pub struct VerifyingKey { /* private fields */ }Expand description
A public key: verification only, secret-free.
Implementations§
Source§impl VerifyingKey
impl VerifyingKey
Sourcepub async fn verify(
&self,
data: StreamReader<u8>,
sig: Vec<u8>,
) -> Result<(), Error>
pub async fn verify( &self, data: StreamReader<u8>, sig: Vec<u8>, ) -> Result<(), Error>
Verify sig over an entire byte stream. Like mac-key.verify,
both verdicts are computed over the entire stream and resolve
only after it is fully drained, and it fails closed with
error.authentication-failed (a result, not a bool: an
ignored boolean fails open).
Security:
- Signature verification is a policy, not a bit-exact predicate: the key’s minting interface defines the precise criterion — which degenerate keys and signatures must be rejected — exactly as it defines the wire format.
Source§impl VerifyingKey
impl VerifyingKey
Sourcepub fn algorithm_name(&self) -> String
pub fn algorithm_name(&self) -> String
The registry name of the algorithm family this key is bound to,
e.g. "Ed25519" or "ECDSA" (WebCrypto’s KeyAlgorithm.name).
Source§impl VerifyingKey
impl VerifyingKey
Sourcepub fn algorithm_curve(&self) -> Option<String>
pub fn algorithm_curve(&self) -> Option<String>
The registry name of the curve for algorithms parameterized by
one, e.g. "P-256" (WebCrypto’s EcKeyAlgorithm.namedCurve).
none for Ed25519, whose curve is implied by the name.
Source§impl VerifyingKey
impl VerifyingKey
Sourcepub fn algorithm_hash(&self) -> Option<String>
pub fn algorithm_hash(&self) -> Option<String>
The digest bound at mint, e.g. "SHA-256". none for Ed25519:
RFC 8032 fixes SHA-512 internally, so it is not a parameter.
Source§impl VerifyingKey
impl VerifyingKey
Sourcepub fn algorithm_length(&self) -> Option<u32>
pub fn algorithm_length(&self) -> Option<u32>
The key’s length in bits for algorithms parameterized by one —
the RSA modulus length (WebCrypto’s
RsaKeyAlgorithm.modulusLength). none for Ed25519 and
ECDSA, whose key size is fixed by the algorithm or curve.
Source§impl VerifyingKey
impl VerifyingKey
Sourcepub fn algorithm_public_exponent(&self) -> Option<Vec<u8>>
pub fn algorithm_public_exponent(&self) -> Option<Vec<u8>>
The public exponent for RSA-family keys, as WebCrypto’s
RsaKeyAlgorithm.publicExponent denominates it: the
exponent’s big-endian bytes ([1, 0, 1] for 65537). none
for algorithms without one (Ed25519, ECDSA).
Source§impl VerifyingKey
impl VerifyingKey
Sourcepub async fn export_key_raw(&self) -> Result<Vec<u8>, Error>
pub async fn export_key_raw(&self) -> Result<Vec<u8>, Error>
The public key material, in the minting interface’s documented
public format. Algorithms without a raw public form (the RSA
family — the platform serves spki and jwk only) fail
error.unsupported.
There is no extractability gate on this resource, so
error.not-extractable never occurs here. Export is still
fallible: a provider may hold the key as a handle it can use
but not read — verifying with it succeeds while recovering
its encoding fails with error.other (see README.md,
“Extractability”).
Source§impl VerifyingKey
impl VerifyingKey
Source§impl VerifyingKey
impl VerifyingKey
Sourcepub async fn export_key_jwk(&self) -> Result<String, Error>
pub async fn export_key_jwk(&self) -> Result<String, Error>
The public key as a JWK (an RFC 8037 OKP public key for
Ed25519, an EC public key for ECDSA). See
mac-key.export-key-jwk for the package-wide JWK contract;
the same fallibility as export-key-raw applies.