1# This file is dual licensed under the terms of the Apache License, Version
2# 2.0, and the BSD License. See the LICENSE file in the root of this repository
3# for complete details.
4
5from __future__ import annotations
6
7import abc
8
9from cryptography.exceptions import UnsupportedAlgorithm, _Reasons
10from cryptography.hazmat.bindings._rust import openssl as rust_openssl
11from cryptography.hazmat.primitives import _serialization
12
13
14class X25519PublicKey(metaclass=abc.ABCMeta):
15 @classmethod
16 def from_public_bytes(cls, data: bytes) -> X25519PublicKey:
17 from cryptography.hazmat.backends.openssl.backend import backend
18
19 if not backend.x25519_supported():
20 raise UnsupportedAlgorithm(
21 "X25519 is not supported by this version of OpenSSL.",
22 _Reasons.UNSUPPORTED_EXCHANGE_ALGORITHM,
23 )
24
25 return rust_openssl.x25519.from_public_bytes(data)
26
27 @abc.abstractmethod
28 def public_bytes(
29 self,
30 encoding: _serialization.Encoding,
31 format: _serialization.PublicFormat,
32 ) -> bytes:
33 """
34 The serialized bytes of the public key.
35 """
36
37 @abc.abstractmethod
38 def public_bytes_raw(self) -> bytes:
39 """
40 The raw bytes of the public key.
41 Equivalent to public_bytes(Raw, Raw).
42 """
43
44 @abc.abstractmethod
45 def __eq__(self, other: object) -> bool:
46 """
47 Checks equality.
48 """
49
50
51X25519PublicKey.register(rust_openssl.x25519.X25519PublicKey)
52
53
54class X25519PrivateKey(metaclass=abc.ABCMeta):
55 @classmethod
56 def generate(cls) -> X25519PrivateKey:
57 from cryptography.hazmat.backends.openssl.backend import backend
58
59 if not backend.x25519_supported():
60 raise UnsupportedAlgorithm(
61 "X25519 is not supported by this version of OpenSSL.",
62 _Reasons.UNSUPPORTED_EXCHANGE_ALGORITHM,
63 )
64 return rust_openssl.x25519.generate_key()
65
66 @classmethod
67 def from_private_bytes(cls, data: bytes) -> X25519PrivateKey:
68 from cryptography.hazmat.backends.openssl.backend import backend
69
70 if not backend.x25519_supported():
71 raise UnsupportedAlgorithm(
72 "X25519 is not supported by this version of OpenSSL.",
73 _Reasons.UNSUPPORTED_EXCHANGE_ALGORITHM,
74 )
75
76 return rust_openssl.x25519.from_private_bytes(data)
77
78 @abc.abstractmethod
79 def public_key(self) -> X25519PublicKey:
80 """
81 Returns the public key associated with this private key
82 """
83
84 @abc.abstractmethod
85 def private_bytes(
86 self,
87 encoding: _serialization.Encoding,
88 format: _serialization.PrivateFormat,
89 encryption_algorithm: _serialization.KeySerializationEncryption,
90 ) -> bytes:
91 """
92 The serialized bytes of the private key.
93 """
94
95 @abc.abstractmethod
96 def private_bytes_raw(self) -> bytes:
97 """
98 The raw bytes of the private key.
99 Equivalent to private_bytes(Raw, Raw, NoEncryption()).
100 """
101
102 @abc.abstractmethod
103 def exchange(self, peer_public_key: X25519PublicKey) -> bytes:
104 """
105 Performs a key exchange operation using the provided peer's public key.
106 """
107
108
109X25519PrivateKey.register(rust_openssl.x25519.X25519PrivateKey)