Skip to main content

Module binding

Module binding 

Source
Expand description

TLS and CONNECT bindings and status statements, as macula_key_bindings and macula-go make and check them. A binding ties a station’s TLS leaf, or a node’s CONNECT key, to an identity key for up to 7 days; a status statement keeps a binding in force for up to an hour. Each travels as {tbs, signature}, the signature over its label, a zero byte and the tbs bytes; a verifier checks the signature over the bytes it received first, and only then decodes them.

Structs§

BindingInfo
What a verified binding says.
SignedTbs
A signed structure as it travels: tbs, the deterministic CBOR of its fields, and a signature over its label, a zero byte and tbs.

Enums§

BindingError
The refusals of the binding and status checks, named as macula names them.
BindingUse
What a binding binds to the identity key.

Functions§

connect_binding
Binds a CONNECT key, by the SHA-384 of the key as carried, to identity_key, from not_before to not_after in milliseconds.
status_statement
Keeps binding in force from issued_at to expires_at in milliseconds, at most an hour, signed by identity_key.
tls_binding
Binds the TLS key of the leaf certificate a listener presents to identity_key, by the SHA-384 of the leaf’s DER, from not_before to not_after in milliseconds.
verify_connect_binding
Checks binding against the identity key as carried, under profile, and the CONNECT key as carried, at now_ms with 5 minutes of tolerance.
verify_status
Checks a status statement for the binding it came with, against the identity key as carried, under profile, at now_ms with 5 minutes of tolerance, and returns when the statement expires. It checks that the statement names that binding, not the binding itself: a caller verifies the binding too.
verify_tls_binding
Checks binding against the identity key as carried, under profile, and the leaf certificate this connection presented, at now_ms with 5 minutes of tolerance.