Skip to main content

NsmSession

Struct NsmSession 

Source
pub struct NsmSession { /* private fields */ }
Expand description

An open session with the Nitro Security Module (/dev/nsm).

Implements RAII to ensure the device file descriptor is automatically closed via nsm_exit when the session is dropped.

Implementations§

Source§

impl NsmSession

NSM operations: opening a session, attestation requests and PCR management.

Source

pub fn open() -> Result<Self, AttestationError>

Opens a new session with the Nitro Security Module.

Calls nsm_init to open /dev/nsm. Returns AttestationError::DeviceOpenFailed if the device file cannot be opened (e.g., if not running inside an AWS Nitro Enclave).

Source

pub fn from_raw_fd(fd: i32) -> Result<Self, AttestationError>

Creates an NsmSession from an existing raw file descriptor.

Source

pub fn raw_fd(&self) -> i32

Returns the underlying raw file descriptor.

Source

pub fn create_attestation( &self, params: &AttestationParams, ) -> Result<Vec<u8>, AttestationError>

Requests an Attestation Document from the NSM.

Returns the raw COSE_Sign1 formatted document bytes.

Source

pub fn create_attestation_for_cert( &self, cert_der: &[u8], ) -> Result<Vec<u8>, AttestationError>

Convenience method to create an attestation document binding an ephemeral TLS certificate.

Computes the SHA-256 hash of cert_der and supplies it as user_data.

Source

pub fn describe_nsm(&self) -> Result<NsmDescription, AttestationError>

Describes the connected Nitro Security Module capabilities and configuration.

Source

pub fn get_random(&self) -> Result<Vec<u8>, AttestationError>

Requests cryptographic entropy (random bytes) from the NSM.

Source

pub fn describe_pcr( &self, index: u16, ) -> Result<(bool, Vec<u8>), AttestationError>

Describes a Platform Configuration Register (PCR) at index. Returns (locked, data).

Source

pub fn extend_pcr( &self, index: u16, data: Vec<u8>, ) -> Result<Vec<u8>, AttestationError>

Extends a Platform Configuration Register (PCR) at index with data.

Source

pub fn lock_pcr(&self, index: u16) -> Result<(), AttestationError>

Locks a Platform Configuration Register (PCR) at index against further modification.

Trait Implementations§

Source§

impl AttestationProvider for NsmSession

Nitro implementation of AttestationProvider, backed by /dev/nsm.

Source§

fn name(&self) -> &'static str

Returns "aws-nitro".

Source§

fn is_available() -> bool

Returns true if the NSM device /dev/nsm exists.

Source§

fn generate_document( &self, params: &AttestationParams, ) -> Result<EatClaimsSet, AttestationError>

Requests a real attestation document from the NSM for params and wraps it as an EAT claims-set.

Source§

impl Debug for NsmSession

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Drop for NsmSession

Closes the NSM device file descriptor when the session goes out of scope.

Source§

fn drop(&mut self)

Calls nsm_exit on the open file descriptor, at most once.

Source§

fn pin_drop(self: Pin<&mut Self>)

🔬This is a nightly-only experimental API. (pin_ergonomics)
Execute the destructor for this type, but different to Drop::drop, it requires self to be pinned. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more