64 lines
10 KiB
HTML
64 lines
10 KiB
HTML
<!DOCTYPE html><html lang="en"><head><meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1.0"><meta name="generator" content="rustdoc"><meta name="description" content="API documentation for the Rust `sign` mod in crate `openssl`."><meta name="keywords" content="rust, rustlang, rust-lang, sign"><title>openssl::sign - Rust</title><link rel="stylesheet" type="text/css" href="../../normalize.css"><link rel="stylesheet" type="text/css" href="../../rustdoc.css" id="mainThemeStyle"><link rel="stylesheet" type="text/css" href="../../light.css" id="themeStyle"><link rel="stylesheet" type="text/css" href="../../dark.css" disabled ><link rel="stylesheet" type="text/css" href="../../ayu.css" disabled ><script id="default-settings"></script><script src="../../storage.js"></script><noscript><link rel="stylesheet" href="../../noscript.css"></noscript><link rel="icon" type="image/svg+xml" href="../../favicon.svg">
|
||
<link rel="alternate icon" type="image/png" href="../../favicon-16x16.png">
|
||
<link rel="alternate icon" type="image/png" href="../../favicon-32x32.png"><style type="text/css">#crate-search{background-image:url("../../down-arrow.svg");}</style></head><body class="rustdoc mod"><!--[if lte IE 8]><div class="warning">This old browser is unsupported and will most likely display funky things.</div><![endif]--><nav class="sidebar"><div class="sidebar-menu">☰</div><a href='../../openssl/index.html'><div class='logo-container rust-logo'><img src='../../rust-logo.png' alt='logo'></div></a><p class="location">Module sign</p><div class="sidebar-elems"><div class="block items"><ul><li><a href="#structs">Structs</a></li></ul></div><p class="location"><a href="../index.html">openssl</a></p><div id="sidebar-vars" data-name="sign" data-ty="mod" data-relpath="../"></div><script defer src="../sidebar-items.js"></script></div></nav><div class="theme-picker"><button id="theme-picker" aria-label="Pick another theme!" aria-haspopup="menu"><img src="../../brush.svg" width="18" alt="Pick another theme!"></button><div id="theme-choices" role="menu"></div></div><script src="../../theme.js"></script><nav class="sub"><form class="search-form"><div class="search-container"><div><select id="crate-search"><option value="All crates">All crates</option></select><input class="search-input" name="search" disabled autocomplete="off" spellcheck="false" placeholder="Click or press ‘S’ to search, ‘?’ for more options…" type="search"></div><button type="button" class="help-button">?</button>
|
||
<a id="settings-menu" href="../../settings.html"><img src="../../wheel.svg" width="18" alt="Change settings"></a></div></form></nav><section id="main" class="content"><h1 class="fqn"><span class="in-band">Module <a href="../index.html">openssl</a>::<wbr><a class="mod" href="">sign</a></span><span class="out-of-band"><span id="render-detail"><a id="toggle-all-docs" href="javascript:void(0)" title="collapse all docs">[<span class="inner">−</span>]</a></span><a class="srclink" href="../../src/openssl/sign.rs.html#1-872" title="goto source code">[src]</a></span></h1><div class="docblock"><p>Message signatures.</p>
|
||
<p>The <code>Signer</code> allows for the computation of cryptographic signatures of
|
||
data given a private key. The <code>Verifier</code> can then be used with the
|
||
corresponding public key to verify the integrity and authenticity of that
|
||
data given the signature.</p>
|
||
<h1 id="examples" class="section-header"><a href="#examples">Examples</a></h1>
|
||
<p>Sign and verify data given an RSA keypair:</p>
|
||
|
||
<div class="example-wrap"><pre class="rust rust-example-rendered">
|
||
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">sign</span>::{<span class="ident">Signer</span>, <span class="ident">Verifier</span>};
|
||
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">rsa</span>::<span class="ident">Rsa</span>;
|
||
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">pkey</span>::<span class="ident">PKey</span>;
|
||
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">hash</span>::<span class="ident">MessageDigest</span>;
|
||
|
||
<span class="comment">// Generate a keypair</span>
|
||
<span class="kw">let</span> <span class="ident">keypair</span> <span class="op">=</span> <span class="ident">Rsa</span>::<span class="ident">generate</span>(<span class="number">2048</span>).<span class="ident">unwrap</span>();
|
||
<span class="kw">let</span> <span class="ident">keypair</span> <span class="op">=</span> <span class="ident">PKey</span>::<span class="ident">from_rsa</span>(<span class="ident">keypair</span>).<span class="ident">unwrap</span>();
|
||
|
||
<span class="kw">let</span> <span class="ident">data</span> <span class="op">=</span> <span class="string">b"hello, world!"</span>;
|
||
<span class="kw">let</span> <span class="ident">data2</span> <span class="op">=</span> <span class="string">b"hola, mundo!"</span>;
|
||
|
||
<span class="comment">// Sign the data</span>
|
||
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">signer</span> <span class="op">=</span> <span class="ident">Signer</span>::<span class="ident">new</span>(<span class="ident">MessageDigest</span>::<span class="ident">sha256</span>(), <span class="kw-2">&</span><span class="ident">keypair</span>).<span class="ident">unwrap</span>();
|
||
<span class="ident">signer</span>.<span class="ident">update</span>(<span class="ident">data</span>).<span class="ident">unwrap</span>();
|
||
<span class="ident">signer</span>.<span class="ident">update</span>(<span class="ident">data2</span>).<span class="ident">unwrap</span>();
|
||
<span class="kw">let</span> <span class="ident">signature</span> <span class="op">=</span> <span class="ident">signer</span>.<span class="ident">sign_to_vec</span>().<span class="ident">unwrap</span>();
|
||
|
||
<span class="comment">// Verify the data</span>
|
||
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">verifier</span> <span class="op">=</span> <span class="ident">Verifier</span>::<span class="ident">new</span>(<span class="ident">MessageDigest</span>::<span class="ident">sha256</span>(), <span class="kw-2">&</span><span class="ident">keypair</span>).<span class="ident">unwrap</span>();
|
||
<span class="ident">verifier</span>.<span class="ident">update</span>(<span class="ident">data</span>).<span class="ident">unwrap</span>();
|
||
<span class="ident">verifier</span>.<span class="ident">update</span>(<span class="ident">data2</span>).<span class="ident">unwrap</span>();
|
||
<span class="macro">assert</span><span class="macro">!</span>(<span class="ident">verifier</span>.<span class="ident">verify</span>(<span class="kw-2">&</span><span class="ident">signature</span>).<span class="ident">unwrap</span>());</pre></div>
|
||
<p>Compute an HMAC:</p>
|
||
|
||
<div class="example-wrap"><pre class="rust rust-example-rendered">
|
||
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">hash</span>::<span class="ident">MessageDigest</span>;
|
||
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">memcmp</span>;
|
||
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">pkey</span>::<span class="ident">PKey</span>;
|
||
<span class="kw">use</span> <span class="ident">openssl</span>::<span class="ident">sign</span>::<span class="ident">Signer</span>;
|
||
|
||
<span class="comment">// Create a PKey</span>
|
||
<span class="kw">let</span> <span class="ident">key</span> <span class="op">=</span> <span class="ident">PKey</span>::<span class="ident">hmac</span>(<span class="string">b"my secret"</span>).<span class="ident">unwrap</span>();
|
||
|
||
<span class="kw">let</span> <span class="ident">data</span> <span class="op">=</span> <span class="string">b"hello, world!"</span>;
|
||
<span class="kw">let</span> <span class="ident">data2</span> <span class="op">=</span> <span class="string">b"hola, mundo!"</span>;
|
||
|
||
<span class="comment">// Compute the HMAC</span>
|
||
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">signer</span> <span class="op">=</span> <span class="ident">Signer</span>::<span class="ident">new</span>(<span class="ident">MessageDigest</span>::<span class="ident">sha256</span>(), <span class="kw-2">&</span><span class="ident">key</span>).<span class="ident">unwrap</span>();
|
||
<span class="ident">signer</span>.<span class="ident">update</span>(<span class="ident">data</span>).<span class="ident">unwrap</span>();
|
||
<span class="ident">signer</span>.<span class="ident">update</span>(<span class="ident">data2</span>).<span class="ident">unwrap</span>();
|
||
<span class="kw">let</span> <span class="ident">hmac</span> <span class="op">=</span> <span class="ident">signer</span>.<span class="ident">sign_to_vec</span>().<span class="ident">unwrap</span>();
|
||
|
||
<span class="comment">// `Verifier` cannot be used with HMACs; use the `memcmp::eq` function instead</span>
|
||
<span class="comment">//</span>
|
||
<span class="comment">// Do not simply check for equality with `==`!</span>
|
||
<span class="macro">assert</span><span class="macro">!</span>(<span class="ident">memcmp</span>::<span class="ident">eq</span>(<span class="kw-2">&</span><span class="ident">hmac</span>, <span class="kw-2">&</span><span class="ident">target</span>));</pre></div>
|
||
</div><h2 id="structs" class="section-header"><a href="#structs">Structs</a></h2>
|
||
<table><tr class="module-item"><td><a class="struct" href="struct.RsaPssSaltlen.html" title="openssl::sign::RsaPssSaltlen struct">RsaPssSaltlen</a></td><td class="docblock-short"><p>Salt lengths that must be used with <code>set_rsa_pss_saltlen</code>.</p>
|
||
</td></tr><tr class="module-item"><td><a class="struct" href="struct.Signer.html" title="openssl::sign::Signer struct">Signer</a></td><td class="docblock-short"><p>A type which computes cryptographic signatures of data.</p>
|
||
</td></tr><tr class="module-item"><td><a class="struct" href="struct.Verifier.html" title="openssl::sign::Verifier struct">Verifier</a></td><td class="docblock-short"></td></tr></table></section><section id="search" class="content hidden"></section><section class="footer"></section><div id="rustdoc-vars" data-root-path="../../" data-current-crate="openssl"></div>
|
||
<script src="../../main.js"></script><script defer src="../../search-index.js"></script></body></html> |