.jpg.age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p \
-r age1lggyhqrw2nlhcxprm67z43rta597azn8gknawjehu9d9dl0jq3yqqvfafg example.jpg
يمكن أيضًا سرد مستلمين متعددين، واحد لكل سطر، في ملف واحد أو أكثر يُمرَّر عبر علامة -R/--recipients-file.
$ cat recipients.txt
# Alice
age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p
# Bob
age1lggyhqrw2nlhcxprm67z43rta597azn8gknawjehu9d9dl0jq3yqqvfafg
$ age -R recipients.txt example.jpg > example.jpg.age
إذا كانت الوسيطة لـ -R (أو -i) هي -، يُقرأ الملف من الإدخال القياسي.