moonbitstack/mooncrypt/rsa does not have a README file

    Digest

    pub(all) enum Digest {
    Sha1
    Sha224
    Sha256
    Sha384
    Sha512
    } derive(Eq,
    Debug
    )

    Which digest a signature is taken over.

    PKCS#1 v1.5 embeds an ASN.1 algorithm identifier in the block it signs, so the scheme cannot be written over an arbitrary hash the way HMAC can: only a digest with a registered identifier is signable. That constraint is this enum.

    Digest::equal

    fn Digest::equal(Digest, Digest) -> Bool

    Digest::not_equal

    fn Digest::not_equal(x : Digest, y : Digest) -> Bool

    Digest::to_repr

    PrivateKey

    type PrivateKey

    An RSA signing key: modulus, public exponent and private exponent.

    The CRT factors speed signing up fourfold and are not carried, because a key read from its three numbers is the shape every JWK and every hand-written test gives — and because a CRT implementation without fault countermeasures leaks the factorisation to a single bit-flip.

    PrivateKey::decrypt

    fn PrivateKey::decrypt(self : PrivateKey, cipher : BytesView, digest? : Digest, mgf? : Digest, label? : BytesView) -> Bytes raise
    Broken

    Decrypt an RSAES-OAEP block (RFC 8017 §7.1.2).

    Every way the block can be wrong reports the same [@spec.Tag], and the checks all run before any of them is acted on: which check failed is exactly what Manger's 2001 attack reads off, so it is not told apart here.

    digest, mgf and label mean what they do in [PublicKey::encrypt] and must match what encrypted the block.

    PrivateKey::new

    fn PrivateKey::new(modulus : BytesView, exponent : BytesView, private_exponent : BytesView, digest? : Digest, scheme? : Scheme) -> PrivateKey raise
    Broken

    Read a signing key from its modulus and its two exponents, big-endian.

    PrivateKey::public

    fn PrivateKey::public(self : PrivateKey) -> PublicKey

    The public half of a signing key — what verifies what it signs.

    PrivateKey::sign

    fn PrivateKey::sign(self : PrivateKey, msg : BytesView) -> Bytes

    PrivateKey::size

    fn PrivateKey::size(self : PrivateKey) -> Int

    The modulus width in bytes, which is also the signature width.

    PublicKey

    type PublicKey

    An RSA verification key: modulus and public exponent.

    PublicKey::encrypt

    fn PublicKey::encrypt(self : PublicKey, plain : BytesView, seed~ : BytesView, digest? : Digest, mgf? : Digest, label? : BytesView) -> Bytes raise
    Broken

    Encrypt under RSAES-OAEP (RFC 8017 §7.1.1), returning a block exactly as wide as the modulus.

    seed is the hLen random octets OAEP masks with, and it is a required parameter rather than something drawn here: this library holds no entropy source, and the seed is what makes the same message encrypt differently twice. Go's rsa.EncryptOAEP and Rust's rsa crate take the randomness the same way. Reusing a seed across messages destroys OAEP's security — draw it fresh from the platform's CSPRNG for every call.

    digest is the hash OAEP runs, and mgf the one MGF1 masks with; leaving mgf out uses digest, which is what Go and Node do, while Python and Java let the two differ, which is why it is a parameter here.

    digest defaults to SHA-1: it is RFC 8017's own default, and what OpenSSL, Java's OAEPParameterSpec.DEFAULT and Node all take. OAEP does not rest on the hash's collision resistance, so this is not the choice it would be for a signature — but Go and Python require the caller to name it, and a new design should pass digest=Sha256.

    The key's own digest and scheme govern signatures and are not consulted here; encryption and signing are separate schemes over the same key.

    PublicKey::exponent

    fn PublicKey::exponent(self : PublicKey) -> Bytes

    The public exponent, big-endian with no leading zeroes.

    PublicKey::modulus

    fn PublicKey::modulus(self : PublicKey) -> Bytes

    The modulus, big-endian and fixed-width.

    PublicKey::new

    fn PublicKey::new(modulus : BytesView, exponent : BytesView, digest? : Digest, scheme? : Scheme) -> PublicKey raise
    Broken

    Read a verification key from its modulus and exponent, big-endian.

    PublicKey::size

    fn PublicKey::size(self : PublicKey) -> Int

    The modulus width in bytes, which is also the signature width.

    PublicKey::verify

    fn PublicKey::verify(self : PublicKey, msg : BytesView, sig : BytesView) -> Bool

    Scheme

    pub(all) enum Scheme {
    Pkcs1
    Pss(salt~ : Int)
    } derive(Eq,
    Debug
    )

    Which padding a signature uses.

    Pkcs1 is the deterministic block of RFC 8017 §9.2, which JOSE calls RS256 and almost every certificate in existence carries. Pss is the probabilistic scheme of §9.1, which JOSE calls PS256 and which new designs should prefer — its security rests on a proof rather than on the absence of a known attack.

    Scheme::equal

    fn Scheme::equal(Scheme, Scheme) -> Bool

    Scheme::not_equal

    fn Scheme::not_equal(x : Scheme, y : Scheme) -> Bool

    Scheme::to_repr

    Source Files