pub struct KeyRotation {
pub agora_governance_key_rotation: u32,
pub reason: RotationReason,
pub old_key: PublicKeyHex,
pub new_key: PublicKeyHex,
pub proof: SignatureHex,
pub proof_signed_at: i64,
pub last_trusted: Option<TrustedHead>,
pub note: String,
}Expand description
The data of a key_rotation entry.
Build one with routine or
compromise: both compute the proof of possession,
which is the only thing standing between “the Steward moved the chain to
a new key” and “someone published a key they do not hold”.
Fields§
§agora_governance_key_rotation: u32Always KEY_ROTATION_VERSION
reason: RotationReason§old_key: PublicKeyHex§new_key: PublicKeyHex§proof: SignatureHexcrypto::sign(new_key, RotationStatement::hash , proof_signed_at) — the new key signing for itself, at one position
in one chain
proof_signed_at: i64Unix seconds; what the proof signature covers
last_trusted: Option<TrustedHead>Compromise only: the last entry trusted under old_key
note: StringImplementations§
Source§impl KeyRotation
impl KeyRotation
Sourcepub fn routine(
old_key: PublicKeyHex,
new_signing_key: &SigningKey,
prev_hash: Option<Sha256Hex>,
now: DateTime<Utc>,
note: impl Into<String>,
) -> Self
pub fn routine( old_key: PublicKeyHex, new_signing_key: &SigningKey, prev_hash: Option<Sha256Hex>, now: DateTime<Utc>, note: impl Into<String>, ) -> Self
A scheduled rotation from old_key to new_signing_key.
The entry itself is signed by the old key; entries after it
verify under the new one. prev_hash is the rotation entry’s own.
Sourcepub fn compromise(
old_key: PublicKeyHex,
new_signing_key: &SigningKey,
last_trusted: TrustedHead,
prev_hash: Option<Sha256Hex>,
now: DateTime<Utc>,
note: impl Into<String>,
) -> Self
pub fn compromise( old_key: PublicKeyHex, new_signing_key: &SigningKey, last_trusted: TrustedHead, prev_hash: Option<Sha256Hex>, now: DateTime<Utc>, note: impl Into<String>, ) -> Self
A declaration that old_key is compromised, trusted only through
last_trusted.
The entry is signed by the new key — the old one proves nothing
any more — so a verifier accepts it only from its KeyAnchor.
last_trusted must name an entry from before any earlier
compromise window; a reattestation inside one restores the entry,
not the ability to anchor trust there.
Sourcepub fn statement(&self, prev_hash: Option<Sha256Hex>) -> RotationStatement
pub fn statement(&self, prev_hash: Option<Sha256Hex>) -> RotationStatement
The statement this rotation’s proof covers, at prev_hash
Sourcepub fn verify_proof(
&self,
prev_hash: Option<Sha256Hex>,
) -> Result<(), RotationError>
pub fn verify_proof( &self, prev_hash: Option<Sha256Hex>, ) -> Result<(), RotationError>
Version, last_trusted shape, and the proof of possession at the
position prev_hash names — everything checkable without the rest
of the chain
Trait Implementations§
Source§impl Clone for KeyRotation
impl Clone for KeyRotation
Source§fn clone(&self) -> KeyRotation
fn clone(&self) -> KeyRotation
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more