pub struct SignatureConfig {
pub typ: SignatureType,
pub pub_alg: PublicKeyAlgorithm,
pub hash_alg: HashAlgorithm,
pub unhashed_subpackets: Vec<Subpacket>,
pub hashed_subpackets: Vec<Subpacket>,
pub version_specific: SignatureVersionSpecific,
}Expand description
The metadata of an OpenPGP Signature packet.
An OpenPGP Signature packet is split into a SignatureConfig (this struct),
a two byte excerpt of the signed hash value, and the cryptographic signature as such.
A SignatureConfig specifies the “type” of a signature and the cryptographic algorithms
that the signature uses.
In addition, it contains two lists of Subpackets:
The subpackets in the list of hashed_subpackets are protected by the signature, they
represent a part of the “semantics” of that signature.
The authenticity of hashed_subpackets is guaranteed if signature verification succeeds.
A Signature will usually include a subpacket with the
SubpacketData::SignatureCreationTime in their hashed area, and usually other subpackets.
The unhashed_subpackets, by contracts, are not covered by the cryptographic signature.
The contents of this area are thus not protected against tampering.
Potential uses of the unhashed_area:
- subpackets that can be independently verified by a recipient
(e.g.
SubpacketData::IssuerKeyId, - annotations made on a signature by a third party, such as a key server (note that a third party can’t add data to the hashed area without breaking the cryptographic signature), or
- information that the sender wants to be able to plausibly deny
Fields§
§typ: SignatureType§pub_alg: PublicKeyAlgorithm§hash_alg: HashAlgorithm§unhashed_subpackets: Vec<Subpacket>§hashed_subpackets: Vec<Subpacket>§version_specific: SignatureVersionSpecificImplementations§
Source§impl SignatureConfig
impl SignatureConfig
pub fn from_key<R: CryptoRng + Rng, S: SigningKey>( rng: R, key: &S, typ: SignatureType, ) -> Result<Self>
Sourcepub fn v2(
typ: SignatureType,
pub_alg: PublicKeyAlgorithm,
hash_alg: HashAlgorithm,
created: Timestamp,
issuer_key_id: KeyId,
) -> Self
pub fn v2( typ: SignatureType, pub_alg: PublicKeyAlgorithm, hash_alg: HashAlgorithm, created: Timestamp, issuer_key_id: KeyId, ) -> Self
Constructor for a v2 SignatureConfig (which represents the data of a v2 OpenPGP signature packet)
OpenPGP v2 Signatures are historical and not used anymore.
Sourcepub fn v3(
typ: SignatureType,
pub_alg: PublicKeyAlgorithm,
hash_alg: HashAlgorithm,
created: Timestamp,
issuer_key_id: KeyId,
) -> Self
pub fn v3( typ: SignatureType, pub_alg: PublicKeyAlgorithm, hash_alg: HashAlgorithm, created: Timestamp, issuer_key_id: KeyId, ) -> Self
Constructor for a v3 SignatureConfig (which represents the data of a v3 OpenPGP signature packet)
OpenPGP v3 Signatures are historical and not used anymore.
Sourcepub fn v4(
typ: SignatureType,
pub_alg: PublicKeyAlgorithm,
hash_alg: HashAlgorithm,
) -> Self
pub fn v4( typ: SignatureType, pub_alg: PublicKeyAlgorithm, hash_alg: HashAlgorithm, ) -> Self
Constructor for a v4 SignatureConfig (which represents the data of a v4 OpenPGP signature packet)
OpenPGP v4 signatures were first specified in RFC 2440, and are commonly produced by OpenPGP v4 keys.
Sourcepub fn v6<R: CryptoRng + Rng>(
rng: R,
typ: SignatureType,
pub_alg: PublicKeyAlgorithm,
hash_alg: HashAlgorithm,
) -> Result<Self>
pub fn v6<R: CryptoRng + Rng>( rng: R, typ: SignatureType, pub_alg: PublicKeyAlgorithm, hash_alg: HashAlgorithm, ) -> Result<Self>
Constructor for a v6 SignatureConfig (which represents the data of a v6 OpenPGP signature packet).
Generates a new salt via rng.
OpenPGP v6 signatures are specified in RFC 9580, they are produced by OpenPGP v6 keys.
Sourcepub fn v6_with_salt(
typ: SignatureType,
pub_alg: PublicKeyAlgorithm,
hash_alg: HashAlgorithm,
salt: Vec<u8>,
) -> Self
pub fn v6_with_salt( typ: SignatureType, pub_alg: PublicKeyAlgorithm, hash_alg: HashAlgorithm, salt: Vec<u8>, ) -> Self
Constructor for a v6 SignatureConfig (which represents the data of a v6 OpenPGP signature packet).
OpenPGP v6 signatures are specified in RFC 9580, they are produced by OpenPGP v6 keys.
pub fn version(&self) -> SignatureVersion
Sourcepub fn sign<R>(
self,
key: &impl SigningKey,
key_pw: &Password,
data: R,
) -> Result<Signature>where
R: Read,
pub fn sign<R>(
self,
key: &impl SigningKey,
key_pw: &Password,
data: R,
) -> Result<Signature>where
R: Read,
Sign the given data.
pub fn into_hasher(self) -> Result<SignatureHasher>
Sourcepub fn sign_certification<S, K>(
self,
key: &S,
pub_key: &K,
key_pw: &Password,
tag: Tag,
id: &impl Serialize,
) -> Result<Signature>
pub fn sign_certification<S, K>( self, key: &S, pub_key: &K, key_pw: &Password, tag: Tag, id: &impl Serialize, ) -> Result<Signature>
Create a certification self-signature.
Sourcepub fn sign_certification_third_party<K>(
self,
signer: &impl SigningKey,
signer_pw: &Password,
signee: &K,
tag: Tag,
id: &impl Serialize,
) -> Result<Signature>where
K: KeyDetails + Serialize,
pub fn sign_certification_third_party<K>(
self,
signer: &impl SigningKey,
signer_pw: &Password,
signee: &K,
tag: Tag,
id: &impl Serialize,
) -> Result<Signature>where
K: KeyDetails + Serialize,
Create a certification third-party signature.
Sourcepub fn sign_subkey_binding<S, K1, K2>(
self,
signer: &S,
signer_pub: &K1,
signer_pw: &Password,
signee: &K2,
) -> Result<Signature>
pub fn sign_subkey_binding<S, K1, K2>( self, signer: &S, signer_pub: &K1, signer_pw: &Password, signee: &K2, ) -> Result<Signature>
Sign a subkey binding that associates a subkey with a primary key.
The primary key is expected as signer, the subkey as signee.
Produces a “Subkey Binding Signature (type ID 0x18)”
Sourcepub fn sign_primary_key_binding<S, K1, K2>(
self,
signer: &S,
signer_pub: &K1,
signer_pw: &Password,
signee: &K2,
) -> Result<Signature>
pub fn sign_primary_key_binding<S, K1, K2>( self, signer: &S, signer_pub: &K1, signer_pw: &Password, signee: &K2, ) -> Result<Signature>
Sign a primary key binding, or “back signature” (with this signature, the subkey signals that it wants to be associated with the primary).
The subkey is expected as signer, the primary key as signee.
Produces a “Primary Key Binding Signature (type ID 0x19)”
Sourcepub fn sign_key<S, K>(
self,
signing_key: &S,
key_pw: &Password,
key: &K,
) -> Result<Signature>
pub fn sign_key<S, K>( self, signing_key: &S, key_pw: &Password, key: &K, ) -> Result<Signature>
Signs a direct key signature or a revocation.
Sourcepub fn typ(&self) -> SignatureType
pub fn typ(&self) -> SignatureType
Returns what kind of signature this is.
Sourcepub fn hash_signature_data(
&self,
hasher: &mut Box<dyn DynDigest + Send>,
) -> Result<usize>
pub fn hash_signature_data( &self, hasher: &mut Box<dyn DynDigest + Send>, ) -> Result<usize>
Calculate the serialized version of this packet, but only the part relevant for hashing.
pub fn hash_data_to_sign<R>(
&self,
hasher: &mut Box<dyn DynDigest + Send>,
data: R,
) -> Result<usize>where
R: Read,
pub fn trailer(&self, len: usize) -> Result<Vec<u8>>
Sourcepub fn subpackets(&self) -> impl Iterator<Item = &Subpacket>
👎Deprecated: Usually only hashed_subpackets should be used. unhashed_subpackets are only safe and useful to access in rare circumstances. When they are needed, unhashed_subpackets should be explicitly called.
pub fn subpackets(&self) -> impl Iterator<Item = &Subpacket>
Usually only hashed_subpackets should be used. unhashed_subpackets are only safe and useful to access in rare circumstances. When they are needed, unhashed_subpackets should be explicitly called.
Returns an iterator of all subpackets in the signature: all subpackets in the hashed area followed by all subpackets in the unhashed area.
Sourcepub fn hashed_subpackets(&self) -> impl Iterator<Item = &Subpacket>
pub fn hashed_subpackets(&self) -> impl Iterator<Item = &Subpacket>
Returns an iterator over the hashed subpackets of this signature.
Sourcepub fn unhashed_subpackets(&self) -> impl Iterator<Item = &Subpacket>
pub fn unhashed_subpackets(&self) -> impl Iterator<Item = &Subpacket>
Returns an iterator over the unhashed subpackets of this signature.
Sourcepub fn is_certification(&self) -> bool
pub fn is_certification(&self) -> bool
Returns if the signature is a certification or not.
Sourcepub fn created(&self) -> Option<Timestamp>
pub fn created(&self) -> Option<Timestamp>
Signature Creation Time.
The time the signature was made. MUST be present in the hashed area.
https://www.rfc-editor.org/rfc/rfc9580.html#name-signature-creation-time
Returns the first Signature Creation Time subpacket, only from the hashed area.
Sourcepub fn issuer_key_id(&self) -> Vec<&KeyId>
pub fn issuer_key_id(&self) -> Vec<&KeyId>
Issuer Key ID.
The OpenPGP Key ID of the key issuing the signature.
https://www.rfc-editor.org/rfc/rfc9580.html#name-issuer-key-id
Returns Issuer subpacket data from both the hashed and unhashed area.
Sourcepub fn issuer_fingerprint(&self) -> Vec<&Fingerprint>
pub fn issuer_fingerprint(&self) -> Vec<&Fingerprint>
Issuer Fingerprint.
The OpenPGP Key fingerprint of the key issuing the signature.
https://www.rfc-editor.org/rfc/rfc9580.html#name-issuer-fingerprint
Returns Issuer Fingerprint subpacket data from both the hashed and unhashed area.
Trait Implementations§
Source§impl Clone for SignatureConfig
impl Clone for SignatureConfig
Source§fn clone(&self) -> SignatureConfig
fn clone(&self) -> SignatureConfig
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for SignatureConfig
impl Debug for SignatureConfig
impl Eq for SignatureConfig
Source§impl PartialEq for SignatureConfig
impl PartialEq for SignatureConfig
Source§fn eq(&self, other: &SignatureConfig) -> bool
fn eq(&self, other: &SignatureConfig) -> bool
self and other values to be equal, and is used by ==.impl StructuralPartialEq for SignatureConfig
Auto Trait Implementations§
impl Freeze for SignatureConfig
impl RefUnwindSafe for SignatureConfig
impl Send for SignatureConfig
impl Sync for SignatureConfig
impl Unpin for SignatureConfig
impl UnsafeUnpin for SignatureConfig
impl UnwindSafe for SignatureConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.