.. _stdlib_crypto: ======================== Cryptographic primitives ======================== .. das:module:: crypto Native OpenSSL cryptographic primitives. Enable dasCrypto with OpenSSL 3 or newer; this module is unavailable in Emscripten. Byte inputs are bounded to 16 MiB unless a narrower limit is stated. Output-producing functions clear their output on failure and allow output/input aliasing. Callers own key storage and protocol validation. +++++++++++++++++++++++++ Randomness and comparison +++++++++++++++++++++++++ * :ref:`crypto_equal (a: array\; b: array\) : bool ` * :ref:`crypto_random_bytes (count: int; output: array\) : bool ` .. _function-crypto_crypto_equal_array_ls_uint8_gr__array_ls_uint8_gr_: .. das:function:: crypto_equal(a: array; b: array) : bool Compares equal-length byte arrays in constant time. Returns false for unequal lengths or inputs over 16 MiB; the length is not secret. :Arguments: * **a** : array implicit * **b** : array implicit .. _function-crypto_crypto_random_bytes_int_array_ls_uint8_gr_: .. das:function:: crypto_random_bytes(count: int; output: array) : bool Fills output with count cryptographically secure random bytes. Count must be between 0 and 4096 inclusive. Returns false and clears output on invalid count or generator failure. :Arguments: * **count** : int * **output** : array implicit ++++++++++++++++++++++ Message authentication ++++++++++++++++++++++ * :ref:`crypto_hmac_sha1 (key: array\; message: array\; output: array\) : bool ` * :ref:`crypto_hmac_sha256 (key: array\; message: array\; output: array\) : bool ` .. _function-crypto_crypto_hmac_sha1_array_ls_uint8_gr__array_ls_uint8_gr__array_ls_uint8_gr_: .. das:function:: crypto_hmac_sha1(key: array; message: array; output: array) : bool Computes a 20-byte HMAC-SHA1 for protocols requiring it, such as TOTP. Returns false and clears output for oversized input or cryptographic failure. :Arguments: * **key** : array implicit * **message** : array implicit * **output** : array implicit .. _function-crypto_crypto_hmac_sha256_array_ls_uint8_gr__array_ls_uint8_gr__array_ls_uint8_gr_: .. das:function:: crypto_hmac_sha256(key: array; message: array; output: array) : bool Computes a 32-byte HMAC-SHA256 from key and message. Returns false and clears output for oversized input or cryptographic failure. :Arguments: * **key** : array implicit * **message** : array implicit * **output** : array implicit ++++++++++++++++++++++++ Authenticated encryption ++++++++++++++++++++++++ * :ref:`crypto_aes256_gcm_open (key: array\; nonce: array\; ciphertext: array\; aad: array\; output: array\) : bool ` * :ref:`crypto_aes256_gcm_seal (key: array\; nonce: array\; plain: array\; aad: array\; output: array\) : bool ` .. _function-crypto_crypto_aes256_gcm_open_array_ls_uint8_gr__array_ls_uint8_gr__array_ls_uint8_gr__array_ls_uint8_gr__array_ls_uint8_gr_: .. das:function:: crypto_aes256_gcm_open(key: array; nonce: array; ciphertext: array; aad: array; output: array) : bool Authenticates and decrypts ciphertext followed by its 16-byte AES-256-GCM tag. Key is 32 bytes and nonce is 12 bytes. Returns false and clears output for invalid sizes, tag or AAD; unauthenticated plaintext is never published. :Arguments: * **key** : array implicit * **nonce** : array implicit * **ciphertext** : array implicit * **aad** : array implicit * **output** : array implicit .. _function-crypto_crypto_aes256_gcm_seal_array_ls_uint8_gr__array_ls_uint8_gr__array_ls_uint8_gr__array_ls_uint8_gr__array_ls_uint8_gr_: .. das:function:: crypto_aes256_gcm_seal(key: array; nonce: array; plain: array; aad: array; output: array) : bool Encrypts and authenticates plain with AES-256-GCM. Key is 32 bytes and nonce is 12 bytes; never reuse a nonce with the same key. Output contains ciphertext followed by a 16-byte tag. AAD is authenticated but not encrypted. Returns false and clears output on failure. :Arguments: * **key** : array implicit * **nonce** : array implicit * **plain** : array implicit * **aad** : array implicit * **output** : array implicit ++++++++++++++++++++++ Signature verification ++++++++++++++++++++++ * :ref:`crypto_verify_rsa_sha256 (modulus: array\; exponent: array\; message: array\; signature: array\) : bool ` .. _function-crypto_crypto_verify_rsa_sha256_array_ls_uint8_gr__array_ls_uint8_gr__array_ls_uint8_gr__array_ls_uint8_gr_: .. das:function:: crypto_verify_rsa_sha256(modulus: array; exponent: array; message: array; signature: array) : bool Verifies an RSA PKCS#1 v1.5 SHA-256 signature. Modulus and exponent are unsigned big-endian bytes; modulus is 2048–8192 bits and exponent is at most 8 bytes. Signature length equals the modulus byte length. Returns false for invalid inputs or signature. This does not parse certificates or establish trust in the supplied key. :Arguments: * **modulus** : array implicit * **exponent** : array implicit * **message** : array implicit * **signature** : array implicit