pub trait Signer: Send + Sync {
// Required methods
fn algorithms(&self) -> &[SignatureAlgorithm];
fn public_key(&self) -> &[u8] ⓘ;
fn custody(&self) -> Custody;
fn sign(
&self,
algorithm: SignatureAlgorithm,
message: &[u8],
rng: &mut dyn RandomSource,
out: &mut [u8],
) -> Result<usize>;
}Expand description
A private key that can sign, wherever it is held.
Object-safe, and Send + Sync: a server shares one key between the
connections it is serving at once, so a signer that could not cross threads
would be unusable exactly where a signer is most needed. Signing takes
&self for the same reason; a signer with state to change guards it itself.
§What an implementation promises
signsignsmessageitself, not a digest of it: the algorithm names its own hash.- It writes nothing past the length it returns, and allocates only if the implementation must, so a software signer can serve a caller that may not allocate.
- It refuses, rather than substitutes, an algorithm it did not list in
algorithms.
§Blocking
sign returns when the signature exists. For a key in a remote service that
is a network round trip made inside the call; a caller that cannot block
needs to run it elsewhere and is not served by this interface alone.
Required Methods§
Sourcefn algorithms(&self) -> &[SignatureAlgorithm]
fn algorithms(&self) -> &[SignatureAlgorithm]
The algorithms this key signs with, most preferred first.
The order is meaningful: a protocol negotiating an algorithm takes the first one here that its peer and its policy also allow. Listing an algorithm is a statement about the key, not about any protocol – an RSA key may list PKCS#1 v1.5 for the certificates it signs, and a TLS 1.3 handshake still will not use it.
Sourcefn public_key(&self) -> &[u8] ⓘ
fn public_key(&self) -> &[u8] ⓘ
The public key, as a DER SubjectPublicKeyInfo.
These must be the bytes the key’s certificate carries, not a re-encoding of the same key: callers compare the two byte for byte to check that a certificate and a signer belong together. A signer for a remote key reads this once, when it is made.
Sourcefn sign(
&self,
algorithm: SignatureAlgorithm,
message: &[u8],
rng: &mut dyn RandomSource,
out: &mut [u8],
) -> Result<usize>
fn sign( &self, algorithm: SignatureAlgorithm, message: &[u8], rng: &mut dyn RandomSource, out: &mut [u8], ) -> Result<usize>
Sign message with algorithm, writing the signature to the front of
out and returning its length.
rng supplies randomness for the algorithms that use it; a device that
draws its own ignores it. out shorter than the signature is refused
with InvalidLength, with nothing written and nothing consumed;
SignatureAlgorithm::max_signature_len is always long enough. An
algorithm not in algorithms is refused with
InvalidParameter.
Dyn Compatibility§
This trait is dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".