pub struct SecretKey(/* private fields */);Expand description
A secret key for key exchange
This represents a Curve25519 secret key used in the X25519 key exchange. Secret keys must be kept private and never shared.
§Size
A secret key is always exactly SECRETKEYBYTES (32) bytes.
§Security Considerations
Secret keys should be generated using a secure random number generator and should never be exposed. When a secret key is no longer needed, it should be securely erased from memory.
§Security
Secret keys should be protected with the same care as passwords or encryption keys. They should never be transmitted over a network or stored in plaintext.
§Usage
Secret keys are typically generated with the KeyPair::generate() function
and used locally to compute shared session keys.
Implementations§
Source§impl SecretKey
impl SecretKey
Sourcepub fn from_bytes(bytes: &[u8]) -> Result<Self>
pub fn from_bytes(bytes: &[u8]) -> Result<Self>
Create a secret key from existing bytes
This function creates a secret key from an existing byte array. It’s useful when you need to deserialize a secret key that was previously serialized or derived from another source.
§Security Considerations
Be extremely careful when handling secret key material. Secret keys should never be transmitted over a network or stored in plaintext.
§Arguments
bytes- A byte slice of exactlySECRETKEYBYTES(32) length
§Returns
Result<Self>- A new secret key or an error if the input is invalid
§Errors
Returns an error if the input is not exactly SECRETKEYBYTES bytes long.
§Example
use libsodium_rs as sodium;
use sodium::crypto_kx::SecretKey;
use sodium::ensure_init;
// Initialize libsodium
ensure_init().expect("Failed to initialize libsodium");
// Create a secret key from bytes (e.g., from secure storage)
let key_bytes = [0x42; 32]; // 32 bytes of data
let secret_key = SecretKey::from_bytes(&key_bytes).unwrap();Sourcepub fn as_bytes(&self) -> &[u8] ⓘ
pub fn as_bytes(&self) -> &[u8] ⓘ
Get the raw bytes of the secret key
This function returns a reference to the internal byte array of the secret key. It’s useful when you need to serialize the secret key for secure storage.
§Security Considerations
Be extremely careful when handling the raw bytes of a secret key. They should never be logged, transmitted over a network, or stored in plaintext.
§Returns
&[u8]- A reference to the secret key bytes
§Example
use libsodium_rs as sodium;
use sodium::crypto_kx;
use sodium::ensure_init;
// Initialize libsodium
ensure_init().expect("Failed to initialize libsodium");
// Generate a keypair
let keypair = crypto_kx::KeyPair::generate().unwrap();
let secret_key = keypair.secret_key;
// Get the raw bytes of the secret key (handle with care!)
let key_bytes = secret_key.as_bytes();
assert_eq!(key_bytes.len(), crypto_kx::SECRETKEYBYTES);