Skip to main content
This is unreleased documentation for the main (development) branch of crypto-glue.

Parameters

Struct Parameters 

Source
pub struct Parameters {
    pub kdf: Kdf,
    pub encryption: EncryptionScheme,
}
Expand description

Password-Based Encryption Scheme 2 parameters as defined in RFC 8018 Appendix A.4.

 PBES2-params ::= SEQUENCE {
      keyDerivationFunc AlgorithmIdentifier {{PBES2-KDFs}},
      encryptionScheme AlgorithmIdentifier {{PBES2-Encs}} }

These define a set of algorithms for password-based key derivation, as well as a salt value (typically randomly generated) to provide to the KDF algorithm, along with an encryption algorithm and its associated IV/nonce (typically randomly generated).

Security Warning

This type should not be used to encrypt multiple plaintexts under the same IV/salt values.

Instead, new values should be randomly generated for every usage.

Fields§

§kdf: Kdf

Key derivation function

§encryption: EncryptionScheme

Encryption scheme

Implementations§

Source§

impl Parameters

Generate PBES2 parameters using the recommended algorithm settings and a randomly generated salt and IV.

This is currently an alias for Parameters::generate_scrypt. See that method for more information.

§Errors

Returns Error::Rng in the event the random number generator R fails.

Source

pub fn generate_pbkdf2<R: TryCryptoRng>(rng: &mut R) -> Result<Self>

Generate PBES2 parameters using PBKDF2 as the password hashing algorithm, using that algorithm’s recommended algorithm settings (OWASP recommended default: 600,000 rounds) along with a randomly generated salt and IV.

This will use AES-256-CBC as the encryption algorithm and SHA-256 as the hash function for PBKDF2.

§Errors

Returns Error::Rng in the event the random number generator R fails.

Source

pub fn generate_pbkdf2_sha256_aes128cbc( pbkdf2_iterations: u32, pbkdf2_salt: &[u8], aes_iv: [u8; 16], ) -> Result<Self>

Initialize PBES2 parameters using PBKDF2-SHA256 as the password-based key derivation function and AES-128-CBC as the symmetric cipher.

§Errors

Propagates errors from Pbkdf2Params::hmac_sha256.

Source

pub fn generate_pbkdf2_sha256_aes256cbc( pbkdf2_iterations: u32, pbkdf2_salt: &[u8], aes_iv: [u8; 16], ) -> Result<Self>

Initialize PBES2 parameters using PBKDF2-SHA256 as the password-based key derivation function and AES-256-CBC as the symmetric cipher.

§Errors

Propagates errors from Pbkdf2Params::hmac_sha256.

Source

pub fn generate_scrypt<R: TryCryptoRng>(rng: &mut R) -> Result<Self>

Generate PBES2 parameters using scrypt as the password hashing algorithm, using that algorithm’s recommended algorithm settings along with a randomly generated salt and IV.

This will use AES-256-CBC as the encryption algorithm.

scrypt parameters are deliberately chosen to retain compatibility with OpenSSL v3. See RustCrypto/formats#1205 for more information. Parameter choices are as follows:

  • log_n: 14
  • r: 8
  • p: 1
  • salt length: 16
§Errors

Returns Error::Rng in the event the random number generator R fails.

Source

pub fn generate_scrypt_aes128cbc( params: Params, salt: &[u8], aes_iv: [u8; 16], ) -> Result<Self>

Initialize PBES2 parameters using scrypt as the password-based key derivation function and AES-128-CBC as the symmetric cipher.

For more information on scrypt parameters, see documentation for the scrypt::Params struct.

§Errors

Propagates errors from ScryptParams::from_params_and_salt.

Source

pub fn generate_scrypt_aes256cbc( params: Params, salt: &[u8], aes_iv: [u8; 16], ) -> Result<Self>

Initialize PBES2 parameters using scrypt as the password-based key derivation function and AES-256-CBC as the symmetric cipher.

For more information on scrypt parameters, see documentation for the scrypt::Params struct.

When in doubt, use Default::default() as the scrypt::Params. This also avoids the need to import the type from the scrypt crate.

§Errors

Propagates errors from ScryptParams::from_params_and_salt.

Source

pub fn scrypt_aes128gcm( params: Params, salt: &[u8], gcm_nonce: [u8; 12], ) -> Result<Self>

Initialize PBES2 parameters using scrypt as the password-based key derivation function and AES-128-GCM as the symmetric cipher.

For more information on scrypt parameters, see documentation for the scrypt::Params struct.

§Errors

Propagates errors from ScryptParams::from_params_and_salt.

Source

pub fn scrypt_aes256gcm( params: Params, salt: &[u8], gcm_nonce: [u8; 12], ) -> Result<Self>

Initialize PBES2 parameters using scrypt as the password-based key derivation function and AES-256-GCM as the symmetric cipher.

For more information on scrypt parameters, see documentation for the scrypt::Params struct.

§Errors

Propagates errors from ScryptParams::from_params_and_salt.

Source

pub fn decrypt( &self, password: impl AsRef<[u8]>, ciphertext: &[u8], ) -> Result<Vec<u8>>

Attempt to decrypt the given ciphertext, allocating and returning a byte vector containing the plaintext.

§Errors

Returns Error::UnsupportedAlgorithm if support for the requested algorithm has not been enabled in this crate’s features.

Source

pub fn decrypt_in_place<'a>( &self, password: impl AsRef<[u8]>, buffer: &'a mut [u8], ) -> Result<&'a [u8]>

Attempt to decrypt the given ciphertext in-place using a key derived from the provided password and this scheme’s parameters.

Returns an error if the algorithm specified in this scheme’s parameters is unsupported, or if the ciphertext is malformed (e.g. not a multiple of a block mode’s padding).

§Errors

Returns Error::UnsupportedAlgorithm if support for the requested algorithm has not been enabled in this crate’s features.

Source

pub fn encrypt( &self, password: impl AsRef<[u8]>, plaintext: &[u8], ) -> Result<Vec<u8>>

Encrypt the given plaintext, allocating and returning a vector containing the ciphertext.

§Errors

Returns Error::UnsupportedAlgorithm if support for the requested algorithm has not been enabled in this crate’s features.

Source

pub fn encrypt_in_place<'a>( &self, password: impl AsRef<[u8]>, buffer: &'a mut [u8], pos: usize, ) -> Result<&'a [u8]>

Encrypt the given plaintext in-place using a key derived from the provided password and this scheme’s parameters, writing the ciphertext into the same buffer.

§Errors

Returns Error::UnsupportedAlgorithm if support for the requested algorithm has not been enabled in this crate’s features.

Trait Implementations§

Source§

impl Clone for Parameters

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Parameters

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'a> DecodeValue<'a> for Parameters

Source§

type Error = Error

Type returned in the event of a decoding error.
Source§

fn decode_value<R: Reader<'a>>(reader: &mut R, header: Header) -> Result<Self>

Attempt to decode this value using the provided Reader. Read more
Source§

impl EncodeValue for Parameters

Source§

fn value_len(&self) -> Result<Length>

Compute the length of this value (sans [Tag]+Length header) when encoded as ASN.1 DER. Read more
Source§

fn encode_value(&self, writer: &mut impl Writer) -> Result<()>

Encode value (sans [Tag]+Length header) as ASN.1 DER using the provided Writer. Read more
Source§

fn header(&self) -> Result<Header, Error>
where Self: Tagged,

Get the Header used to encode this value. Read more
Source§

impl Eq for Parameters

Source§

impl From<Parameters> for EncryptionScheme

Source§

fn from(params: Parameters) -> EncryptionScheme

Converts to this type from the input type.
Source§

impl PartialEq for Parameters

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Sequence<'_> for Parameters

Source§

impl StructuralPartialEq for Parameters

Source§

impl TryFrom<AnyRef<'_>> for Parameters

Source§

type Error = Error

The type returned in the event of a conversion error.
Source§

fn try_from(any: AnyRef<'_>) -> Result<Self>

Performs the conversion.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<'a, T> Choice<'a> for T
where T: Decode<'a> + FixedTag,

Source§

fn can_decode(tag: Tag) -> bool

Is the provided Tag decodable as a variant of this CHOICE?
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<'a, T> Decode<'a> for T
where T: DecodeValue<'a> + FixedTag + 'a,

Source§

type Error = <T as DecodeValue<'a>>::Error

Type returned in the event of a decoding error.
Source§

fn decode<R>(reader: &mut R) -> Result<T, <T as DecodeValue<'a>>::Error>
where R: Reader<'a>,

Attempt to decode this TLV message using the provided decoder. Read more
Source§

fn from_der(bytes: &'a [u8]) -> Result<Self, Self::Error>

Parse Self from the provided DER-encoded byte slice. Read more
Source§

fn from_der_partial(bytes: &'a [u8]) -> Result<(Self, &'a [u8]), Self::Error>

Parse Self from the provided DER-encoded byte slice. Read more
Source§

impl<T> DecodeOwned for T
where T: for<'a> Decode<'a>,

Source§

impl<T> Encode for T
where T: EncodeValue + Tagged + ?Sized,

Source§

fn encoded_len(&self) -> Result<Length, Error>

Compute the length of this TLV object in bytes when encoded as ASN.1 DER. Read more
Source§

fn encode(&self, writer: &mut impl Writer) -> Result<(), Error>

Encode this TLV object as ASN.1 DER using the provided Writer. Read more
Source§

fn encode_to_slice<'a>(&self, buf: &'a mut [u8]) -> Result<&'a [u8], Error>

Encode this TLV object to the provided byte slice, returning a sub-slice containing the encoded message. Read more
Source§

fn encode_to_vec(&self, buf: &mut Vec<u8>) -> Result<Length, Error>

Encode this TLV object as ASN.1 DER, appending it to the provided byte vector. Read more
Source§

fn to_der(&self) -> Result<Vec<u8>, Error>

Encode this TLV object as ASN.1 DER, returning a byte vector. Read more
Source§

impl<'a, S> FixedTag for S
where S: Sequence<'a>,

Source§

const TAG: Tag = Tag::Sequence

ASN.1 tag
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IsConstructed for T
where T: FixedTag + ?Sized,

Source§

const CONSTRUCTED: bool

ASN.1 constructed bit
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> Tagged for T
where T: FixedTag + ?Sized,

Source§

fn tag(&self) -> Tag

Get the ASN.1 tag that this type is encoded with.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.