pub struct NsmSession { /* private fields */ }Expand description
An open session with the Nitro Security Module (/dev/nsm).
Implements RAII to ensure the device file descriptor is automatically closed
via nsm_exit when the session is dropped.
Implementations§
Source§impl NsmSession
NSM operations: opening a session, attestation requests and PCR management.
impl NsmSession
NSM operations: opening a session, attestation requests and PCR management.
Sourcepub fn open() -> Result<Self, AttestationError>
pub fn open() -> Result<Self, AttestationError>
Opens a new session with the Nitro Security Module.
Calls nsm_init to open /dev/nsm. Returns AttestationError::DeviceOpenFailed
if the device file cannot be opened (e.g., if not running inside an AWS Nitro Enclave).
Sourcepub fn from_raw_fd(fd: i32) -> Result<Self, AttestationError>
pub fn from_raw_fd(fd: i32) -> Result<Self, AttestationError>
Creates an NsmSession from an existing raw file descriptor.
Sourcepub fn create_attestation(
&self,
params: &AttestationParams,
) -> Result<Vec<u8>, AttestationError>
pub fn create_attestation( &self, params: &AttestationParams, ) -> Result<Vec<u8>, AttestationError>
Requests an Attestation Document from the NSM.
Returns the raw COSE_Sign1 formatted document bytes.
Sourcepub fn create_attestation_for_cert(
&self,
cert_der: &[u8],
) -> Result<Vec<u8>, AttestationError>
pub fn create_attestation_for_cert( &self, cert_der: &[u8], ) -> Result<Vec<u8>, AttestationError>
Convenience method to create an attestation document binding an ephemeral TLS certificate.
Computes the SHA-256 hash of cert_der and supplies it as user_data.
Sourcepub fn describe_nsm(&self) -> Result<NsmDescription, AttestationError>
pub fn describe_nsm(&self) -> Result<NsmDescription, AttestationError>
Describes the connected Nitro Security Module capabilities and configuration.
Sourcepub fn get_random(&self) -> Result<Vec<u8>, AttestationError>
pub fn get_random(&self) -> Result<Vec<u8>, AttestationError>
Requests cryptographic entropy (random bytes) from the NSM.
Sourcepub fn describe_pcr(
&self,
index: u16,
) -> Result<(bool, Vec<u8>), AttestationError>
pub fn describe_pcr( &self, index: u16, ) -> Result<(bool, Vec<u8>), AttestationError>
Describes a Platform Configuration Register (PCR) at index.
Returns (locked, data).
Sourcepub fn extend_pcr(
&self,
index: u16,
data: Vec<u8>,
) -> Result<Vec<u8>, AttestationError>
pub fn extend_pcr( &self, index: u16, data: Vec<u8>, ) -> Result<Vec<u8>, AttestationError>
Extends a Platform Configuration Register (PCR) at index with data.
Trait Implementations§
Source§impl AttestationProvider for NsmSession
Nitro implementation of AttestationProvider, backed by /dev/nsm.
impl AttestationProvider for NsmSession
Nitro implementation of AttestationProvider, backed by /dev/nsm.
Source§fn is_available() -> bool
fn is_available() -> bool
Returns true if the NSM device /dev/nsm exists.
Source§fn generate_document(
&self,
params: &AttestationParams,
) -> Result<EatClaimsSet, AttestationError>
fn generate_document( &self, params: &AttestationParams, ) -> Result<EatClaimsSet, AttestationError>
Requests a real attestation document from the NSM for params and wraps it as an EAT claims-set.
Source§impl Debug for NsmSession
impl Debug for NsmSession
Source§impl Drop for NsmSession
Closes the NSM device file descriptor when the session goes out of scope.
impl Drop for NsmSession
Closes the NSM device file descriptor when the session goes out of scope.