pub struct Parameters {
pub kdf: Kdf,
pub encryption: EncryptionScheme,
}Expand description
Password-Based Encryption Scheme 2 parameters as defined in RFC 8018 Appendix A.4.
PBES2-params ::= SEQUENCE {
keyDerivationFunc AlgorithmIdentifier {{PBES2-KDFs}},
encryptionScheme AlgorithmIdentifier {{PBES2-Encs}} }These define a set of algorithms for password-based key derivation, as well as a salt value (typically randomly generated) to provide to the KDF algorithm, along with an encryption algorithm and its associated IV/nonce (typically randomly generated).
This type should not be used to encrypt multiple plaintexts under the same IV/salt values.
Instead, new values should be randomly generated for every usage.
Fields§
§kdf: KdfKey derivation function
encryption: EncryptionSchemeEncryption scheme
Implementations§
Source§impl Parameters
impl Parameters
Sourcepub fn generate_recommended<R: TryCryptoRng>(rng: &mut R) -> Result<Self>
pub fn generate_recommended<R: TryCryptoRng>(rng: &mut R) -> Result<Self>
Generate PBES2 parameters using the recommended algorithm settings and a randomly generated salt and IV.
This is currently an alias for Parameters::generate_scrypt. See that method
for more information.
§Errors
Returns Error::Rng in the event the random number generator R fails.
Sourcepub fn generate_pbkdf2<R: TryCryptoRng>(rng: &mut R) -> Result<Self>
pub fn generate_pbkdf2<R: TryCryptoRng>(rng: &mut R) -> Result<Self>
Generate PBES2 parameters using PBKDF2 as the password hashing algorithm, using that algorithm’s recommended algorithm settings (OWASP recommended default: 600,000 rounds) along with a randomly generated salt and IV.
This will use AES-256-CBC as the encryption algorithm and SHA-256 as the hash function for PBKDF2.
§Errors
Returns Error::Rng in the event the random number generator R fails.
Sourcepub fn generate_pbkdf2_sha256_aes128cbc(
pbkdf2_iterations: u32,
pbkdf2_salt: &[u8],
aes_iv: [u8; 16],
) -> Result<Self>
pub fn generate_pbkdf2_sha256_aes128cbc( pbkdf2_iterations: u32, pbkdf2_salt: &[u8], aes_iv: [u8; 16], ) -> Result<Self>
Initialize PBES2 parameters using PBKDF2-SHA256 as the password-based key derivation function and AES-128-CBC as the symmetric cipher.
§Errors
Propagates errors from Pbkdf2Params::hmac_sha256.
Sourcepub fn generate_pbkdf2_sha256_aes256cbc(
pbkdf2_iterations: u32,
pbkdf2_salt: &[u8],
aes_iv: [u8; 16],
) -> Result<Self>
pub fn generate_pbkdf2_sha256_aes256cbc( pbkdf2_iterations: u32, pbkdf2_salt: &[u8], aes_iv: [u8; 16], ) -> Result<Self>
Initialize PBES2 parameters using PBKDF2-SHA256 as the password-based key derivation function and AES-256-CBC as the symmetric cipher.
§Errors
Propagates errors from Pbkdf2Params::hmac_sha256.
Sourcepub fn generate_scrypt<R: TryCryptoRng>(rng: &mut R) -> Result<Self>
pub fn generate_scrypt<R: TryCryptoRng>(rng: &mut R) -> Result<Self>
Generate PBES2 parameters using scrypt as the password hashing algorithm, using that algorithm’s recommended algorithm settings along with a randomly generated salt and IV.
This will use AES-256-CBC as the encryption algorithm.
scrypt parameters are deliberately chosen to retain compatibility with OpenSSL v3. See RustCrypto/formats#1205 for more information. Parameter choices are as follows:
log_n: 14r: 8p: 1- salt length: 16
§Errors
Returns Error::Rng in the event the random number generator R fails.
Sourcepub fn generate_scrypt_aes128cbc(
params: Params,
salt: &[u8],
aes_iv: [u8; 16],
) -> Result<Self>
pub fn generate_scrypt_aes128cbc( params: Params, salt: &[u8], aes_iv: [u8; 16], ) -> Result<Self>
Initialize PBES2 parameters using scrypt as the password-based key derivation function and AES-128-CBC as the symmetric cipher.
For more information on scrypt parameters, see documentation for the
scrypt::Params struct.
§Errors
Propagates errors from ScryptParams::from_params_and_salt.
Sourcepub fn generate_scrypt_aes256cbc(
params: Params,
salt: &[u8],
aes_iv: [u8; 16],
) -> Result<Self>
pub fn generate_scrypt_aes256cbc( params: Params, salt: &[u8], aes_iv: [u8; 16], ) -> Result<Self>
Initialize PBES2 parameters using scrypt as the password-based key derivation function and AES-256-CBC as the symmetric cipher.
For more information on scrypt parameters, see documentation for the
scrypt::Params struct.
When in doubt, use Default::default() as the scrypt::Params.
This also avoids the need to import the type from the scrypt crate.
§Errors
Propagates errors from ScryptParams::from_params_and_salt.
Sourcepub fn scrypt_aes128gcm(
params: Params,
salt: &[u8],
gcm_nonce: [u8; 12],
) -> Result<Self>
pub fn scrypt_aes128gcm( params: Params, salt: &[u8], gcm_nonce: [u8; 12], ) -> Result<Self>
Initialize PBES2 parameters using scrypt as the password-based key derivation function and AES-128-GCM as the symmetric cipher.
For more information on scrypt parameters, see documentation for the
scrypt::Params struct.
§Errors
Propagates errors from ScryptParams::from_params_and_salt.
Sourcepub fn scrypt_aes256gcm(
params: Params,
salt: &[u8],
gcm_nonce: [u8; 12],
) -> Result<Self>
pub fn scrypt_aes256gcm( params: Params, salt: &[u8], gcm_nonce: [u8; 12], ) -> Result<Self>
Initialize PBES2 parameters using scrypt as the password-based key derivation function and AES-256-GCM as the symmetric cipher.
For more information on scrypt parameters, see documentation for the
scrypt::Params struct.
§Errors
Propagates errors from ScryptParams::from_params_and_salt.
Sourcepub fn decrypt(
&self,
password: impl AsRef<[u8]>,
ciphertext: &[u8],
) -> Result<Vec<u8>>
pub fn decrypt( &self, password: impl AsRef<[u8]>, ciphertext: &[u8], ) -> Result<Vec<u8>>
Attempt to decrypt the given ciphertext, allocating and returning a byte vector containing the plaintext.
§Errors
Returns Error::UnsupportedAlgorithm if support for the requested algorithm has not been
enabled in this crate’s features.
Sourcepub fn decrypt_in_place<'a>(
&self,
password: impl AsRef<[u8]>,
buffer: &'a mut [u8],
) -> Result<&'a [u8]>
pub fn decrypt_in_place<'a>( &self, password: impl AsRef<[u8]>, buffer: &'a mut [u8], ) -> Result<&'a [u8]>
Attempt to decrypt the given ciphertext in-place using a key derived from the provided password and this scheme’s parameters.
Returns an error if the algorithm specified in this scheme’s parameters is unsupported, or if the ciphertext is malformed (e.g. not a multiple of a block mode’s padding).
§Errors
Returns Error::UnsupportedAlgorithm if support for the requested algorithm has not been
enabled in this crate’s features.
Sourcepub fn encrypt(
&self,
password: impl AsRef<[u8]>,
plaintext: &[u8],
) -> Result<Vec<u8>>
pub fn encrypt( &self, password: impl AsRef<[u8]>, plaintext: &[u8], ) -> Result<Vec<u8>>
Encrypt the given plaintext, allocating and returning a vector containing the ciphertext.
§Errors
Returns Error::UnsupportedAlgorithm if support for the requested algorithm has not been
enabled in this crate’s features.
Sourcepub fn encrypt_in_place<'a>(
&self,
password: impl AsRef<[u8]>,
buffer: &'a mut [u8],
pos: usize,
) -> Result<&'a [u8]>
pub fn encrypt_in_place<'a>( &self, password: impl AsRef<[u8]>, buffer: &'a mut [u8], pos: usize, ) -> Result<&'a [u8]>
Encrypt the given plaintext in-place using a key derived from the provided password and this scheme’s parameters, writing the ciphertext into the same buffer.
§Errors
Returns Error::UnsupportedAlgorithm if support for the requested algorithm has not been
enabled in this crate’s features.