
Uno strumento di crittografia semplice, moderno e sicuro (e libreria Go) con chiavi esplicite piccole, nessuna opzione di configurazione e componibilità in stile UNIX.
age è uno strumento di crittografia file semplice, moderno e sicuro, con relativo formato e libreria Go.
Offre chiavi esplicite di piccole dimensioni, supporto post-quantistico, nessuna opzione di configurazione e componibilità in stile UNIX.
$ age-keygen -o key.txt
Public key: age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p
$ tar cvz ~/data | age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p > data.tar.gz.age
$ age --decrypt -i key.txt data.tar.gz.age > data.tar.gz
📜 La specifica del formato è disponibile su age-encryption.org/v1. age è stato progettato da @benjojo e @FiloSottile.
🦀 Un'implementazione Rust alternativa e interoperabile è disponibile su github.com/str4d/rage.
🌍 Typage è un'implementazione TypeScript. Funziona nel browser, Node.js, Deno e Bun.
🔑 I token hardware PIV come le YubiKey sono supportati tramite il plugin age-plugin-yubikey.
✨ Per altri plugin, implementazioni, strumenti e integrazioni, consulta l'elenco awesome age.
💬 L'autore lo pronuncia [aɡe̞] con una g dura, come GIF, ed è sempre scritto in minuscolo.
| Homebrew (macOS o Linux) |
brew install age
|
| MacPorts |
port install age
|
| Windows |
winget install --id FiloSottile.age
|
| Alpine Linux v3.15+ |
apk add age
|
| Arch Linux |
pacman -S age
|
| Debian 12+ (Bookworm) |
apt install age
|
| Debian 11 (Bullseye) |
apt install age/bullseye-backports
(abilita i backports per age v1.0.0+)
|
| Fedora 33+ |
dnf install age
|
| Gentoo Linux |
emerge app-crypt/age
|
| Guix System |
guix package -i age
|
| NixOS / Nix |
nix-env -i age
|
| openSUSE Tumbleweed |
zypper install age
|
| Ubuntu 22.04+ |
apt install age
|
| Void Linux |
xbps-install age
|
| FreeBSD |
pkg install age (security/age)
|
| OpenBSD 6.7+ |
pkg_add age (security/age)
|
| Chocolatey (Windows) |
choco install age.portable
|
| Scoop (Windows) |
scoop bucket add extras && scoop install age
|
Su Windows, Linux, macOS e FreeBSD puoi utilizzare i binari precompilati.
Se scarichi i binari precompilati, puoi verificarne le prove Sigsum.
Se il tuo sistema dispone di una versione supportata di Go, puoi compilare dal sorgente.
go install filippo.io/age/cmd/...@latest
L'aiuto di nuovi maintainer di pacchetti è molto gradito.
Per la documentazione completa, leggi la pagina man di age(1).
Usage:
age [--encrypt] (-r RECIPIENT | -R PATH)... [--armor] [-o OUTPUT] [INPUT]
age [--encrypt] --passphrase [--armor] [-o OUTPUT] [INPUT]
age --decrypt [-i PATH]... [-o OUTPUT] [INPUT]
Options:
-e, --encrypt Encrypt the input to the output. Default if omitted.
-d, --decrypt Decrypt the input to the output.
-o, --output OUTPUT Write the result to the file at path OUTPUT.
-a, --armor Encrypt to a PEM encoded format.
-p, --passphrase Encrypt with a passphrase.
-r, --recipient RECIPIENT Encrypt to the specified RECIPIENT. Can be repeated.
-R, --recipients-file PATH Encrypt to recipients listed at PATH. Can be repeated.
-i, --identity PATH Use the identity file at PATH. Can be repeated.
--version Print the version.
INPUT defaults to standard input, and OUTPUT defaults to standard output.
If OUTPUT exists, it will be overwritten.
RECIPIENT can be an age public key generated by age-keygen ("age1...")
or an SSH public key ("ssh-ed25519 AAAA...", "ssh-rsa AAAA...").
Recipient files contain one or more recipients, one per line. Empty lines
and lines starting with "#" are ignored as comments. "-" may be used to
read recipients from standard input.
Identity files contain one or more secret keys ("AGE-SECRET-KEY-1..."),
one per line, or an SSH key. Empty lines and lines starting with "#" are
ignored as comments. Passphrase encrypted age files can be used as
identity files. Multiple key files can be provided, and any unused ones
will be ignored. "-" may be used to read identities from standard input.
When --encrypt is specified explicitly, -i can also be used to encrypt to an
identity file symmetrically, instead or in addition to normal recipients.
I file possono essere crittografati per più destinatari ripetendo -r/--recipient. Ogni destinatario potrà decrittografare il file.
$ age -o example.jpg.age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p \
-r age1lggyhqrw2nlhcxprm67z43rta597azn8gknawjehu9d9dl0jq3yqqvfafg example.jpg
Più destinatari possono anche essere elencati uno per riga in uno o più file passati con il flag -R/--recipients-file.