* Move `KeGroup` to `KeyExchange::Group`
- Introduce `KeyExchange::Hash`, which separates the OPRF hash from the one used in `KeyExchange`.
- Remove `De/Serialize` requirement on key exchange messages and states, which forced a lot of where bounds on downstream users.
- Rename `KeGroup` to `Group`.
- Replace `D` generic for hash with `H`.
* Use `voprf::derive_key()` directly
* Implement SIGMA-I key exchange
* Improve `KeyExchange` for SIGMA-I and Ed25519
* Implement EdDSA
* Un-qualify some method calls
* SIGMA-I: only include client identity in client mac
* SIGMA-I: include server mac in client signature
* Expose key exchange types in `crate` & move modules
* Implement Ed25519ph
* Document `ed25519` crate feature
* Remove `ristretto255-voprf` crate feature
* Adjust CI crate feature testing
* Fix Rustdoc
* Remove unnecessary generic parameters from SIGMA-I
* Properly mark to-do's with TODO
* Assorted fixes
* SIGMA-I: include context in signature
* SIGMA-I: include identifiers in signature
* Merge `ServerLoginStart/FinishParameters`
* Re-export more necessary types
* More carefully expose types
* Add ECDSA test
* SIGMA-I: share context hashing
* De-duplicate client static public key storage
* Hide `KeyExchange` better
* Use the correct hash in the root documentation
* Bump `derive-where`
* Format documentation examples a bit further
* Add remote OPRF seed documentation
* Rename `deserialize_key_pair` to `deserialize_take_key_pair`
* Add more key tests
* Remove `SharedSecret` trait
* SIGMA-I refactor message API
* Share more implementation between 3DH and SIGMA-I
* Remove unnecessary zero scalar check for Curve25519
* Use correct hash in test
* Add some more TODOs
* Exclude `tests` folder from Cargo publishing
* Enable missing dependencies
* Use right crate for testing Ed25519
* Remove unnecessary `Sized` constraints
* Remove unnecessary `ecdsa` crate features
* Move signature de/serialization to trait methods
* Nit: move import to appropriate location
* Add warning to SIGMA-I
This tweaks the documentation on the main module, in order to
add some details on the outcome of the client login final step.
In particular, it clarifies the result of `ClientLogin::finish()`
both on success and on errors and it adds some intra-crate links
to the relevant structures and fields.
* Curve25519 test vectors
* Adjust `derive_auth_keypair()` for Curve25519
* Update test vectors
* Fix Curve25519 random scalar generation
Co-Authored-By: Kevin Lewi <[email protected]>
* Update test vectors
* Update test vectors
* Update test vectors
---------
Co-authored-by: Kevin Lewi <[email protected]>