Skip to main content

classify_encrypted_pin

Function classify_encrypted_pin 

Source
fn classify_encrypted_pin(
    pin_algorithm: Option<SymmetricKeyAlgorithm>,
    pin_key_id: Option<&KeyId>,
    user_key_algorithm: SymmetricKeyAlgorithm,
    user_key_id: &KeyId,
) -> PinMigrationAction
Expand description

Decides what to do with the PIN enrollment, from the algorithms of the encrypted PIN and the user key.

  • A V1 (AES-CBC-HMAC) PIN under a V2 user key is a V1 -> V2 upgrade.
  • Otherwise the PIN must be under the user key itself. A key id, when the PIN carries one, must match; V1 PINs may carry none.