Skip to main content

Module signed_object

Module signed_object 

Source
Expand description

Signed objects, as macula_signed_object and macula-go sign and verify them: a record, a request, a reply, a relay error, a publication, or a stream frame. The fields gain alg, the signer’s profile algorithm, and are encoded as tbs in the deterministic form; the signature covers the label, a zero byte, the SHA-384 of the signer’s key as carried, and tbs. An Object carries its key; a HeldObject leaves it out for a verifier that already holds it, and still signs its hash.

Structs§

HeldObject
A signed object whose verifier already holds the signer’s key.
Object
A signed object that carries its signer’s key as carried.
VerifiedObject
A signed object that verified: the key it verified with, its tbs bytes as received, and the map they decode to.

Enums§

ObjectError
The refusals of a signed object, named as macula_signed_object names them, and the ones signing gives.

Functions§

sign_held_object
sign_object for a verifier that already holds key.
sign_object
Signs fields under label with key. The fields gain alg, replacing any alg they held; every field needs a text key of its own.
verify_held_object
Verifies an object whose key the verifier holds, as carried, under label and the verifier’s profile.
verify_object
Verifies an object that carries its key, under label and the verifier’s profile, in macula’s order: exactly key, tbs and signature, each a byte string; key in the profile’s carried form; the signature over tbs as received; only then tbs under the decoding rule, a map whose alg names the profile’s algorithm. alg is checked and never selects an algorithm.