HORIZON HASKELLDocslts/ghc-9.10.xc74966e2026-09-27Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27

Modulecrypto-api-0.13.3Haskell98

Crypto.Padding

PKCS5 (RFC 1423) and IPSec ESP (RFC 4303) padding methods are implemented both as trivial functions operating on bytestrings and as Put routines usable from the Data.Serialize module. These methods do not work for algorithms or pad sizes in excess of 255 bytes (2040 bits, so extremely large as far as cipher needs are concerned).

  • 10 values
  • Packagecrypto-api-0.13.3
  • Exports10
  • LanguageHaskell98
  • LicenceBSD-3-Clause
  • SourcePadding.hs

PKCS5 (RFC 1423) based [un]padding routines

5 declarations

Ex:

    putPaddedPKCS5 m bs

Will pad out bs to a byte multiple of m and put both the bytestring and it's padding via Put (this saves on copying if you are already using Cereal).

ESP (RFC 4303) [un]padding routines

5 declarations
valuepadESP :: Int -> ByteString -> ByteString
#

Pad a bytestring to the IPSEC esp specification

padESP m payload

is equivilent to:

              (msg)       (padding)       (length field)
    B.concat [payload, B.pack [1,2,3,4..], B.pack [padLen]]

Where:

  • the msg is any payload, including TFC.

  • the padding is <= 255

  • the length field is one byte.

Notice the result bytesting length remainder r equals zero. The lack of a "next header" field means this function is not directly useable for an IPSec implementation (copy/paste the 4 line function and add in a "next header" field if you are making IPSec ESP).

valueputPadESP :: Int -> ByteString -> Put
#

Pad a bytestring to the IPSEC ESP specification using Put. This can reduce copying if you are already using Put.