sql.mysql.ed25519
import sql.mysql.ed25519
sqldoes not re-export this module, so it is reached only by importing it directly.
Ed25519 signing over a key derived from a password, which is what
MariaDB’s client_ed25519 authentication is built on.
Why this is not crypto.ed25519
An ordinary Ed25519 private key is a 32 byte seed, and signing begins by hashing that seed into the 64 bytes the signature is actually computed from. MariaDB skips the seed: it hashes the password into those 64 bytes directly, so the user’s password takes the place of the expanded key rather than the place of the seed.
Nothing in crypto.ed25519 can express that, since it takes a
PEM-encoded key and does its own expansion internally. So the curve
arithmetic lives here, where the one thing that needs it is.
Correctness
Everything below the password derivation is Ed25519 exactly as RFC 8032
specifies it, and is checked against that document’s test vectors and
against crypto.ed25519 over random keys.
Constants
P
sql.mysql.ed25519.P
The field prime, 2^255 - 19.
L
sql.mysql.ed25519.L
The order of the base point’s subgroup.
D
sql.mysql.ed25519.D
The curve constant, -121665/121666.
D2
sql.mysql.ed25519.D2
Twice the curve constant, which is what the addition uses.
Functions
password_key()
sql.mysql.ed25519.password_key(password: string) -> bytes
Expands a password into the 64 bytes MariaDB signs with.
Parameters
password(string)
Returns bytes
public_key()
sql.mysql.ed25519.public_key(expanded) -> bytes
The public key matching an expanded key.
Parameters
expanded(bytes) — The 64 bytes frompassword_key().
Returns bytes — The 32 byte encoded public key.
sign()
sql.mysql.ed25519.sign(expanded, message) -> bytes
Signs message with an expanded key.
Parameters
expanded(bytes) — The 64 bytes frompassword_key().message(bytes)
Returns bytes — The 64 byte signature.
2026, Richard Ore and Zuri contributors