HORIZON HASKELLDocslts/ghc-9.10.xc74966e2026-09-27Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27

Modulelibsodium-bindings-0.0.1.1Haskell2010

LibSodium.Bindings.CryptoSign

  • 1 type
  • 18 values

Introduction

0 declarations

When signing with public-key cryptography, a signer generates a key pair consisting of:

  • A secret key, which you can use to append a signature to any number of messages.

  • A public key, which anybody can use to verify that the signature appended to a message was issued by the creator of the public key.

Verifiers need to already know and ultimately trust a public key before messages signed using it can be verified.

Warning: this is different from authenticated encryption. Appending a signature does not change the representation of the message itself.

Key pair generation

2 declarations

Combined mode

2 declarations
valuecryptoSign
  1. :: Ptr CUChar

    Pointer to the signed message.

  2. -> Ptr CULLong

    Pointer to the length of the signed message.

  3. -> Ptr CUChar

    Pointer to the message to sign.

  4. -> CULLong

    Length of the message.

  5. -> Ptr CUChar

    Pointer to the secret key.

  6. -> IO CInt

    Returns 0 on success, -1 on error.

#

Prepend a signature to a message, using the secret key.

The signed message, which includes the signature plus an unaltered copy of the message, is put into the signed message buffer, and is of length cryptoSignBytes + length of the message bytes.

If the pointer to the length of the signed message is not a Foreign.nullPtr, then the actual length of the signed message is stored in it.

See: crypto_sign()

valuecryptoSignOpen
  1. :: Ptr CUChar

    Pointer to the buffer holding the message without the signature.

  2. -> Ptr CULLong

    Pointer to the buffer holding the length of the message, if it is not a Foreign.nullPtr.

  3. -> Ptr CUChar

    Pointer to the signed message.

  4. -> CULLong

    Length of the signed message.

  5. -> Ptr CUChar

    Pointer to the public key.

  6. -> IO CInt

    On success, the function returns 0 If the signature isn't valid, then the function returns -1.

#

Check that the signed message has a valid signature for the public key.

On success, it puts the message, without the signature into the first buffer. The length of the message will be stored in the , if the pointer is not a Foreign.nullPtr.

See: crypto_sign_open()

Detached Mode

2 declarations

In detached mode, the signature is stored without attaching a copy of the original message to it.

valuecryptoSignDetached
  1. :: Ptr CUChar

    Pointer to the signature.

  2. -> Ptr CULLong

    Pointer to the length of the signature.

  3. -> Ptr CUChar

    Pointer to the message to sign.

  4. -> CULLong

    Length of the message.

  5. -> Ptr CUChar

    Pointer to the secret key.

  6. -> IO CInt

    Returns 0 on success, -1 on error.

#

Sign the message using the secret key and put the signature into a buffer, which can be up to cryptoSignBytes bytes long. The actual length of the signature is put into a buffer if its pointer is not Foreign.nullPtr. It is safe to ignore the length of the signature and always consider a signature as cryptoSignBytes bytes long; shorter signatures will be transparently padded with zeros if necessary.

See: crypto_sign_detached()

Multi-part messages

8 declarations

If the message you're trying to sign doesn't fit in memory, then it can be provided as a sequence of arbitrarily-sized chunks. This uses the Ed25519ph signature system, which pre-hashes the message. In other words, what gets signed is not the message itself but its image through a hash function. If the message can fit in memory and be supplied as a single chunk, then the single-part API should be preferred.

Note

Ed25519ph(m) is intentionally not equivalent to Ed25519(SHA512(m)). If, for some reason, you need to pre-hash the message yourself, then use the multi-part LibSodium.Bindings.GenericHashing module and sign the 512-bit output.

valuecryptoSignFinalCreate
  1. :: Ptr CryptoSignState

    A pointer to an initialized cryptographic state. Cannot be Foreign.nullPtr.

  2. -> Ptr CUChar

    Pointer to the signature. Cannot be Foreign.nullPtr.

  3. -> Ptr CULLong

    A pointer to the length of the signature. Can be Foreign.nullPtr.

  4. -> Ptr CUChar

    Pointer to the secret key. Cannot be Foreign.nullPtr.

  5. -> IO CInt

    Returns 0 on success, -1 on error.

#

Compute a signature for the previously supplied message using the secret key, and put it into the signature buffer.

If the pointer to the length of the signature is not a Foreign.nullPtr, then the length of the signature is stored at this address. It is safe to ignore the length of the signature and always consider a signature as cryptoSignBytes bytes long; shorter signatures will be transparently padded with zeros if necessary.

See: crypto_sign_final_create()

Constants

5 declarations