HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

Modulecryptohash-sha256-0.11.102.1Haskell2010

Crypto.Hash.SHA256

A module containing SHA-256 bindings

  • 1 type
  • 14 values

Incremental API

8 declarations

This API is based on 4 different functions, similar to the lowlevel operations of a typical hash:

  • init: create a new hash context

  • update: update non-destructively a new hash context with a strict bytestring

  • updates: same as update, except that it takes a list of strict bytestrings

  • finalize: finalize the context and returns a digest bytestring.

all those operations are completely pure, and instead of changing the context as usual in others language, it re-allocates a new context each time.

Example:

import qualified Data.ByteString
import qualified Crypto.Hash.SHA256 as SHA256

main = print digest
  where
    digest = SHA256.finalize ctx
    ctx    = foldl SHA256.update ctx0 (map Data.ByteString.pack [ [1,2,3], [4,5,6] ])
    ctx0   = SHA256.init
newtypenewtype Ctx
#

SHA-256 Context

The context data is exactly 104 bytes long, however the data in the context is stored in host-endianness.

The context data is made up of

  • a Word64 representing the number of bytes already feed to hash algorithm so far,

  • a 64-element Word8 buffer holding partial input-chunks, and finally

  • a 8-element Word32 array holding the current work-in-progress digest-value.

Consequently, a SHA-256 digest as produced by hash, hashlazy, or finalize is 32 bytes long.

Constructors

Instances1Eq
  • Eq CtxDefined in cryptohash-sha256-0.11.102.1 · Crypto.Hash.SHA256.FFI
valueinit :: Ctx
#

create a new hash context

Single Pass API

3 declarations

This API use the incremental API under the hood to provide the common all-in-one operations to create digests out of a ByteString and lazy ByteString.

Example:

import qualified Data.ByteString
import qualified Crypto.Hash.SHA256 as SHA256

main = print $ SHA256.hash (Data.ByteString.pack [0..255])

NOTE: The returned digest is a binary ByteString. For converting to a base16/hex encoded digest the base16-bytestring package is recommended.

HMAC-SHA-256

RFC2104-compatible HMAC-SHA-256 digests

HKDF-SHA-256

RFC5869-compatible HKDF-SHA-256 key derivation function

valuehkdf
  1. :: ByteString

    IKM Input keying material

  2. -> ByteString

    salt Optional salt value, a non-secret random value (can be "")

  3. -> ByteString

    info Optional context and application specific information (can be "")

  4. -> Int

    L length of output keying material in octets (at most 255*32 bytes)

  5. -> ByteString

    OKM Output keying material (L bytes)

#

RFC6234-compatible HKDF-SHA-256 key derivation function.