Expand description
Server-side key generation for EST /serverkeygen (RFC 7030 §4.4).
Generates key pairs in software or via PKCS#11 HSM per NIAP CA PP FCS_CKM.1 (approved key generation methods). Supports RSA and ECDSA key types with configurable sizes.
Structs§
- KeyGen
Config - Configuration for key generation.
- KeyGen
Result - Result of a key generation operation.
Enums§
- Classical
Signing Alg - Classical signing algorithms paired with ML-DSA in composite mode.
- EcCurve
- Supported elliptic curves for ECDSA.
- KeyGen
Error - Errors during key generation.
- KeyType
- Supported key types for server-side generation.
- MlDsa
Level - ML-DSA security levels per FIPS 204.
- MlKem
Level - ML-KEM security levels per FIPS 203.
Functions§
- composite_
sub_ arc - Map a composite ML-DSA key type to the OID sub-arc per draft-ietf-lamps-pq-composite-sigs-19 (sub-arcs 37-54).
- generate_
key_ pair - Generate a key pair for the EST
/serverkeygenendpoint.