summaryrefslogtreecommitdiff
path: root/crates/tor-llcrypto/src/pk
Commit message (Collapse)AuthorAgeFilesLines
* tor-llcrypto: key blinding: Use consistent terminologyIan Jackson2023-03-281-19/+22
| | | | | | | | | | | | | | | | | | | | Unhelpfully, the spec uses the variable name `h` and the phrase "blinding factor" for both the unclamped and clamped value. The clamped value is internal to the algorithm. In our code: * Don't ever use the word "parameter" or variable name `param`. This doesn't appear in the spec anywhere. * Use `h` for the unclamped blinding factor, and `blinding_factor` for the clamped blinding factor. * Rename `blinding_factor` function to `clamp_blinding_factor`, since in the spec's terminology it takes an (unclamped) "blinding factor" and returns a (clamped) "blinding factor". * State explicitly what thing in the spec the `h` parameters are.
* Use the type system to enforce use of blinded keys.Gabriela Moldovan2023-03-271-0/+12
| | | | | | | | | | | | | | | Hidden services use blinded singing keys derived from the identity key to sign descriptor signing keys. Before this patch, the hidden descriptor builder represented its blinded signing keys (`blinded_id`) as plain `ed25519::Keypair`s. This was not ideal, as there was nothing preventing the caller from accidentally initializing `blinded_id` with an unblinded keypair. This introduces a new `HsBlindKeypair` type to represent blinded keypairs. Signed-off-by: Gabriela Moldovan <[email protected]>
* Expose a little new functionality from tor-llcrypto.Nick Mathewson2023-02-281-0/+9
| | | | | Expose ED25519 signature length; make ValidatableEd25519Signature implement Debug and Clone.
* llcrypto: Implement `Into<[u8;32]>` for Ed25519IdentityNick Mathewson2023-02-071-0/+6
|
* tor-llcrypto: Tolerate some warnings (fmt)Ian Jackson2023-01-201-1/+4
|
* tor-llcrypto: Tolerate some warningsIan Jackson2023-01-201-0/+4
| | | | | | Without this, cargo +stable clippy -p tor-netdoc --all-features produces warnings.
* Upgrade to latest rsa crate.Nick Mathewson2023-01-201-1/+1
|
* Complete our migration to base64ct.Nick Mathewson2023-01-201-12/+5
| | | | | | | | | This is in lieu of upgrading to the latest base64 crate, which has a different API from the old one. Since we have to migrate either way, we might as well use base64ct everywhere. I don't think that most of these cases _require_ constant-time base64, but it won't hurt.
* Merge branch 'blind_privkey' into 'main'Ian Jackson2023-01-091-17/+159
|\ | | | | | | | | | | | | llcrypto: Implement secret-key blinding. Closes #719 See merge request tpo/core/arti!964
| * llcrypto: Implement secret-key blinding.Nick Mathewson2023-01-061-17/+159
| | | | | | | | | | | | | | | | Closes #719. Due to a difference between ed25519-dalek and ed25519-donna, converting these secret keys directly to public keys does not work. I've documented this in a "Limitations" section.
* | llcrypto: fix a comment.Nick Mathewson2023-01-061-1/+1
| | | | | | | | This described the wrong type of key.
* | llcrypto: clarify meaning of "Identity".Nick Mathewson2023-01-062-8/+17
| | | | | | | | | | | | | | | | | | | | The `Ed25519Identity` and `RsaIdentity` types are not precisely always used as relay identifiers: they are more generally used as _key_ identifiers. This will become relevant as `RsaIdentity` is used for authority keys (as in authorities' VoterInfo blocks), and as `Ed25519Identity` is used as the identifier behind an onion service key.
* | Add a new "CtByteArray" type, and use it in Id types.Nick Mathewson2023-01-052-39/+28
|/ | | | | | This type provides a common implementation for types that are implemented as arrays of bytes that should only be compared with constant-time comparisons.
* llcrypto: Make key id types Redactable.Nick Mathewson2022-11-282-0/+28
|
* Fix a bunch of "needless borrow" warnings on nightlyNick Mathewson2022-11-181-1/+1
| | | | | It looks like, despite a few false starts, they've got this warning right; there weren't any false positives.
* Upgrade rsa to 0.7. Closes #613.Nick Mathewson2022-11-101-1/+1
|
* Add a new constant-time is_zero() check for RsaIdentityNick Mathewson2022-09-201-0/+11
| | | | | | | | | | | | | There are some places in the protocol where we have an all-zero RSA identity that does not truly represent a key, but rather represents an absent or unknown key. For these, it's better to use `RsaIdentity::is_zero` instead of manually checking for a set of zero bytes: it expresses the intent better, and ensures that the operation is constant-time. I am deliberately not introducing a more general IsZero trait here, or implementing is_zero for anything else: This is the only one we seem to need right now. We can generalize it later if we have to.
* Merge branch 'main' into 'linkspec_refactor_v3'Nick Mathewson2022-08-101-2/+1
|\ | | | | | | # Conflicts: # crates/tor-netdir/semver.md
| * Stop deriving Zeroize for RsaIdentity.Nick Mathewson2022-08-011-2/+1
| | | | | | | | These are not secret.
* | Define a constant for ED25519 identity length.Nick Mathewson2022-08-101-3/+6
|/
* Merge branch 'generate_cert' into 'main'Nick Mathewson2022-07-081-1/+1
|\ | | | | | | | | | | | | Implement functionality to construct signed Ed25519 certs. Closes #511 See merge request tpo/core/arti!611
| * tor-llcrypto: expose the Signer API from ed25519-dalekNick Mathewson2022-07-061-1/+1
| |
* | Update `rsa` dependency (and use `x25519-dalek` prerelease)eta2022-07-061-1/+1
|/ | | | | | | | | | | | | | - arti#448 and arti!607 highlight an issue with upgrading `rsa`: namely, the `x25519-dalek` version previously used has a hard dependency on `zeroize` 1.3, which creates a dependency conflict. - However, `x25519-dalek` version `2.0.0-pre.1` relaxes this dependency. Reviewing the changelogs, it doesn't look like that version is substantially different from the current one at all, so it should be safe to use despite the "prerelease" tag. - The new `x25519-dalek` version also bumps `rand_core`, which means we don't have to use the RNG compat wrapper in `tor-llcrypto` as much. closes arti#448
* Merge remote-tracking branch 'origin/mr/610'Nick Mathewson2022-07-051-1/+1
|\
| * Fixed typo in convert_curve25519_to_ed25519_private commentsRichard Pospesel2022-06-291-1/+1
| |
* | tor-llcrypto: style fixes on BlindingErrorNick Mathewson2022-06-221-2/+2
| |
* | Use testing_rng() in tests throughout our crates.Nick Mathewson2022-06-021-2/+2
| | | | | | | | | | | | This only affects uses of thread_rng(), and affects them all more or less indiscriminately. One test does not work with ARTI_TEST_PRNG=deterministic; the next commit will fix it.
* | squash! Bump every crate's edition to 2021.Nick Mathewson2022-04-252-4/+0
| | | | | | | | | | Remove all `use` statements for `TryFrom` and `TryInto`. These are now redundant in Rust 2021.
* | Implement Ord for Ed25519Identity.Nick Mathewson2022-03-301-1/+1
| |
* | Add a from_hex method for RsaIdentity.Nick Mathewson2022-03-041-3/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | We perform this operation in a bunch of places, and most of them use hex::decode(). That's not great, since hex::decode() has to do heap allocation. This implementation uses hex::decode_to_slice(), which should be faster. (In the future we might choose to use one of the faster hex implementations, but I'm hoping that this change will be sufficient to get hex decoding out of our profiles.) Part of #377.
* | tor-llcrypto: Replace a tiny bit of code duplication with a callIan Jackson2022-03-021-1/+1
| | | | | | | | No functional change.
* | Remove a XXXX comment in tor-llcrypto.Nick Mathewson2021-12-081-1/+0
| | | | | | | | | | This comment was about an unspecified string; the issue of specifying the string is now torspec!55.
* | Upgrade to digest v0.10.0Nick Mathewson2021-12-071-2/+2
| | | | | | | | | | We generally try to track the latest rust-crypto traits when we can: fortunately, this upgrade didn't break much, considering.
* | Resolve roughly half of the XXXXs.Nick Mathewson2021-12-061-4/+3
| | | | | | | | | | | | | | | | We want to only use TODO in the codebase for non-blockers, and open tickets for anything that is a bigger blocker than a TODO. These XXXXs seem like definite non-blockers to me. Part of arti#231.
* | Fix a few typos.Nick Mathewson2021-11-241-1/+1
| | | | | | | | Also fix some commonwealth spellings that had slipped in.
* | tor-llcrypto: Put currently unused functions behind features.Nick Mathewson2021-11-121-7/+18
| | | | | | | | | | | | | | | | We don't currently need a couple of the key manipulation features that we have, since we aren't yet doing relays or onion service clients. Part of #125
* | Improve some documentation linksNick Mathewson2021-10-291-2/+2
|/ | | | | | | | | Instead of putting a fully qualified name in the text, in most cases we should just use the short name of the type or function we're referring to. In other words, instead of saying [`crate::module::Foo`], we should typically say [`Foo`](crate::module::Foo).
* Implement ConstantTimeEq for key ids.Nick Mathewson2021-10-012-4/+16
|
* fix/silence clippy lints in test modulesDaniel Eades2021-09-081-0/+1
|
* Move all crates into a `crates` subdirectory.Nick Mathewson2021-08-273-0/+787
This will cause some pain for now, but now is really the best time to do this kind of thing.