mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
Add interfaces for creating an ML-KEM keypair and encapsulation and decapsulation. The public part of it can be used to encapsulate a shared secret in a ciphertext. The latter can be decapsulated with the private part of the keypair to recover the shared secret. In terms of code, a keypair of type `PKey<Private>` can be generated with `generate_ml_kem` specifying `KeyType::ML_KEM_512`, `KeyType::ML_KEM_768`, or `KeyType::ML_KEM_1024`. To encapsulate a shared secret, generate a `PkeyCtx<Public>` with `PkeyCtx::new`, initialize it with `encapsulate_init`, and encapsulate with `encapsulate_to_vec`. To decapsulate the ciphertext to the shared secret, generate a `PkeyCtx<Private>` with `PkeyCtx::new`, initialize it with `decapsulate_init`, and decapsulate with `decapsulate_to_vec`. Note that when https://github.com/rust-openssl/rust-openssl/pull/2532 is getting merged into `rust-openssl`, these changes will become unnecessary. Assisted-by: IBM Bob:1.0.4 Reviewed-by: Marc Hartmayer <marc@linux.ibm.com> Acked-by: Steffen Eiden <seiden@linux.ibm.com> Signed-off-by: Timo Keller <tkeller@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
s390_pv - library for pv-tools
This library is intended to be used by tools and libraries that
are used for creating and managing IBM Secure Execution guests.
pv provides abstraction layers for encryption, secure memory management,
and accessing the uvdevice.
If your project is not targeted to provide tooling for and/or managing of IBM Secure execution guests, do not use this crate.
OpenSSL 1.1.0+ is required
If you do not need any OpenSSL features use s390_pv_core.
This crate reexports all symbols from s390_pv_core. If your project uses this crate do not include s390_pv_core as well.
Import crate
The recommended way of importing this crate is:
cargo add s390_pv --rename pv