Expand description
A macula 12 node’s keys, as macula and macula-go hold them: ML-DSA-87 in
pq_pure, and in pq_hybrid the LAMPS composite id-MLDSA87-RSA4096-PSS-SHA512
(draft-ietf-lamps-pq-composite-sigs), which signs with both halves and is
valid only when both verify. An identity key’s node_id (D5) solves the
admission puzzle; a CONNECT key is bound to it (see crate::binding).
Keys are stored in macula’s seed form, readable by their owner only (see
NodeKey::save and NodeKey::load).
The ML-DSA-87 half is macula-mldsa, the implementation macula-pqc signs TLS with, kept as its 32-byte seed. The RSA-PSS-4096 half is aws-lc-rs, already linked through rustls: constant-time, with a FIPS path.
Structs§
- NodeKey
- One of a node’s keys in its profile: the ML-DSA-87 half, and in pq_hybrid the RSA-PSS-4096 half. It signs as a whole, never with one half on its own. Showing it gives its purpose, profile and key id, never a private half.
Enums§
- KeyError
- Why a key operation refused.
- KeyFile
Error - Why a key file was not saved or loaded.
- Purpose
- What a node key is for. Each key serves exactly one purpose.
Constants§
- PUZZLE_
DIFFICULTY - How many leading zero bits an identity key’s node_id has: a node generates
its identity key for it (
NodeKey::generate_identity), and stations check it.
Functions§
- carried_
key_ well_ formed - Whether
keyis a key in its one carried form forprofile(D13): exactly 2,592 bytes in pq_pure, and in pq_hybrid the ML-DSA-87 key followed by a DERRSAPublicKeythat encodes back to the same bytes, with a 4,096-bit modulus and exponent 65537. It says nothing about who holds the key. - key_
id_ of - The key id of a key as carried that is not an identity key. Like a node_id, it earns no trust on its own.
- node_
id_ of - The node_id of an identity key as carried, under
profile(D5). A node_id earns no trust on its own: rely on it only after a signature by the same carried key has verified. - puzzle_
solved - Whether
node_idstarts withdifficultyzero bits. A difficulty above 256 is never solved. - signature_
size - The size of a signature by a node key in
profile: the ML-DSA-87 signature, followed in pq_hybrid by an RSA-PSS signature as long as the modulus. - verify
- Whether
signatureis valid overmessagefor a key as carried, underprofile: an ML-DSA-87 signature in pq_pure, and in pq_hybrid a composite whose two halves both verify, with the key in its one carried form. Malformed input is refused, never panicked on.