Expand description
Signed objects, as macula_signed_object and macula-go sign and verify them:
a record, a request, a reply, a relay error, a publication, or a stream
frame. The fields gain alg, the signer’s profile algorithm, and are
encoded as tbs in the deterministic form; the signature covers the label, a
zero byte, the SHA-384 of the signer’s key as carried, and tbs. An
Object carries its key; a HeldObject leaves it out for a verifier
that already holds it, and still signs its hash.
Structs§
- Held
Object - A signed object whose verifier already holds the signer’s key.
- Object
- A signed object that carries its signer’s key as carried.
- Verified
Object - A signed object that verified: the key it verified with, its tbs bytes as received, and the map they decode to.
Enums§
- Object
Error - The refusals of a signed object, named as macula_signed_object names them, and the ones signing gives.
Functions§
- sign_
held_ object sign_objectfor a verifier that already holdskey.- sign_
object - Signs
fieldsunderlabelwithkey. The fields gain alg, replacing any alg they held; every field needs a text key of its own. - verify_
held_ object - Verifies an object whose key the verifier holds, as carried, under
labeland the verifier’sprofile. - verify_
object - Verifies an object that carries its key, under
labeland the verifier’sprofile, in macula’s order: exactly key, tbs and signature, each a byte string; key in the profile’s carried form; the signature over tbs as received; only then tbs under the decoding rule, a map whose alg names the profile’s algorithm. alg is checked and never selects an algorithm.