pub struct Mac(/* private fields */);Expand description
A mac.mac-key: a message-authentication-code key, bound to one
algorithm at creation.
Implementations§
Source§impl Mac
impl Mac
Sourcepub async fn sign(
&self,
data: impl Into<DataSource<'_>>,
) -> Result<Vec<u8>, Error>
pub async fn sign( &self, data: impl Into<DataSource<'_>>, ) -> Result<Vec<u8>, Error>
Compute the authentication tag over data.
Fails only for operational reasons (Error::Other, or
Error::Read for a failing DataSource::from_reader source) —
never for misuse, which is unrepresentable.
Sourcepub async fn verify(
&self,
data: impl Into<DataSource<'_>>,
tag: impl Into<Cow<'_, [u8]>>,
) -> Result<(), Error>
pub async fn verify( &self, data: impl Into<DataSource<'_>>, tag: impl Into<Cow<'_, [u8]>>, ) -> Result<(), Error>
Verify tag over data, in constant time.
Fails closed with Error::AuthenticationFailed if the tag does not
verify — deliberately a Result rather than a bool: an ignored
boolean fails open, a dropped Result does not.
Sourcepub fn algorithm_name(&self) -> String
pub fn algorithm_name(&self) -> String
The name of the key’s algorithm family, e.g. "HMAC" — WebCrypto’s
KeyAlgorithm.name, spelled as the W3C Web Cryptography API
algorithm registry
spells it.
Sourcepub fn algorithm_hash(&self) -> Option<String>
pub fn algorithm_hash(&self) -> Option<String>
The registry name of the digest the algorithm is parameterized over,
e.g. "SHA-256" for HMAC-SHA-256 (WebCrypto’s
HmacKeyAlgorithm.hash, spelled per the same registry as
algorithm_name). None for MAC algorithms
not built on a digest.
Sourcepub fn algorithm_length(&self) -> u32
pub fn algorithm_length(&self) -> u32
The key length in bits (WebCrypto’s HmacKeyAlgorithm.length: the
length of the key material).
Sourcepub fn extractable(&self) -> bool
pub fn extractable(&self) -> bool
Whether export_key_raw may return the key
material.
Asking is not the same as exporting: interrogating extractability
through export_key_raw alone would hand you the
material whenever the answer is yes.
Sourcepub fn can_sign(&self) -> bool
pub fn can_sign(&self) -> bool
Whether the key permits sign — the usage recorded
at mint. A refused operation fails Error::NotPermitted.
Sourcepub fn can_verify(&self) -> bool
pub fn can_verify(&self) -> bool
Sourcepub async fn export_key_raw(&self) -> Result<Vec<u8>, Error>
pub async fn export_key_raw(&self) -> Result<Vec<u8>, Error>
The raw key material; fails with Error::NotExtractable unless the
key was minted extractable. Extractability is an API property, not a
physical one: the guarantee is that components holding only the
handle cannot obtain the material through this API.
Sourcepub async fn export_key_jwk(&self) -> Result<String, Error>
pub async fn export_key_jwk(&self) -> Result<String, Error>
The key as an RFC 7517 oct JSON Web Key (JSON text), behind the
same extractability gate as export_key_raw.
Sourcepub async fn to_wrap_input_raw(&self) -> Result<WrapInput, Error>
pub async fn to_wrap_input_raw(&self) -> Result<WrapInput, Error>
This key’s raw material as a WrapInput, behind the same
extractability gate as export_key_raw.