pub struct KeyRotation {
pub agora_governance_key_rotation: u32,
pub reason: RotationReason,
pub old_key: PublicKeyHex,
pub new_key: PublicKeyHex,
pub proof: SignatureHex,
pub proof_signed_at: i64,
pub certificate: KeyCertificate,
pub outgoing_certificate: Option<KeyCertificate>,
}Expand description
The data of a key_rotation entry.
Build one with routine or
compromise: both compute the proof of possession.
The certificate is what authenticates the change; the proof only
shows the certified key is one somebody holds.
No free text, and unknown fields are refused: a rotation can never be redacted, so it carries nothing anyone could need erased. Narrative belongs in a separate, redactable entry.
Fields§
§agora_governance_key_rotation: u32Always KEY_ROTATION_VERSION
reason: RotationReason§old_key: PublicKeyHex§new_key: PublicKeyHex§proof: SignatureHexcrypto::sign(new_key, RotationStatement::hash , proof_signed_at) — the new key signing for itself, at one position
in one chain
proof_signed_at: i64Unix seconds; what the proof signature covers
certificate: KeyCertificateThe root’s word that new_key holds the chain from here. For a
compromise its statement also names the last entry trusted under
old_key.
outgoing_certificate: Option<KeyCertificate>The CertPurpose::Genesis certificate for the key the chain
started under, which predates the root: on the chain’s first
rotation, and only there.
Implementations§
Source§impl KeyRotation
impl KeyRotation
Sourcepub fn routine(
old_key: PublicKeyHex,
new_signing_key: &SigningKey,
prev_hash: Option<Sha256Hex>,
now: DateTime<Utc>,
certificate: KeyCertificate,
) -> Self
pub fn routine( old_key: PublicKeyHex, new_signing_key: &SigningKey, prev_hash: Option<Sha256Hex>, now: DateTime<Utc>, certificate: KeyCertificate, ) -> Self
A scheduled rotation from old_key to new_signing_key.
The entry itself is signed by the old key; entries after it
verify under the new one. prev_hash is the rotation entry’s own,
and certificate is over KeyCertStatement::routine at it.
Sourcepub fn compromise(
old_key: PublicKeyHex,
new_signing_key: &SigningKey,
prev_hash: Option<Sha256Hex>,
now: DateTime<Utc>,
certificate: KeyCertificate,
) -> Self
pub fn compromise( old_key: PublicKeyHex, new_signing_key: &SigningKey, prev_hash: Option<Sha256Hex>, now: DateTime<Utc>, certificate: KeyCertificate, ) -> Self
A declaration that old_key is compromised, trusted only through
the last_trusted its certificate names.
The entry is signed by the new key — the old one proves nothing
any more. last_trusted must name an entry from before any earlier
compromise window; a reattestation inside one restores the entry,
not the ability to anchor trust there.
Sourcepub fn with_outgoing(self, certificate: KeyCertificate) -> Self
pub fn with_outgoing(self, certificate: KeyCertificate) -> Self
This rotation, carrying the genesis key’s retroactive certificate
Sourcepub fn statement(&self, prev_hash: Option<Sha256Hex>) -> RotationStatement
pub fn statement(&self, prev_hash: Option<Sha256Hex>) -> RotationStatement
The statement this rotation’s proof covers, at prev_hash
Sourcepub fn last_trusted(&self) -> Option<&TrustedHead>
pub fn last_trusted(&self) -> Option<&TrustedHead>
Compromise only: the last entry trusted under old_key, as the
root certified it
Sourcepub fn expected_statement(
&self,
seq: u64,
prev_hash: Option<Sha256Hex>,
) -> Result<KeyCertStatement, RotationError>
pub fn expected_statement( &self, seq: u64, prev_hash: Option<Sha256Hex>, ) -> Result<KeyCertStatement, RotationError>
What certificate must say for this rotation, appended at seq
with prev_hash, to be authentic.
Derived from the chain. Only last_trusted is taken from the
certificate, because only the root can say it.
Sourcepub fn verify_proof(
&self,
prev_hash: Option<Sha256Hex>,
) -> Result<(), RotationError>
pub fn verify_proof( &self, prev_hash: Option<Sha256Hex>, ) -> Result<(), RotationError>
Version and the proof of possession at the position prev_hash
names
Sourcepub fn verify_certified(
&self,
seq: u64,
prev_hash: Option<Sha256Hex>,
roots: &RootSet,
) -> Result<(), RotationError>
pub fn verify_certified( &self, seq: u64, prev_hash: Option<Sha256Hex>, roots: &RootSet, ) -> Result<(), RotationError>
verify_proof, and certificate is the
root’s for this key at this position — everything checkable
without the rest of the chain