Expand description
Signing through an interface, so a key need not be in memory.
The signature schemes in this library take a private key as bytes. That is
the wrong shape for a key held in an HSM, a TPM or a cloud key service,
where the caller has a handle and the device does the arithmetic. Signer
is the shape both fit: name the algorithm, pass the message, get a
signature. A TLS handshake or a certificate issuer written against it does
not know or care where the key lives; Signer::custody is there for the
callers that must.
This crate defines the interface and nothing that implements it. A key
held in memory signs through ic_sig::SoftwareSigner; the hardware and
service backends are other crates’; verification, which needs no private
key, is ic_sig::verify.
§Encodings
Public keys are DER SubjectPublicKeyInfo. Signatures are in the form
X.509 and TLS 1.3 both carry: an ASN.1 Ecdsa-Sig-Value for ECDSA, and the
algorithm’s own bytes for Ed25519, RSA, ML-DSA, SLH-DSA and HSS/LMS. One
encoding at the
interface means a signer written for certificates serves a handshake
unchanged.
Enums§
- Custody
- Where a private key lives, as far as its holder can say.
- Signature
Algorithm - A signature algorithm: the key type and everything that goes with it.
Traits§
- Signer
- A private key that can sign, wherever it is held.