Generate a key that can be used by the primitives of the secretbox API.
Modulelibsodium-bindings-0.0.1.1Haskell2010
LibSodium.Bindings.Secretbox
- 10 values
- Packagelibsodium-bindings-0.0.1.1
- Exports10
- LanguageHaskell2010
- LicenceBSD-3-Clause
- SourceSecretbox.hs
Introduction
0 declarationsThis API allows encrypting a message using a secret key and a nonce. The ciphertext is accompanied by an authentication tag.
It comes in two flavours:
- easy
Both the ciphertext and authentication tag are stored in the same buffer.
- detached
The ciphertext and authentication tag may be stored in separate buffers.
The same key is used for both encryption and decryption, so it must be kept secret. A key can be generated using the cryptoSecretboxKeygen primitive.
Each message must use a unique nonce, which may be generated with the randombytesBuf primitive. The nonce does not need to be kept secret but should never be reused with the same secret key.
For more information see the upstream docs: https://doc.libsodium.org/secret-key_cryptography/secretbox
Secretbox
0 declarationsKeygen
Easy
cryptoSecretboxEasy :: Ptr CUCharA pointer to the buffer that will hold the ciphertext. The length of the ciphertext is the length of the message in bytes plus cryptoSecretboxMACBytes bytes.
-> Ptr CUCharA pointer to the buffer holding the message to be encrypted.
-> CULLongThe length of the message in bytes.
-> Ptr CUCharA pointer to the nonce of size cryptoSecretboxNonceBytes bytes.
-> Ptr CUCharA pointer to the secret key of size cryptoSecretboxKeyBytes bytes.
-> IO CIntReturns 0 on success and -1 on error.
Encrypt a message using a secret key and nonce.
The message and ciphertext buffers may overlap enabling in-place encryption, but note that the ciphertext will be cryptoSecretboxMACBytes bytes longer than the message.
cryptoSecretboxOpenEasy :: Ptr CUCharA pointer to the buffer that will hold the decrypted message. The length of the message is the length of the ciphertext in bytes minus cryptoSecretboxMACBytes bytes.
-> Ptr CUCharA pointer to the buffer holding the ciphertext to be verified and decrypted.
-> CULLongThe length of the ciphertext in bytes.
-> Ptr CUCharA pointer to the nonce of size cryptoSecretboxNonceBytes bytes.
-> Ptr CUCharA pointer to the secret key of size cryptoSecretboxKeyBytes bytes.
-> IO CIntReturns 0 on success and -1 on error.
Verify and decrypt ciphertext using a secret key and nonce.
The message and ciphertext buffers may overlap enabling in-place decryption, but note that the message will be cryptoSecretboxMACBytes bytes shorter than the ciphertext.
Detached
cryptoSecretboxDetached :: Ptr CUCharA pointer to the buffer that will hold the ciphertext. This will have the same length as the message.
-> Ptr CUCharA pointer to the buffer that will hold the authentication tag. This will be of length cryptoSecretboxMACBytes bytes.
-> Ptr CUCharA pointer to the buffer holding the message to be encrypted.
-> CULLongThe length of the message in bytes.
-> Ptr CUCharA pointer to the nonce of size cryptoSecretboxNonceBytes bytes.
-> Ptr CUCharA pointer to the secret key of size cryptoSecretboxKeyBytes bytes.
-> IO CIntReturns 0 on success and -1 on error.
Encrypt a message using a secret key and nonce.
cryptoSecretboxOpenDetached :: Ptr CUCharA pointer to the buffer that will hold the decrypted message. This will have the same length as the ciphertext.
-> Ptr CUCharA pointer to the buffer holding the ciphertext to be decrypted.
-> Ptr CUCharA pointer to the buffer holding the authentication tag to be verified.
-> CULLongThe length of the ciphertext in bytes.
-> Ptr CUCharA pointer to the nonce of size cryptoSecretboxNonceBytes bytes.
-> Ptr CUCharA pointer to the secret key of size cryptoSecretboxKeyBytes bytes.
-> IO CIntReturns 0 on success and -1 on error.
Verify and decrypt ciphertext using a secret key and nonce
Constants
The length of a secretbox key in bytes.
The length of a secretbox nonce in bytes.
The length of a secretbox authentication tag in bytes.
The underlying cryptographic algorithm used to implement the secretbox API.
Maximum length of a message in bytes that can be encrypted using the secretbox API.