Files
2021-03-26 19:20:48 +00:00

64 lines
10 KiB
HTML
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<!DOCTYPE html><html lang="en"><head><meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1.0"><meta name="generator" content="rustdoc"><meta name="description" content="API documentation for the Rust `sign` mod in crate `openssl`."><meta name="keywords" content="rust, rustlang, rust-lang, sign"><title>openssl::sign - Rust</title><link rel="stylesheet" type="text/css" href="../../normalize.css"><link rel="stylesheet" type="text/css" href="../../rustdoc.css" id="mainThemeStyle"><link rel="stylesheet" type="text/css" href="../../light.css" id="themeStyle"><link rel="stylesheet" type="text/css" href="../../dark.css" disabled ><link rel="stylesheet" type="text/css" href="../../ayu.css" disabled ><script id="default-settings"></script><script src="../../storage.js"></script><noscript><link rel="stylesheet" href="../../noscript.css"></noscript><link rel="icon" type="image/svg+xml" href="../../favicon.svg">
<link rel="alternate icon" type="image/png" href="../../favicon-16x16.png">
<link rel="alternate icon" type="image/png" href="../../favicon-32x32.png"><style type="text/css">#crate-search{background-image:url("../../down-arrow.svg");}</style></head><body class="rustdoc mod"><!--[if lte IE 8]><div class="warning">This old browser is unsupported and will most likely display funky things.</div><![endif]--><nav class="sidebar"><div class="sidebar-menu">&#9776;</div><a href='../../openssl/index.html'><div class='logo-container rust-logo'><img src='../../rust-logo.png' alt='logo'></div></a><p class="location">Module sign</p><div class="sidebar-elems"><div class="block items"><ul><li><a href="#structs">Structs</a></li></ul></div><p class="location"><a href="../index.html">openssl</a></p><div id="sidebar-vars" data-name="sign" data-ty="mod" data-relpath="../"></div><script defer src="../sidebar-items.js"></script></div></nav><div class="theme-picker"><button id="theme-picker" aria-label="Pick another theme!" aria-haspopup="menu"><img src="../../brush.svg" width="18" alt="Pick another theme!"></button><div id="theme-choices" role="menu"></div></div><script src="../../theme.js"></script><nav class="sub"><form class="search-form"><div class="search-container"><div><select id="crate-search"><option value="All crates">All crates</option></select><input class="search-input" name="search" disabled autocomplete="off" spellcheck="false" placeholder="Click or press S to search, ? for more options…" type="search"></div><button type="button" class="help-button">?</button>
<a id="settings-menu" href="../../settings.html"><img src="../../wheel.svg" width="18" alt="Change settings"></a></div></form></nav><section id="main" class="content"><h1 class="fqn"><span class="in-band">Module <a href="../index.html">openssl</a>::<wbr><a class="mod" href="">sign</a></span><span class="out-of-band"><span id="render-detail"><a id="toggle-all-docs" href="javascript:void(0)" title="collapse all docs">[<span class="inner">&#x2212;</span>]</a></span><a class="srclink" href="../../src/openssl/sign.rs.html#1-872" title="goto source code">[src]</a></span></h1><div class="docblock"><p>Message signatures.</p>
<p>The <code>Signer</code> allows for the computation of cryptographic signatures of
data given a private key. The <code>Verifier</code> can then be used with the
corresponding public key to verify the integrity and authenticity of that
data given the signature.</p>
<h1 id="examples" class="section-header"><a href="#examples">Examples</a></h1>
<p>Sign and verify data given an RSA keypair:</p>
<div class="example-wrap"><pre class="rust rust-example-rendered">
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">sign</span>::{<span class="ident">Signer</span>, <span class="ident">Verifier</span>};
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">rsa</span>::<span class="ident">Rsa</span>;
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">pkey</span>::<span class="ident">PKey</span>;
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">hash</span>::<span class="ident">MessageDigest</span>;
<span class="comment">// Generate a keypair</span>
<span class="kw">let</span> <span class="ident">keypair</span> <span class="op">=</span> <span class="ident">Rsa</span>::<span class="ident">generate</span>(<span class="number">2048</span>).<span class="ident">unwrap</span>();
<span class="kw">let</span> <span class="ident">keypair</span> <span class="op">=</span> <span class="ident">PKey</span>::<span class="ident">from_rsa</span>(<span class="ident">keypair</span>).<span class="ident">unwrap</span>();
<span class="kw">let</span> <span class="ident">data</span> <span class="op">=</span> <span class="string">b&quot;hello, world!&quot;</span>;
<span class="kw">let</span> <span class="ident">data2</span> <span class="op">=</span> <span class="string">b&quot;hola, mundo!&quot;</span>;
<span class="comment">// Sign the data</span>
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">signer</span> <span class="op">=</span> <span class="ident">Signer</span>::<span class="ident">new</span>(<span class="ident">MessageDigest</span>::<span class="ident">sha256</span>(), <span class="kw-2">&amp;</span><span class="ident">keypair</span>).<span class="ident">unwrap</span>();
<span class="ident">signer</span>.<span class="ident">update</span>(<span class="ident">data</span>).<span class="ident">unwrap</span>();
<span class="ident">signer</span>.<span class="ident">update</span>(<span class="ident">data2</span>).<span class="ident">unwrap</span>();
<span class="kw">let</span> <span class="ident">signature</span> <span class="op">=</span> <span class="ident">signer</span>.<span class="ident">sign_to_vec</span>().<span class="ident">unwrap</span>();
<span class="comment">// Verify the data</span>
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">verifier</span> <span class="op">=</span> <span class="ident">Verifier</span>::<span class="ident">new</span>(<span class="ident">MessageDigest</span>::<span class="ident">sha256</span>(), <span class="kw-2">&amp;</span><span class="ident">keypair</span>).<span class="ident">unwrap</span>();
<span class="ident">verifier</span>.<span class="ident">update</span>(<span class="ident">data</span>).<span class="ident">unwrap</span>();
<span class="ident">verifier</span>.<span class="ident">update</span>(<span class="ident">data2</span>).<span class="ident">unwrap</span>();
<span class="macro">assert</span><span class="macro">!</span>(<span class="ident">verifier</span>.<span class="ident">verify</span>(<span class="kw-2">&amp;</span><span class="ident">signature</span>).<span class="ident">unwrap</span>());</pre></div>
<p>Compute an HMAC:</p>
<div class="example-wrap"><pre class="rust rust-example-rendered">
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">hash</span>::<span class="ident">MessageDigest</span>;
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">memcmp</span>;
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">pkey</span>::<span class="ident">PKey</span>;
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">sign</span>::<span class="ident">Signer</span>;
<span class="comment">// Create a PKey</span>
<span class="kw">let</span> <span class="ident">key</span> <span class="op">=</span> <span class="ident">PKey</span>::<span class="ident">hmac</span>(<span class="string">b&quot;my secret&quot;</span>).<span class="ident">unwrap</span>();
<span class="kw">let</span> <span class="ident">data</span> <span class="op">=</span> <span class="string">b&quot;hello, world!&quot;</span>;
<span class="kw">let</span> <span class="ident">data2</span> <span class="op">=</span> <span class="string">b&quot;hola, mundo!&quot;</span>;
<span class="comment">// Compute the HMAC</span>
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">signer</span> <span class="op">=</span> <span class="ident">Signer</span>::<span class="ident">new</span>(<span class="ident">MessageDigest</span>::<span class="ident">sha256</span>(), <span class="kw-2">&amp;</span><span class="ident">key</span>).<span class="ident">unwrap</span>();
<span class="ident">signer</span>.<span class="ident">update</span>(<span class="ident">data</span>).<span class="ident">unwrap</span>();
<span class="ident">signer</span>.<span class="ident">update</span>(<span class="ident">data2</span>).<span class="ident">unwrap</span>();
<span class="kw">let</span> <span class="ident">hmac</span> <span class="op">=</span> <span class="ident">signer</span>.<span class="ident">sign_to_vec</span>().<span class="ident">unwrap</span>();
<span class="comment">// `Verifier` cannot be used with HMACs; use the `memcmp::eq` function instead</span>
<span class="comment">//</span>
<span class="comment">// Do not simply check for equality with `==`!</span>
<span class="macro">assert</span><span class="macro">!</span>(<span class="ident">memcmp</span>::<span class="ident">eq</span>(<span class="kw-2">&amp;</span><span class="ident">hmac</span>, <span class="kw-2">&amp;</span><span class="ident">target</span>));</pre></div>
</div><h2 id="structs" class="section-header"><a href="#structs">Structs</a></h2>
<table><tr class="module-item"><td><a class="struct" href="struct.RsaPssSaltlen.html" title="openssl::sign::RsaPssSaltlen struct">RsaPssSaltlen</a></td><td class="docblock-short"><p>Salt lengths that must be used with <code>set_rsa_pss_saltlen</code>.</p>
</td></tr><tr class="module-item"><td><a class="struct" href="struct.Signer.html" title="openssl::sign::Signer struct">Signer</a></td><td class="docblock-short"><p>A type which computes cryptographic signatures of data.</p>
</td></tr><tr class="module-item"><td><a class="struct" href="struct.Verifier.html" title="openssl::sign::Verifier struct">Verifier</a></td><td class="docblock-short"></td></tr></table></section><section id="search" class="content hidden"></section><section class="footer"></section><div id="rustdoc-vars" data-root-path="../../" data-current-crate="openssl"></div>
<script src="../../main.js"></script><script defer src="../../search-index.js"></script></body></html>