pub struct KeyCertStatement {
pub agora_governance_key_cert: u32,
pub key: PublicKeyHex,
pub purpose: CertPurpose,
pub from_seq: u64,
pub prev_hash: Option<Sha256Hex>,
pub last_trusted: Option<TrustedHead>,
}Expand description
What a root key signs: key holds the chain from from_seq.
Every field is always serialized, null when absent, and unknown
fields are refused: the bytes a verifier rebuilds are exactly the bytes
the Steward read before touching the device.
Fields§
§agora_governance_key_cert: u32Always KEY_CERT_VERSION
key: PublicKeyHexThe online signing key being certified
purpose: CertPurpose§from_seq: u64The first chain_seq key signs
prev_hash: Option<Sha256Hex>The rotation entry’s own prev_hash, so a certificate is good at
one position of one chain. null for CertPurpose::Genesis.
last_trusted: Option<TrustedHead>CertPurpose::Compromise only: the last entry trusted under the
outgoing key. The root says where the window opens, not the online
key that may be the thief’s.
Implementations§
Source§impl KeyCertStatement
impl KeyCertStatement
Sourcepub fn genesis(key: PublicKeyHex) -> Self
pub fn genesis(key: PublicKeyHex) -> Self
key is the key the chain started under
Sourcepub fn routine(
key: PublicKeyHex,
seq: u64,
prev_hash: Option<Sha256Hex>,
) -> Self
pub fn routine( key: PublicKeyHex, seq: u64, prev_hash: Option<Sha256Hex>, ) -> Self
key takes over after the routine rotation appended at seq,
whose prev_hash is prev_hash
Sourcepub fn compromise(
key: PublicKeyHex,
seq: u64,
prev_hash: Option<Sha256Hex>,
last_trusted: TrustedHead,
) -> Self
pub fn compromise( key: PublicKeyHex, seq: u64, prev_hash: Option<Sha256Hex>, last_trusted: TrustedHead, ) -> Self
key signs the compromise declaration appended at seq and
everything after it
Sourcepub fn signed_bytes(&self) -> Vec<u8> ⓘ
pub fn signed_bytes(&self) -> Vec<u8> ⓘ
The exact bytes a root key signs