pub struct NodeKey { /* private fields */ }Expand description
One of a node’s keys in its profile: the ML-DSA-87 half, and in pq_hybrid the RSA-PSS-4096 half. It signs as a whole, never with one half on its own. Showing it gives its purpose, profile and key id, never a private half.
Implementations§
Source§impl NodeKey
impl NodeKey
Sourcepub fn save(&self, path: &Path) -> Result<(), KeyFileError>
pub fn save(&self, path: &Path) -> Result<(), KeyFileError>
Writes the key to path in the seed form, readable by its owner only.
The file is created in a new owner-only directory beside path,
written, synced and renamed over any file at path; then path’s
directory is synced and the new one removed. Nothing else in the
directory is read, written or removed.
Sourcepub fn load(
path: &Path,
purpose: Purpose,
profile: Profile,
) -> Result<NodeKey, KeyFileError>
pub fn load( path: &Path, purpose: Purpose, profile: Profile, ) -> Result<NodeKey, KeyFileError>
The key saved at path for purpose in profile, checked before it
is returned. A path that names anything but a regular file, directly
or through a symlink, is refused before it is opened, and the opened
file is checked again: a regular file, owned by the effective user,
that its group and others cannot read, of at most 64 KiB. Then a key
for another purpose or profile, halves that do not fit the profile, a
stored public key its private key does not derive, and a key that
fails a sign-and-verify round trip are refused.
Sourcepub fn load_or_create(
path: &Path,
profile: Profile,
) -> Result<NodeKey, KeyFileError>
pub fn load_or_create( path: &Path, profile: Profile, ) -> Result<NodeKey, KeyFileError>
The identity key at path in profile, or, when nothing is there, a
new one with the admission puzzle solved, saved there first. Anything
at path that does not load as such a key is refused and left as it
is, never replaced.
Sourcepub fn save_to_keystore(&self, store: &dyn KeyStore) -> Result<(), KeyFileError>
pub fn save_to_keystore(&self, store: &dyn KeyStore) -> Result<(), KeyFileError>
Keeps the key in store, as the bytes of its key file: the platform
secure store a mobile app keeps its key in (see crate::keystore).
Sourcepub fn load_from_keystore(
store: &dyn KeyStore,
purpose: Purpose,
profile: Profile,
) -> Result<NodeKey, KeyFileError>
pub fn load_from_keystore( store: &dyn KeyStore, purpose: Purpose, profile: Profile, ) -> Result<NodeKey, KeyFileError>
The key kept in store for purpose in profile, checked as a key
file’s is, but for the file’s owner and permissions, which the store
keeps.
Source§impl NodeKey
impl NodeKey
Sourcepub fn generate(purpose: Purpose, profile: Profile) -> Result<NodeKey, KeyError>
pub fn generate(purpose: Purpose, profile: Profile) -> Result<NodeKey, KeyError>
A new key for purpose in profile.
Sourcepub fn generate_identity(
profile: Profile,
difficulty: u32,
) -> Result<NodeKey, KeyError>
pub fn generate_identity( profile: Profile, difficulty: u32, ) -> Result<NodeKey, KeyError>
A new identity key in profile whose node_id starts with difficulty
zero bits, found in about 2^difficulty tries. Each try makes a new
ML-DSA-87 half; a pq_hybrid key keeps its RSA-PSS half, since the
node_id covers both.
Sourcepub fn public_key(&self) -> Vec<u8> ⓘ
pub fn public_key(&self) -> Vec<u8> ⓘ
The key as carried (D13): the 2,592-byte ML-DSA-87 key, followed in
pq_hybrid by the DER RSAPublicKey.
Sourcepub fn key_id(&self) -> [u8; 32]
pub fn key_id(&self) -> [u8; 32]
The id that names the key in signed objects: an identity key’s node_id, and the key id of any other key.
Sourcepub fn sign(&self, message: &[u8]) -> Result<Vec<u8>, KeyError>
pub fn sign(&self, message: &[u8]) -> Result<Vec<u8>, KeyError>
Signs message: with ML-DSA-87 alone in pq_pure, and in pq_hybrid with
the composite, where both halves sign the message representative, the
ML-DSA-87 half with the composite label as its context, and the
signature is the ML-DSA-87 signature followed by the RSA-PSS one.
ML-DSA-87 signs hedged and RSA-PSS salted, so each signature is new.