1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
#![deny(
missing_docs,
trivial_casts,
trivial_numeric_casts,
unsafe_code,
unused_import_braces,
unused_qualifications,
warnings
)]
use ockam_core::Result;
use ockam_vault_core::Secret;
use zeroize::Zeroize;
pub trait KeyExchanger {
fn name(&self) -> String;
fn generate_request(&mut self, payload: &[u8]) -> Result<Vec<u8>>;
fn handle_response(&mut self, response: &[u8]) -> Result<Vec<u8>>;
fn is_complete(&self) -> bool;
fn finalize(self) -> Result<CompletedKeyExchange>;
}
pub trait NewKeyExchanger {
type Initiator: KeyExchanger + Send + 'static;
type Responder: KeyExchanger + Send + 'static;
fn initiator(&self) -> Result<Self::Initiator>;
fn responder(&self) -> Result<Self::Responder>;
}
#[derive(Debug, Zeroize)]
pub struct CompletedKeyExchange {
h: [u8; 32],
encrypt_key: Secret,
decrypt_key: Secret,
}
impl CompletedKeyExchange {
pub fn h(&self) -> &[u8; 32] {
&self.h
}
pub fn encrypt_key(&self) -> &Secret {
&self.encrypt_key
}
pub fn decrypt_key(&self) -> &Secret {
&self.decrypt_key
}
}
impl CompletedKeyExchange {
pub fn new(h: [u8; 32], encrypt_key: Secret, decrypt_key: Secret) -> Self {
CompletedKeyExchange {
h,
encrypt_key,
decrypt_key,
}
}
}