Expand description
Random values from the system CSPRNG.
One definition of an idiom that had been written out at every call site
that needed it: fill a buffer from ring::rand::SystemRandom and panic if
the OS cannot supply the bytes. The comments at those sites cross-referenced
each other by name (“the same trade-off authz::generate_token makes”),
which is the shape a hoist is owed.
Two sites deliberately stay outside this module, both because their failure
handling differs rather than their randomness:
signer::local_ca’s serial generator returns a Result, and the
job runner’s retry jitter falls back to an unjittered delay rather than
panicking.
Functions§
- random_
bytes Nbytes from the system CSPRNG.- random_
token - A fresh high-entropy token: [
TOKEN_BYTES] random bytes, base64url-encoded without padding, which is 43 characters.