Skip to main content

KeyRing

Struct KeyRing 

Source
pub struct KeyRing { /* private fields */ }
Expand description

One active key for sealing plus any number of retired keys kept only for opening. This is what makes the master key rotatable: run with both, rewrap the store, then drop the old key.

Implementations§

Source§

impl KeyRing

Source

pub fn new(active: &[u8; 32], retired: &[[u8; 32]]) -> Self

Source

pub fn active_key_id(&self) -> u32

Source

pub fn retired_key_count(&self) -> usize

The number of keys that exist only to read old data. Zero means the store is fully rewrapped, or was never rotated.

Trait Implementations§

Source§

impl Aead for KeyRing

Source§

fn seal(&self, plaintext: &[u8]) -> Result<Vec<u8>, CryptoError>

Source§

fn open(&self, blob: &[u8]) -> Result<Vec<u8>, CryptoError>

Source§

fn is_current(&self, blob: &[u8]) -> bool

Whether this blob is already sealed under the key seal would use. Rewrapping asks this so it can skip values that need no work; a single-key implementation has nothing to rotate to, hence the default.
Source§

fn active_key_id(&self) -> String

A short, stable label for the key seal is using, so an operator can confirm which key a replica actually holds.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more