Skip to main content

SecretKey

Struct SecretKey 

Source
pub struct SecretKey(/* private fields */);
Expand description

A secret key for Ed25519 digital signatures

Used to create signatures that can be verified with the corresponding PublicKey. The secret key must be kept private to maintain security.

§Properties

  • Size: 64 bytes (512 bits)
  • Contains both the secret scalar (32 bytes) and the public key (32 bytes)
  • Must be kept confidential
  • Used to sign messages

§Security Considerations

The secret key is the most sensitive component in the digital signature system. If compromised, an attacker can create valid signatures for any message, impersonating the legitimate owner of the key.

Best practices for secret key management:

  • Store secret keys in secure, encrypted storage
  • Consider using hardware security modules (HSMs) for high-security applications
  • Implement proper access controls to limit who can use the signing key
  • Rotate keys periodically according to your security policy
  • Have a revocation plan in case a key is compromised

§Usage

use libsodium_rs as sodium;
use sodium::crypto_sign;
use sodium::ensure_init;

// Initialize libsodium
ensure_init().expect("Failed to initialize libsodium");

// Generate a key pair
let keypair = crypto_sign::KeyPair::generate().unwrap();
let secret_key = keypair.secret_key;

// Sign a message
let message = b"Important document";
let signature = crypto_sign::sign_detached(message, &secret_key).unwrap();

// In a real application, you would securely store the secret key
// and implement proper key management procedures

Implementations§

Source§

impl SecretKey

Source

pub fn from_bytes(bytes: &[u8]) -> Result<Self>

Generate a new secret key from bytes

§Arguments
  • bytes - The bytes to create the secret key from
§Returns
  • Result<Self> - The secret key or an error if the input is invalid
§Errors

Returns an error if the input is not exactly SECRETKEYBYTES bytes long

Source

pub fn as_bytes(&self) -> &[u8; 64]

Get the bytes of the secret key

§Returns
  • &[u8; SECRETKEYBYTES] - A reference to the secret key bytes
Source

pub const fn from_bytes_exact(bytes: [u8; 64]) -> Self

Create a secret key from a fixed-size byte array

§Arguments
  • bytes - Byte array of exactly SECRETKEYBYTES length
§Returns
  • Self - A new secret key

Trait Implementations§

Source§

impl AsRef<[u8]> for SecretKey

Source§

fn as_ref(&self) -> &[u8]

Converts this type into a shared reference of the (usually inferred) input type.
Source§

impl Clone for SecretKey

Source§

fn clone(&self) -> SecretKey

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SecretKey

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for SecretKey

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Drop for SecretKey

Source§

fn drop(&mut self)

Executes the destructor for this type. Read more
Source§

fn pin_drop(self: Pin<&mut Self>)

🔬This is a nightly-only experimental API. (pin_ergonomics)
Execute the destructor for this type, but different to Drop::drop, it requires self to be pinned. Read more
Source§

impl Eq for SecretKey

Source§

impl From<SecretKey> for [u8; 64]

Source§

fn from(key: SecretKey) -> [u8; 64]

Converts to this type from the input type.
Source§

impl From<[u8; 64]> for SecretKey

Source§

fn from(bytes: [u8; 64]) -> Self

Converts to this type from the input type.
Source§

impl PartialEq for SecretKey

Source§

fn eq(&self, other: &SecretKey) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl StructuralPartialEq for SecretKey

Source§

impl TryFrom<&[u8]> for SecretKey

Source§

type Error = SodiumError

The type returned in the event of a conversion error.
Source§

fn try_from(bytes: &[u8]) -> Result<Self, Self::Error>

Performs the conversion.
Source§

impl Zeroize for SecretKey

Source§

fn zeroize(&mut self)

Zero out this object from memory using Rust intrinsics which ensure the zeroization operation is not “optimized away” by the compiler.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.