Skip to main content

KeyStore

Trait KeyStore 

Source
pub trait KeyStore {
    // Required methods
    fn save_key(&self, key: &[u8]) -> Result<(), KeyStoreError>;
    fn load_key(&self) -> Result<Zeroizing<Vec<u8>>, KeyStoreError>;
    fn delete_key(&self) -> Result<(), KeyStoreError>;
}
Expand description

Secure storage for one node key, as the bytes of its key file (the seed form: the ML-DSA-87 seed, and in pq_hybrid the RSA-PSS key too, a few KiB). Implement this directly for a backend other than KeyringStore (a hardware security module, a different vault) — this is the override point “per target platform” hangs off, not a platform enum this crate switches on internally.

Required Methods§

Source

fn save_key(&self, key: &[u8]) -> Result<(), KeyStoreError>

Persist key, overwriting any value already stored under this store’s identity.

Source

fn load_key(&self) -> Result<Zeroizing<Vec<u8>>, KeyStoreError>

Retrieve a previously-save_keyd key. KeyStoreError::NotFound if nothing has been stored yet.

Source

fn delete_key(&self) -> Result<(), KeyStoreError>

Remove a previously-stored key, if any. Not required before a save_key (which overwrites), only for deliberately forgetting an identity.

Dyn Compatibility§

This trait is dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§

Source§

impl KeyStore for KeyringStore

Source§

impl KeyStore for LinuxKeyutilsStore

Available on Linux only.