pub trait KeyStore {
// Required methods
fn save_key(&self, key: &[u8]) -> Result<(), KeyStoreError>;
fn load_key(&self) -> Result<Zeroizing<Vec<u8>>, KeyStoreError>;
fn delete_key(&self) -> Result<(), KeyStoreError>;
}Expand description
Secure storage for one node key, as the bytes of its key file (the seed
form: the ML-DSA-87 seed, and in pq_hybrid the RSA-PSS key too, a few KiB).
Implement this directly for a backend other than KeyringStore (a
hardware security module, a different vault) — this is the override point
“per target platform” hangs off, not a platform enum this crate switches on
internally.
Required Methods§
Sourcefn save_key(&self, key: &[u8]) -> Result<(), KeyStoreError>
fn save_key(&self, key: &[u8]) -> Result<(), KeyStoreError>
Persist key, overwriting any value already stored under this
store’s identity.
Sourcefn load_key(&self) -> Result<Zeroizing<Vec<u8>>, KeyStoreError>
fn load_key(&self) -> Result<Zeroizing<Vec<u8>>, KeyStoreError>
Retrieve a previously-save_keyd key.
KeyStoreError::NotFound if nothing has been stored yet.
Sourcefn delete_key(&self) -> Result<(), KeyStoreError>
fn delete_key(&self) -> Result<(), KeyStoreError>
Remove a previously-stored key, if any. Not required before a
save_key (which overwrites), only for
deliberately forgetting an identity.
Dyn Compatibility§
This trait is dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".