Skip to main content

SignatureConfig

Struct SignatureConfig 

Source
pub struct SignatureConfig {
    pub typ: SignatureType,
    pub pub_alg: PublicKeyAlgorithm,
    pub hash_alg: HashAlgorithm,
    pub unhashed_subpackets: Vec<Subpacket>,
    pub hashed_subpackets: Vec<Subpacket>,
    pub version_specific: SignatureVersionSpecific,
}
Expand description

The metadata of an OpenPGP Signature packet.

An OpenPGP Signature packet is split into a SignatureConfig (this struct), a two byte excerpt of the signed hash value, and the cryptographic signature as such.

A SignatureConfig specifies the “type” of a signature and the cryptographic algorithms that the signature uses.

In addition, it contains two lists of Subpackets:

The subpackets in the list of hashed_subpackets are protected by the signature, they represent a part of the “semantics” of that signature.

The authenticity of hashed_subpackets is guaranteed if signature verification succeeds.

A Signature will usually include a subpacket with the SubpacketData::SignatureCreationTime in their hashed area, and usually other subpackets.

The unhashed_subpackets, by contracts, are not covered by the cryptographic signature. The contents of this area are thus not protected against tampering.

Potential uses of the unhashed_area:

  • subpackets that can be independently verified by a recipient (e.g. SubpacketData::IssuerKeyId,
  • annotations made on a signature by a third party, such as a key server (note that a third party can’t add data to the hashed area without breaking the cryptographic signature), or
  • information that the sender wants to be able to plausibly deny

Fields§

§typ: SignatureType§pub_alg: PublicKeyAlgorithm§hash_alg: HashAlgorithm§unhashed_subpackets: Vec<Subpacket>§hashed_subpackets: Vec<Subpacket>§version_specific: SignatureVersionSpecific

Implementations§

Source§

impl SignatureConfig

Source

pub fn from_key<R: CryptoRng + Rng, S: SigningKey>( rng: R, key: &S, typ: SignatureType, ) -> Result<Self>

Source

pub fn v2( typ: SignatureType, pub_alg: PublicKeyAlgorithm, hash_alg: HashAlgorithm, created: Timestamp, issuer_key_id: KeyId, ) -> Self

Constructor for a v2 SignatureConfig (which represents the data of a v2 OpenPGP signature packet)

OpenPGP v2 Signatures are historical and not used anymore.

Source

pub fn v3( typ: SignatureType, pub_alg: PublicKeyAlgorithm, hash_alg: HashAlgorithm, created: Timestamp, issuer_key_id: KeyId, ) -> Self

Constructor for a v3 SignatureConfig (which represents the data of a v3 OpenPGP signature packet)

OpenPGP v3 Signatures are historical and not used anymore.

Source

pub fn v4( typ: SignatureType, pub_alg: PublicKeyAlgorithm, hash_alg: HashAlgorithm, ) -> Self

Constructor for a v4 SignatureConfig (which represents the data of a v4 OpenPGP signature packet)

OpenPGP v4 signatures were first specified in RFC 2440, and are commonly produced by OpenPGP v4 keys.

Source

pub fn v6<R: CryptoRng + Rng>( rng: R, typ: SignatureType, pub_alg: PublicKeyAlgorithm, hash_alg: HashAlgorithm, ) -> Result<Self>

Constructor for a v6 SignatureConfig (which represents the data of a v6 OpenPGP signature packet). Generates a new salt via rng.

OpenPGP v6 signatures are specified in RFC 9580, they are produced by OpenPGP v6 keys.

Source

pub fn v6_with_salt( typ: SignatureType, pub_alg: PublicKeyAlgorithm, hash_alg: HashAlgorithm, salt: Vec<u8>, ) -> Self

Constructor for a v6 SignatureConfig (which represents the data of a v6 OpenPGP signature packet).

OpenPGP v6 signatures are specified in RFC 9580, they are produced by OpenPGP v6 keys.

Source

pub fn version(&self) -> SignatureVersion

Source

pub fn sign<R>( self, key: &impl SigningKey, key_pw: &Password, data: R, ) -> Result<Signature>
where R: Read,

Sign the given data.

Source

pub fn into_hasher(self) -> Result<SignatureHasher>

Source

pub fn sign_certification<S, K>( self, key: &S, pub_key: &K, key_pw: &Password, tag: Tag, id: &impl Serialize, ) -> Result<Signature>

Create a certification self-signature.

Source

pub fn sign_certification_third_party<K>( self, signer: &impl SigningKey, signer_pw: &Password, signee: &K, tag: Tag, id: &impl Serialize, ) -> Result<Signature>
where K: KeyDetails + Serialize,

Create a certification third-party signature.

Source

pub fn sign_subkey_binding<S, K1, K2>( self, signer: &S, signer_pub: &K1, signer_pw: &Password, signee: &K2, ) -> Result<Signature>

Sign a subkey binding that associates a subkey with a primary key.

The primary key is expected as signer, the subkey as signee.

Produces a “Subkey Binding Signature (type ID 0x18)”

Source

pub fn sign_primary_key_binding<S, K1, K2>( self, signer: &S, signer_pub: &K1, signer_pw: &Password, signee: &K2, ) -> Result<Signature>

Sign a primary key binding, or “back signature” (with this signature, the subkey signals that it wants to be associated with the primary).

The subkey is expected as signer, the primary key as signee.

Produces a “Primary Key Binding Signature (type ID 0x19)”

Source

pub fn sign_key<S, K>( self, signing_key: &S, key_pw: &Password, key: &K, ) -> Result<Signature>

Signs a direct key signature or a revocation.

Source

pub fn typ(&self) -> SignatureType

Returns what kind of signature this is.

Source

pub fn hash_signature_data( &self, hasher: &mut Box<dyn DynDigest + Send>, ) -> Result<usize>

Calculate the serialized version of this packet, but only the part relevant for hashing.

Source

pub fn hash_data_to_sign<R>( &self, hasher: &mut Box<dyn DynDigest + Send>, data: R, ) -> Result<usize>
where R: Read,

Source

pub fn trailer(&self, len: usize) -> Result<Vec<u8>>

Source

pub fn subpackets(&self) -> impl Iterator<Item = &Subpacket>

👎Deprecated:

Usually only hashed_subpackets should be used. unhashed_subpackets are only safe and useful to access in rare circumstances. When they are needed, unhashed_subpackets should be explicitly called.

Returns an iterator of all subpackets in the signature: all subpackets in the hashed area followed by all subpackets in the unhashed area.

Source

pub fn hashed_subpackets(&self) -> impl Iterator<Item = &Subpacket>

Returns an iterator over the hashed subpackets of this signature.

Source

pub fn unhashed_subpackets(&self) -> impl Iterator<Item = &Subpacket>

Returns an iterator over the unhashed subpackets of this signature.

Source

pub fn is_certification(&self) -> bool

Returns if the signature is a certification or not.

Source

pub fn created(&self) -> Option<Timestamp>

Signature Creation Time.

The time the signature was made. MUST be present in the hashed area.

https://www.rfc-editor.org/rfc/rfc9580.html#name-signature-creation-time

Returns the first Signature Creation Time subpacket, only from the hashed area.

Source

pub fn issuer_key_id(&self) -> Vec<&KeyId>

Issuer Key ID.

The OpenPGP Key ID of the key issuing the signature.

https://www.rfc-editor.org/rfc/rfc9580.html#name-issuer-key-id

Returns Issuer subpacket data from both the hashed and unhashed area.

Source

pub fn issuer_fingerprint(&self) -> Vec<&Fingerprint>

Issuer Fingerprint.

The OpenPGP Key fingerprint of the key issuing the signature.

https://www.rfc-editor.org/rfc/rfc9580.html#name-issuer-fingerprint

Returns Issuer Fingerprint subpacket data from both the hashed and unhashed area.

Trait Implementations§

Source§

impl Clone for SignatureConfig

Source§

fn clone(&self) -> SignatureConfig

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SignatureConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for SignatureConfig

Source§

impl PartialEq for SignatureConfig

Source§

fn eq(&self, other: &SignatureConfig) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl StructuralPartialEq for SignatureConfig

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> Conv for T

Source§

fn conv<T>(self) -> T
where Self: Into<T>,

Converts self into T using Into<T>. Read more
Source§

impl<T> FmtForward for T

Source§

fn fmt_binary(self) -> FmtBinary<Self>
where Self: Binary,

Causes self to use its Binary implementation when Debug-formatted.
Source§

fn fmt_display(self) -> FmtDisplay<Self>
where Self: Display,

Causes self to use its Display implementation when Debug-formatted.
Source§

fn fmt_lower_exp(self) -> FmtLowerExp<Self>
where Self: LowerExp,

Causes self to use its LowerExp implementation when Debug-formatted.
Source§

fn fmt_lower_hex(self) -> FmtLowerHex<Self>
where Self: LowerHex,

Causes self to use its LowerHex implementation when Debug-formatted.
Source§

fn fmt_octal(self) -> FmtOctal<Self>
where Self: Octal,

Causes self to use its Octal implementation when Debug-formatted.
Source§

fn fmt_pointer(self) -> FmtPointer<Self>
where Self: Pointer,

Causes self to use its Pointer implementation when Debug-formatted.
Source§

fn fmt_upper_exp(self) -> FmtUpperExp<Self>
where Self: UpperExp,

Causes self to use its UpperExp implementation when Debug-formatted.
Source§

fn fmt_upper_hex(self) -> FmtUpperHex<Self>
where Self: UpperHex,

Causes self to use its UpperHex implementation when Debug-formatted.
Source§

fn fmt_list(self) -> FmtList<Self>
where &'a Self: for<'a> IntoIterator,

Formats each item in a sequence. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Pipe for T
where T: ?Sized,

Source§

fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> R
where Self: Sized,

Pipes by value. This is generally the method you want to use. Read more
Source§

fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> R
where R: 'a,

Borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> R
where R: 'a,

Mutably borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
where Self: Borrow<B>, B: 'a + ?Sized, R: 'a,

Borrows self, then passes self.borrow() into the pipe function. Read more
Source§

fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
where Self: BorrowMut<B>, B: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.borrow_mut() into the pipe function. Read more
Source§

fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
where Self: AsRef<U>, U: 'a + ?Sized, R: 'a,

Borrows self, then passes self.as_ref() into the pipe function.
Source§

fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
where Self: AsMut<U>, U: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.as_mut() into the pipe function.
Source§

fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
where Self: Deref<Target = T>, T: 'a + ?Sized, R: 'a,

Borrows self, then passes self.deref() into the pipe function.
Source§

fn pipe_deref_mut<'a, T, R>( &'a mut self, func: impl FnOnce(&'a mut T) -> R, ) -> R
where Self: DerefMut<Target = T> + Deref, T: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.deref_mut() into the pipe function.
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> Tap for T

Source§

fn tap(self, func: impl FnOnce(&Self)) -> Self

Immutable access to a value. Read more
Source§

fn tap_mut(self, func: impl FnOnce(&mut Self)) -> Self

Mutable access to a value. Read more
Source§

fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Immutable access to the Borrow<B> of a value. Read more
Source§

fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Mutable access to the BorrowMut<B> of a value. Read more
Source§

fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Immutable access to the AsRef<R> view of a value. Read more
Source§

fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Mutable access to the AsMut<R> view of a value. Read more
Source§

fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Immutable access to the Deref::Target of a value. Read more
Source§

fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Mutable access to the Deref::Target of a value. Read more
Source§

fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self

Calls .tap() only in debug builds, and is erased in release builds.
Source§

fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self

Calls .tap_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Calls .tap_borrow() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Calls .tap_borrow_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Calls .tap_ref() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Calls .tap_ref_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Calls .tap_deref() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_mut_dbg<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Calls .tap_deref_mut() only in debug builds, and is erased in release builds.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> TryConv for T

Source§

fn try_conv<T>(self) -> Result<T, Self::Error>
where Self: TryInto<T>,

Attempts to convert self into T using TryInto<T>. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V