Expand description
TLS and CONNECT bindings and status statements, as macula_key_bindings and
macula-go make and check them. A binding ties a station’s TLS leaf, or a
node’s CONNECT key, to an identity key for up to 7 days; a status
statement keeps a binding in force for up to an hour. Each travels as
{tbs, signature}, the signature over its label, a zero byte and the tbs
bytes; a verifier checks the signature over the bytes it received first,
and only then decodes them.
Structs§
- Binding
Info - What a verified binding says.
- Signed
Tbs - A signed structure as it travels: tbs, the deterministic CBOR of its fields, and a signature over its label, a zero byte and tbs.
Enums§
- Binding
Error - The refusals of the binding and status checks, named as macula names them.
- Binding
Use - What a binding binds to the identity key.
Functions§
- connect_
binding - Binds a CONNECT key, by the SHA-384 of the key as carried, to
identity_key, fromnot_beforetonot_afterin milliseconds. - status_
statement - Keeps
bindingin force fromissued_attoexpires_atin milliseconds, at most an hour, signed byidentity_key. - tls_
binding - Binds the TLS key of the leaf certificate a listener presents to
identity_key, by the SHA-384 of the leaf’s DER, fromnot_beforetonot_afterin milliseconds. - verify_
connect_ binding - Checks
bindingagainst the identity key as carried, underprofile, and the CONNECT key as carried, atnow_mswith 5 minutes of tolerance. - verify_
status - Checks a status statement for the binding it came with, against the
identity key as carried, under
profile, atnow_mswith 5 minutes of tolerance, and returns when the statement expires. It checks that the statement names that binding, not the binding itself: a caller verifies the binding too. - verify_
tls_ binding - Checks
bindingagainst the identity key as carried, underprofile, and the leaf certificate this connection presented, atnow_mswith 5 minutes of tolerance.