pub struct Pkcs11Provider { /* private fields */ }Expand description
PKCS#11 HSM provider (stub implementation).
This provides the interface for PKCS#11 HSM integration.
A full implementation would use the pkcs11 or cryptoki crate.
Enterprise users would implement this against their specific HSM:
- SafeNet Luna
- Thales nShield
- AWS CloudHSM
- YubiHSM
Implementations§
Source§impl Pkcs11Provider
impl Pkcs11Provider
Sourcepub fn new(config: Pkcs11Config) -> Self
pub fn new(config: Pkcs11Config) -> Self
Create a new PKCS#11 provider.
Sourcepub fn initialize(&mut self) -> HsmResult<()>
pub fn initialize(&mut self) -> HsmResult<()>
Initialize the PKCS#11 session.
In a real implementation, this would:
- Load the PKCS#11 library
- Initialize the library
- Open a session on the specified slot
- Login with the provided PIN
Trait Implementations§
Source§impl SigningProvider for Pkcs11Provider
impl SigningProvider for Pkcs11Provider
Source§fn is_available(&self) -> bool
fn is_available(&self) -> bool
Check if the provider is available and initialized.
Source§fn generate_key(&self, label: &str) -> HsmResult<KeyId>
fn generate_key(&self, label: &str) -> HsmResult<KeyId>
Generate a new key pair and return its identifier.
Source§fn import_key(&self, label: &str, _secret_key: &SecretKey) -> HsmResult<KeyId>
fn import_key(&self, label: &str, _secret_key: &SecretKey) -> HsmResult<KeyId>
Import an existing secret key.
Source§fn get_public_key(&self, key_id: &KeyId) -> HsmResult<PublicKey>
fn get_public_key(&self, key_id: &KeyId) -> HsmResult<PublicKey>
Get the public key for a key identifier.
Source§fn sign(&self, key_id: &KeyId, _message: &[u8]) -> HsmResult<SignatureBytes>
fn sign(&self, key_id: &KeyId, _message: &[u8]) -> HsmResult<SignatureBytes>
Sign a message using the specified key.
Source§fn key_exists(&self, _key_id: &KeyId) -> bool
fn key_exists(&self, _key_id: &KeyId) -> bool
Check if a key exists.
Source§fn verify(
&self,
public_key: &PublicKey,
message: &[u8],
signature: &SignatureBytes,
) -> HsmResult<()>
fn verify( &self, public_key: &PublicKey, message: &[u8], signature: &SignatureBytes, ) -> HsmResult<()>
Verify a signature (can use public key directly).
Source§fn export_key(&self, key_id: &KeyId) -> HsmResult<SecretKey>
fn export_key(&self, key_id: &KeyId) -> HsmResult<SecretKey>
Export secret key (if allowed by key policy).
Source§fn get_key_metadata(&self, key_id: &KeyId) -> HsmResult<KeyMetadata>
fn get_key_metadata(&self, key_id: &KeyId) -> HsmResult<KeyMetadata>
Get key metadata including lifecycle state and usage stats.
Source§fn update_key_state(
&self,
key_id: &KeyId,
state: KeyLifecycleState,
) -> HsmResult<()>
fn update_key_state( &self, key_id: &KeyId, state: KeyLifecycleState, ) -> HsmResult<()>
Update key lifecycle state.
Source§fn health_check(&self) -> HsmResult<HealthStatus>
fn health_check(&self) -> HsmResult<HealthStatus>
Perform health check and return status.
Source§fn batch_sign(
&self,
key_id: &KeyId,
messages: &[&[u8]],
) -> HsmResult<Vec<SignatureBytes>>
fn batch_sign( &self, key_id: &KeyId, messages: &[&[u8]], ) -> HsmResult<Vec<SignatureBytes>>
Batch sign multiple messages.
Source§fn get_audit_log(&self, limit: usize) -> HsmResult<Vec<AuditEntry>>
fn get_audit_log(&self, limit: usize) -> HsmResult<Vec<AuditEntry>>
Get audit log entries (if supported).
Auto Trait Implementations§
impl Freeze for Pkcs11Provider
impl RefUnwindSafe for Pkcs11Provider
impl Send for Pkcs11Provider
impl Sync for Pkcs11Provider
impl Unpin for Pkcs11Provider
impl UnwindSafe for Pkcs11Provider
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
Causes
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
Causes
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
Causes
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
Causes
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
Causes
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
Causes
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
Causes
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
Causes
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Pipes by value. This is generally the method you want to use. Read more
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
Borrows
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
Mutably borrows
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
Borrows
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
Mutably borrows
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
Borrows
self, then passes self.deref() into the pipe function.Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Immutable access to the
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
Mutable access to the
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
Immutable access to the
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
Mutable access to the
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Immutable access to the
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Mutable access to the
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
Calls
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
Calls
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
Calls
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
Calls
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
Calls
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
Calls
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
Calls
.tap_deref() only in debug builds, and is erased in release
builds.