pub trait Signer:
Send
+ Sync
+ Debug {
// Required methods
fn key_id(&self) -> KeyId;
fn sign(&self, hash: &Digest) -> Vec<u8> ⓘ;
// Provided method
fn signature_over(&self, hash: &Digest) -> KeySignature { ... }
}Expand description
Signs a record’s chain hash.
Implementations must be cheap enough to run on every append — this is on the
write path of every journaled effect — and must not perform I/O in sign. A
signer that calls out to a KMS per record turns the journal’s write path into
a network dependency, which is the same mistake as a policy engine that can
fail open. Fetch and cache the credential elsewhere; sign locally.
Required Methods§
Provided Methods§
Sourcefn signature_over(&self, hash: &Digest) -> KeySignature
fn signature_over(&self, hash: &Digest) -> KeySignature
Attach a signature to a hash.
Dyn Compatibility§
This trait is dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".