pub struct SecretKey { /* private fields */ }Expand description
A secret key. agree is one-shot on the immutable key; the
derivation state lives in the derive-input it returns.
Implementations§
Source§impl SecretKey
impl SecretKey
Sourcepub async fn agree(&self, peer: &PublicKey) -> Result<DeriveInput, Error>
pub async fn agree(&self, peer: &PublicKey) -> Result<DeriveInput, Error>
The shared secret with peer, as a derive-input whose grants
are copied from this key’s mint options (the Web Cryptography
API’s model: derive usages live on the secret key).
The returned input has a natural output length — the
agreement’s full shared secret (32 bytes for X25519; the
curve’s field size for ECDH) — so derive-bits(none) returns
the whole secret and hkdf-sha2.prepare-from accepts it as
IKM.
Security:
- Fails
error.invalid-keyif the shared secret is the all-zero value (a small-orderpeer), checked in constant time — the W3C Web Cryptography API’s mandatory contributory check, at the operation that computes the secret. Whether a degenerate peer can reach this check is the minting interface’s import contract: X25519’s deliberately permissive import admits one, and it surfaces here; ECDH’s strict import rejects it at the mint. - Fails
error.invalid-keyifpeeris bound to a different algorithm than this key.
Source§impl SecretKey
impl SecretKey
Sourcepub fn can_derive_bits(&self) -> bool
pub fn can_derive_bits(&self) -> bool
Whether inputs agreed by this key may yield raw bits. See
agreement-key-options.can-derive-bits.
Source§impl SecretKey
impl SecretKey
Sourcepub fn can_derive_key(&self) -> bool
pub fn can_derive_key(&self) -> bool
Whether inputs agreed by this key may mint keys. See
agreement-key-options.can-derive-key.
Source§impl SecretKey
impl SecretKey
Sourcepub fn extractable(&self) -> bool
pub fn extractable(&self) -> bool
Whether the export functions may return this key’s material.
See agreement-key-options.extractable.
Source§impl SecretKey
impl SecretKey
Sourcepub async fn export_key_jwk(&self) -> Result<String, Error>
pub async fn export_key_jwk(&self) -> Result<String, Error>
The secret key as an RFC 8037 OKP private JWK. Fails
error.not-extractable unless the key was minted extractable;
fallible beyond the gate like every export (README.md,
“Extractability”).
Source§impl SecretKey
impl SecretKey
Sourcepub async fn to_wrap_input_jwk(&self) -> Result<WrapInput, Error>
pub async fn to_wrap_input_jwk(&self) -> Result<WrapInput, Error>
The private-key JWK serialization as a wrap-input, for
wrapping under another key (see the wrapping interface).
Behind the same extractability gate as export-key-jwk, and
fallible beyond it like every export; the material itself
never reaches the caller.