pub struct SigningKey { /* private fields */ }Expand description
The confidential client’s long-lived ES256 signing key.
Implementations§
Source§impl SigningKey
impl SigningKey
Sourcepub fn generate(kid: &str) -> Self
pub fn generate(kid: &str) -> Self
Generate a fresh P-256 key.
Draws from the OS CSPRNG via getrandom, the same source as the rest of
the app, rather than pulling in a second RNG stack. A uniformly random
32-byte value is a valid P-256 scalar with overwhelming probability; the
retry covers the ~2^-32 case where it lands outside the curve order.
Sourcepub fn from_jwk_json(jwk_json: &str, kid: &str) -> Result<Self>
pub fn from_jwk_json(jwk_json: &str, kid: &str) -> Result<Self>
Parse a JWK, tolerating the extra members (kid, alg, key_ops,
use) that both this module and the sidecar attach.
Sourcepub fn to_jwk_json(&self) -> Result<String>
pub fn to_jwk_json(&self) -> Result<String>
The PRIVATE JWK, for persistence. Carries kid/alg/key_ops so a
rollback to the sidecar finds the key under the same identifier.
Sourcepub fn public_jwk(&self) -> Result<Value>
pub fn public_jwk(&self) -> Result<Value>
The PUBLIC JWK — what /jwks.json serves. Never contains d.
Sourcepub fn jwks_document(&self) -> Result<Value>
pub fn jwks_document(&self) -> Result<Value>
The document served at jwks_uri, so the PDS can verify our assertions.
Sourcepub fn thumbprint(&self) -> Result<String>
pub fn thumbprint(&self) -> Result<String>
RFC 7638 thumbprint of this key’s public half.
Sourcepub fn public_thumbprint_of(jwk_json: &str) -> Result<String>
pub fn public_thumbprint_of(jwk_json: &str) -> Result<String>
RFC 7638 thumbprint of an arbitrary EC JWK document.
pub fn kid(&self) -> &str
Auto Trait Implementations§
impl Freeze for SigningKey
impl RefUnwindSafe for SigningKey
impl Send for SigningKey
impl Sync for SigningKey
impl Unpin for SigningKey
impl UnsafeUnpin for SigningKey
impl UnwindSafe for SigningKey
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more