Skip to main content

SecretKey

Struct SecretKey 

Source
pub struct SecretKey(/* private fields */);
Expand description

A secret key for key exchange

This represents a Curve25519 secret key used in the X25519 key exchange. Secret keys must be kept private and never shared.

§Size

A secret key is always exactly SECRETKEYBYTES (32) bytes.

§Security Considerations

Secret keys should be generated using a secure random number generator and should never be exposed. When a secret key is no longer needed, it should be securely erased from memory.

§Security

Secret keys should be protected with the same care as passwords or encryption keys. They should never be transmitted over a network or stored in plaintext.

§Usage

Secret keys are typically generated with the KeyPair::generate() function and used locally to compute shared session keys.

Implementations§

Source§

impl SecretKey

Source

pub fn from_bytes(bytes: &[u8]) -> Result<Self>

Create a secret key from existing bytes

This function creates a secret key from an existing byte array. It’s useful when you need to deserialize a secret key that was previously serialized or derived from another source.

§Security Considerations

Be extremely careful when handling secret key material. Secret keys should never be transmitted over a network or stored in plaintext.

§Arguments
  • bytes - A byte slice of exactly SECRETKEYBYTES (32) length
§Returns
  • Result<Self> - A new secret key or an error if the input is invalid
§Errors

Returns an error if the input is not exactly SECRETKEYBYTES bytes long.

§Example
use libsodium_rs as sodium;
use sodium::crypto_kx::SecretKey;
use sodium::ensure_init;

// Initialize libsodium
ensure_init().expect("Failed to initialize libsodium");

// Create a secret key from bytes (e.g., from secure storage)
let key_bytes = [0x42; 32]; // 32 bytes of data
let secret_key = SecretKey::from_bytes(&key_bytes).unwrap();
Source

pub fn as_bytes(&self) -> &[u8]

Get the raw bytes of the secret key

This function returns a reference to the internal byte array of the secret key. It’s useful when you need to serialize the secret key for secure storage.

§Security Considerations

Be extremely careful when handling the raw bytes of a secret key. They should never be logged, transmitted over a network, or stored in plaintext.

§Returns
  • &[u8] - A reference to the secret key bytes
§Example
use libsodium_rs as sodium;
use sodium::crypto_kx;
use sodium::ensure_init;

// Initialize libsodium
ensure_init().expect("Failed to initialize libsodium");

// Generate a keypair
let keypair = crypto_kx::KeyPair::generate().unwrap();
let secret_key = keypair.secret_key;

// Get the raw bytes of the secret key (handle with care!)
let key_bytes = secret_key.as_bytes();
assert_eq!(key_bytes.len(), crypto_kx::SECRETKEYBYTES);

Trait Implementations§

Source§

impl AsRef<[u8]> for SecretKey

Source§

fn as_ref(&self) -> &[u8]

Converts this type into a shared reference of the (usually inferred) input type.
Source§

impl Clone for SecretKey

Source§

fn clone(&self) -> SecretKey

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SecretKey

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Drop for SecretKey

Source§

fn drop(&mut self)

Executes the destructor for this type. Read more
Source§

fn pin_drop(self: Pin<&mut Self>)

🔬This is a nightly-only experimental API. (pin_ergonomics)
Execute the destructor for this type, but different to Drop::drop, it requires self to be pinned. Read more
Source§

impl Eq for SecretKey

Source§

impl From<SecretKey> for [u8; 32]

Source§

fn from(key: SecretKey) -> Self

Converts to this type from the input type.
Source§

impl From<[u8; 32]> for SecretKey

Source§

fn from(bytes: [u8; 32]) -> Self

Converts to this type from the input type.
Source§

impl PartialEq for SecretKey

Source§

fn eq(&self, other: &SecretKey) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl StructuralPartialEq for SecretKey

Source§

impl TryFrom<&[u8]> for SecretKey

Source§

type Error = SodiumError

The type returned in the event of a conversion error.
Source§

fn try_from(bytes: &[u8]) -> Result<Self, Self::Error>

Performs the conversion.
Source§

impl Zeroize for SecretKey

Source§

fn zeroize(&mut self)

Zero out this object from memory using Rust intrinsics which ensure the zeroization operation is not “optimized away” by the compiler.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.