pub struct LockedKey { /* private fields */ }Expand description
A key locked under a passphrase.
Safe to store in the open - next to the data, on a server - for as long as the passphrase is strong: whoever holds a lock can try passphrases against it offline, as fast as Argon2id lets them. That cost is the whole of its protection.
Implementations§
Source§impl LockedKey
impl LockedKey
Sourcepub fn lock(
key: &Key,
passphrase: &[u8],
context: &[u8],
) -> Result<LockedKey, Error>
pub fn lock( key: &Key, passphrase: &[u8], context: &[u8], ) -> Result<LockedKey, Error>
Locks key under passphrase for context, with
KdfParams::DEFAULT.
§Errors
Error::Random when there is no randomness for the salt and nonce.
Sourcepub fn lock_with(
key: &Key,
passphrase: &[u8],
context: &[u8],
params: KdfParams,
) -> Result<LockedKey, Error>
pub fn lock_with( key: &Key, passphrase: &[u8], context: &[u8], params: KdfParams, ) -> Result<LockedKey, Error>
Locks key under passphrase for context, with params.
§Errors
Error::Random when there is no randomness for the salt and nonce;
Error::Parameters when Argon2id refuses params.
Sourcepub fn unlock(&self, passphrase: &[u8], context: &[u8]) -> Result<Key, Error>
pub fn unlock(&self, passphrase: &[u8], context: &[u8]) -> Result<Key, Error>
Unlocks the key with passphrase, for context.
Spends what the lock’s parameters ask for - by default 64 MiB and a fraction of a second.
§Errors
Error::WrongPassphrase when the passphrase or the context is not
the one the key was locked with, or the lock was changed since.
Sourcepub fn locked_at(&self) -> SystemTime
pub fn locked_at(&self) -> SystemTime
When the lock was made, by the clock of the device that made it.
Sourcepub fn from_bytes(bytes: &[u8]) -> Result<LockedKey, Error>
pub fn from_bytes(bytes: &[u8]) -> Result<LockedKey, Error>
Reads a lock, and holds its parameters to KdfParams::MIN and
KdfParams::MAX before anything is spent on them.
§Errors
Error::Malformed or Error::NewerFormat when the bytes are not a
lock this release reads; Error::Parameters when its parameters are
out of bounds.