+# convert nasty chars into gpg-friendly form in pipeline
+# FIXME: escape everything, not just colons!
+gpg_escape() {
+ sed 's/:/\\x3a/g'
+}
+
+# prompt for GPG-formatted expiration, and emit result on stdout
+get_gpg_expiration() {
+ local keyExpire=
+
+ cat >&2 <<EOF
+Please specify how long the key should be valid.
+ 0 = key does not expire
+ <n> = key expires in n days
+ <n>w = key expires in n weeks
+ <n>m = key expires in n months
+ <n>y = key expires in n years
+EOF
+ while [ -z "$keyExpire" ] ; do
+ read -p "Key is valid for? (0) " keyExpire
+ if ! test_gpg_expire ${keyExpire:=0} ; then
+ echo "invalid value" >&2
+ unset keyExpire
+ fi
+ done
+ echo "$keyExpire"
+}
+
+# remove all lines with specified string from specified file
+remove_line() {
+ local file
+ local string
+
+ file="$1"
+ string="$2"
+
+ if [ -z "$file" -o -z "$string" ] ; then
+ return 1
+ fi
+
+ if [ ! -e "$file" ] ; then
+ return 1
+ fi
+
+ # if the string is in the file...
+ if grep -q -F "$string" "$file" 2> /dev/null ; then
+ # remove the line with the string, and return 0
+ grep -v -F "$string" "$file" | sponge "$file"
+ return 0
+ # otherwise return 1
+ else
+ return 1
+ fi
+}
+
+# remove all lines with MonkeySphere strings in file
+remove_monkeysphere_lines() {
+ local file
+
+ file="$1"
+
+ if [ -z "$file" ] ; then
+ return 1
+ fi
+
+ if [ ! -e "$file" ] ; then
+ return 1
+ fi
+
+ egrep -v '^MonkeySphere[[:digit:]]{4}(-[[:digit:]]{2}){2}T[[:digit:]]{2}(:[[:digit:]]{2}){2}$' \
+ "$file" | sponge "$file"
+}
+
+# translate ssh-style path variables %h and %u
+translate_ssh_variables() {
+ local uname
+ local home
+
+ uname="$1"
+ path="$2"
+
+ # get the user's home directory
+ userHome=$(getent passwd "$uname" | cut -d: -f6)
+
+ # translate '%u' to user name
+ path=${path/\%u/"$uname"}
+ # translate '%h' to user home directory
+ path=${path/\%h/"$userHome"}
+
+ echo "$path"
+}
+
+# test that a string to conforms to GPG's expiration format
+test_gpg_expire() {
+ echo "$1" | egrep -q "^[0-9]+[mwy]?$"
+}
+
+# check that a file is properly owned, and that all it's parent
+# directories are not group/other writable
+check_key_file_permissions() {
+ local user
+ local path
+ local access
+ local gAccess
+ local oAccess
+
+ # function to check that an octal corresponds to writability
+ is_write() {
+ [ "$1" -eq 2 -o "$1" -eq 3 -o "$1" -eq 6 -o "$1" -eq 7 ]
+ }
+
+ user="$1"
+ path="$2"
+
+ # return 0 is path does not exist
+ [ -e "$path" ] || return 0
+
+ owner=$(stat --format '%U' "$path")
+ access=$(stat --format '%a' "$path")
+ gAccess=$(echo "$access" | cut -c2)
+ oAccess=$(echo "$access" | cut -c3)
+
+ # check owner
+ if [ "$owner" != "$user" -a "$owner" != 'root' ] ; then
+ return 1
+ fi
+
+ # check group/other writability
+ if is_write "$gAccess" || is_write "$oAccess" ; then
+ return 2
+ fi
+
+ if [ "$path" = '/' ] ; then
+ return 0
+ else
+ check_key_file_permissions $(dirname "$path")
+ fi
+}
+
+### CONVERSION UTILITIES
+
+# output the ssh key for a given key ID
+gpg2ssh() {
+ local keyID
+