base64-decode base64-encode bcrypt bcrypt-is-valid block-cipher/block-size block-cipher/clear block-cipher/decrypt block-cipher/encrypt block-cipher/get-keyspec block-cipher/name block-cipher/new block-cipher/set-key cipher/clear cipher/finish cipher/get-default-nonce-length cipher/get-ideal-update-granularity cipher/get-keyspec cipher/get-tag-length cipher/get-update-granularity cipher/is-authenticated cipher/name cipher/new cipher/output-length cipher/reset cipher/set-associated-data cipher/set-key cipher/start cipher/update cipher/valid-nonce-length constant-time-compare ec-group/from-ber ec-group/from-name ec-group/from-oid ec-group/from-params ec-group/from-pem ec-group/get-a ec-group/get-b ec-group/get-curve-oid ec-group/get-gx ec-group/get-gy ec-group/get-order ec-group/get-p ec-group/supports-application-specific-group ec-group/supports-named-group ec-group/to-der ec-group/to-pem ec-point/add ec-point/from-bytes ec-point/from-xy ec-point/generator ec-point/get-x ec-point/get-xy ec-point/get-y ec-point/identity ec-point/is-identity ec-point/mul ec-point/negate ec-point/to-compressed ec-point/to-uncompressed ec-scalar/from-mp ec-scalar/random ec-scalar/to-mp ffi-api-version ffi-supports-api fpe/decrypt fpe/encrypt fpe/new hash/block-size hash/clear hash/copy hash/final hash/name hash/new hash/output-length hash/security-level hash/update hex-decode hex-encode hotp/check hotp/generate hotp/new kdf mac/clear mac/final mac/get-keyspec mac/name mac/new mac/output-length mac/set-key mac/set-nonce mac/update mpi/add mpi/clear-bit mpi/div mpi/flip-sign mpi/gcd mpi/get-bit mpi/inverse-mod mpi/is-negative mpi/is-positive mpi/is-prime mpi/is-zero mpi/lshift mpi/mod-mul mpi/mul mpi/new mpi/new-random mpi/new-random-range mpi/num-bits mpi/num-bytes mpi/pow-mod mpi/rshift mpi/set-bit mpi/sub mpi/swap mpi/to-bin mpi/to-hex mpi/to-int mpi/to-u32 nist-key-unwrap nist-key-wrap oid/from-string oid/register oid/to-name oid/to-string pbkdf pbkdf-timed pk-decrypt/decrypt pk-decrypt/new pk-encrypt/encrypt pk-encrypt/new pk-kem-decrypt/decrypt-shared-key pk-kem-decrypt/new pk-kem-decrypt/shared-key-length pk-kem-encrypt/create-shared-key pk-kem-encrypt/encapsulated-key-length pk-kem-encrypt/new pk-kem-encrypt/shared-key-length pk-key-agreement/agree pk-key-agreement/new pk-key-agreement/public-value pk-sign/finish pk-sign/new pk-sign/update pk-verify/finish pk-verify/new pk-verify/update privkey/algo-name privkey/check-key privkey/export privkey/get-ec-group privkey/get-ec-private-key privkey/get-field privkey/get-pubkey privkey/load privkey/load-classic-mceliece privkey/load-dh privkey/load-dsa privkey/load-ecdh privkey/load-ecdsa privkey/load-ed25519 privkey/load-ed448 privkey/load-elgamal privkey/load-frodokem privkey/load-ml-dsa privkey/load-ml-kem privkey/load-rsa privkey/load-slh-dsa privkey/load-sm2 privkey/load-x25519 privkey/load-x448 privkey/new privkey/new-ec privkey/oid privkey/remaining-operations privkey/stateful-operation privkey/to-der privkey/to-encrypted-der privkey/to-encrypted-pem privkey/to-pem privkey/to-raw pubkey/algo-name pubkey/check-key pubkey/estimated-strength pubkey/export pubkey/fingerprint pubkey/get-ec-group pubkey/get-field pubkey/get-public-point pubkey/load pubkey/load-classic-mceliece pubkey/load-dh pubkey/load-dsa pubkey/load-ecdh pubkey/load-ecdh-sec1 pubkey/load-ecdsa pubkey/load-ecdsa-sec1 pubkey/load-ed25519 pubkey/load-ed448 pubkey/load-elgamal pubkey/load-frodokem pubkey/load-ml-dsa pubkey/load-ml-kem pubkey/load-rsa pubkey/load-slh-dsa pubkey/load-sm2 pubkey/load-sm2-sec1 pubkey/load-x25519 pubkey/load-x448 pubkey/oid pubkey/to-der pubkey/to-pem pubkey/to-raw rng/add-entropy rng/get rng/get-with-input rng/new rng/new-drbg rng/reseed rng/reseed-from-rng scrypt spake2p-derive-secret spake2p-params/confirmation-size spake2p-params/new spake2p-params/new-custom spake2p-params/share-size spake2p-prover/generate-message spake2p-prover/new spake2p-prover/process-message spake2p-prover/shared-secret spake2p-registration-record spake2p-verifier/new spake2p-verifier/process-message spake2p-verifier/shared-secret spake2p-verifier/skip-confirmation spake2p-verifier/verify-confirmation srp6-client-agree srp6-generate-verifier srp6-server-session/new srp6-server-session/step1 srp6-server-session/step2 totp/check totp/generate totp/new version-datestamp version-major version-minor version-patch version-string x509-cert/allowed-ext-usage x509-cert/allowed-usage x509-cert/authority-key-id x509-cert/create-self-signed x509-cert/dup x509-cert/ext-as-blocks-asnum x509-cert/ext-as-blocks-rdi x509-cert/ext-ip-addr-blocks x509-cert/fingerprint x509-cert/hostname-match x509-cert/is-ca x509-cert/issue x509-cert/issuer-dn x509-cert/load x509-cert/load-file x509-cert/not-after x509-cert/not-before x509-cert/san x509-cert/serial-number x509-cert/subject-dn x509-cert/subject-key-id x509-cert/subject-public-key x509-cert/subject-public-key-bits x509-cert/to-der x509-cert/to-pem x509-cert/to-string x509-cert/validation-status x509-cert/verify x509-crl-entry/create x509-crl-entry/reason x509-crl-entry/revocation-date x509-crl-entry/serial-number x509-crl/create x509-crl/entries-count x509-crl/get-entry x509-crl/is-revoked x509-crl/load x509-crl/load-file x509-crl/next-update x509-crl/revoke x509-crl/this-update x509-crl/to-der x509-crl/to-pem x509-crl/verify xof/accepts-input xof/block-size xof/clear xof/copy xof/name xof/new xof/output xof/update zfec-decode zfec-encode
(base64-decode str)Performs base64 decoding of string data in `str`. Returns the string.
(base64-encode bin)Performs base64 encoding of binary data in `bin`. Returns the string.
(bcrypt password rng &opt work-factor)Provided the password and an RNG object, returns a bcrypt string.
(bcrypt-is-valid password bcrypt)Check a bcrypt hash against the provided password, returning true if the password matches.
(block-cipher/block-size bc-obj)Return the block size of this cipher.
(block-cipher/clear bc-obj)Clear the internal state (such as keys) of this cipher object, but do not deallocate it. Returns `bc-obj`.
(block-cipher/decrypt bc-obj input)Decrypt `input` data. The key must have been set beforehand. Returns decrypted data in buffer format.
(block-cipher/encrypt bc-obj input)Encrypt `input` data. The key must have been set beforehand. Returns encrypted data in buffer format.
(block-cipher/get-keyspec bc-obj)Return the key spec of this cipher in format of [max-key-length min-key-length mod-key-length].
(block-cipher/name bc-obj)Return the name of this block cipher algorithm, which may or may not exactly match what was passed to `block-cipher/new`.
(block-cipher/new name)Create a new cipher mode object, `name` should be for example "AES-128" or "Threefish-512". Returns `bc-obj`.
(block-cipher/set-key bc-obj key)Set the cipher key, which is required before encrypting or decrypting. Returns `bc-obj`.
(cipher/clear cipher-obj)Reset the state of `cipher` back to clean, as if no key and input has been supplied. Returns `cipher-obj`.
(cipher/finish cipher-obj input)Finish processing (with an optional final `input`). May throw if message authentication checks fail, in which case all plaintext previously processed must be discarded. You may call `cipher/finish` with the entire message.
(cipher/get-default-nonce-length cipher-obj)Returns default nonce length.
(cipher/get-ideal-update-granularity cipher-obj)Return the ideal update granularity of the cipher for best performance.
(cipher/get-keyspec cipher-obj)Return the key spec of this `cipher` in format of `[max-key-length min-key-length mod-key-length]`.
(cipher/get-tag-length cipher-obj)Returns the tag length (0 for unauthenticated modes).
(cipher/get-update-granularity cipher-obj)Return the update granularity of the cipher. `cipher/update` must be called with blocks of this size, except for the final.
(cipher/is-authenticated cipher-obj)Returns true if this is an AEAD mode.
(cipher/new name type)Creates an cipher object of the given name, e.g., "AES-256/GCM". Create an encryption cipher if :encrypt type is given, create decryption cipher if :decrypt type is supplied.
(cipher/output-length cipher-obj input-len)Returns the output length of this cipher, for a given `input-len`.
(cipher/reset cipher-obj)Reset the message specific state of `cipher-obj`. The key remains set. Returns `cipher-obj`.
(cipher/set-associated-data cipher-obj ad)Sets the associated data and returns `cipher-obj`. Fails if this is not an AEAD mode.
(cipher/set-key cipher-obj key)Set the symmetric key to be used. Returns `cipher-obj`.
(cipher/start cipher-obj nonce)Start processing a message using `nonce`. Returns `cipher-obj`.
(cipher/update cipher-obj input)Consumes `input` text and returns output. Input text must be of `cipher/get-update-granularity` length. Alternately, always call finish with the entire message, avoiding calls to update entirely.
(cipher/valid-nonce-length cipher-obj nonce-len)Returns true if `nonce-len` is a valid nonce len for this mode.
(constant-time-compare x y)Check if buffer `x` equals buffer `y`. Returns a boolean.
(ec-group/from-ber ber)Create a new EC Group from a BER encoded ECC domain parameter set.
(ec-group/from-name name)Create a new EC Group from a common group name (e.g., "secp256r1").
(ec-group/from-oid oid)Create a new EC Group from a group named by an object identifier.
(ec-group/from-params oid p a b gx gy order)Create a new EC Group from the given parameters. The `oid` is an OID object, `p`, `a`, `b`, `gx`, `gy` and `order` are MPI objects.
(ec-group/get-a ec-group-obj)Returns the MPI object representing the `a` parameter of the elliptic curve equation.
(ec-group/get-b ec-group-obj)Returns the MPI object representing the `b` parameter of the elliptic curve equation.
(ec-group/get-curve-oid ec-group-obj)Returns the curve OID object of an EC Group.
(ec-group/get-gx ec-group-obj)Returns the MPI object representing the `x` coordinate of the base point.
(ec-group/get-gy ec-group-obj)Returns the MPI object representing the `y` coordinate of the base point.
(ec-group/get-order ec-group-obj)Returns the MPI object representing the order of the base point.
(ec-group/get-p ec-group-obj)Returns the MPI object representing the prime modulus of the elliptic curve field.
(ec-group/supports-application-specific-group)Returns true if it is possible to register an application specific elliptic curve, false otherwise.
(ec-group/supports-named-group name)Returns true if `name` is a supported EC group, false otherwise.
(ec-point/from-bytes ec-group-obj bytes)Returns a point on `ec-group-obj` decoded from a SEC1 compressed or uncompressed encoding `bytes`.
(ec-point/from-xy ec-group-obj x y)Returns a point on `ec-group-obj` from the affine integer coordinates `x` and `y` (MPI objects). Both must be within the field and satisfy the curve equation.
(ec-point/generator ec-group-obj)Returns the standard generator point of `ec-group-obj`.
(ec-point/get-x ec-point-obj)Returns the fixed-length encoding of the affine x coordinate of `ec-point-obj`.
(ec-point/get-xy ec-point-obj)Returns the fixed-length concatenated encoding of the affine x and y coordinates of `ec-point-obj`.
(ec-point/get-y ec-point-obj)Returns the fixed-length encoding of the affine y coordinate of `ec-point-obj`.
(ec-point/identity ec-group-obj)Returns the identity element (point at infinity) of `ec-group-obj`.
(ec-point/is-identity ec-point-obj)Returns true if `ec-point-obj` is the identity element, false otherwise.
(ec-point/mul ec-point-obj ec-scalar-obj rng-obj)Returns the scalar multiplication `k*P`. `rng-obj` is used internally for side-channel blinding.
(ec-point/to-compressed ec-point-obj)Returns the SEC1 compressed encoding of `ec-point-obj`.
(ec-point/to-uncompressed ec-point-obj)Returns the SEC1 uncompressed encoding of `ec-point-obj`.
(ec-scalar/from-mp ec-group-obj mp-obj)Returns a new scalar in `ec-group-obj` from the given MPI `mp-obj`. `mp-obj` must satisfy `0 < mp-obj < order`.
(ec-scalar/random ec-group-obj rng-obj)Returns a new random scalar in `ec-group-obj` drawn from `rng-obj`.
(ec-scalar/to-mp ec-scalar-obj)Returns the MPI object representing the value of `ec-scalar-obj`.
(ffi-supports-api version)Check if the FFI version specified is supported by this library. Returns a boolean.
(fpe/decrypt fpe-obj tweak)Decrypt value under the FPE scheme using provided tweak. Returns an MPI object.
(fpe/encrypt fpe-obj tweak)Encrypt value under the FPE scheme using provided tweak. Returns an MPI object.
(fpe/new modulus key &opt round compat-mode)Create a new FPE instance, FE1 scheme Rounds should be 16 or higher for best security. If omitted, default value for `round` is 5, `compat-mode` is false. Returns `fpe-obj`.
(hash/clear hash-obj)Reset the state of `hash-obj` back to clean, as if no input has been supplied. Returns `hash-obj`.
(hash/copy hash-obj)Return a new hash object copied from `hash-obj`. Returns new `hash-obj`.
(hash/new name)Creates a hash of the given name, e.g., "SHA-384". Returns `hash-obj`.
(hash/security-level hash-obj)Return the estimated security level of the `hash-obj` in bits, with respect to collision resistance. Returns zero for checksums.
(hash/update hash-obj input)Add input to the hash computation. Returns `hash-obj`.
(hex-decode str)Performs hex decoding of string data in `str`. Returns the string.
(hex-encode bin)Performs hex encoding of binary data in `bin`. Returns the string.
(hotp/check hotp-obj code counter &opt resync-range)Check if provided `code` is the correct code for `counter`. If omitted, the default value for `resync-range` is 0. If `resync-range` is greater than zero, HOTP also checks up to `resync-range` following `counter` values.
Returns a tuple of (boolean number) where the boolean indicates if the code was valid, and the number indicates the next counter value that should be used. If the `code` did not verify, the next counter value is always identical to the counter that was passed in. If the `code` did verify and `resync-range` was zero, then the next counter will always be counter+1.
(hotp/generate hotp-obj counter)Generate an HOTP code for the provided `counter`.
(hotp/new key &opt hash digits)Instantiate a new HOTP instance with the given parameters. If omitted, the default value for `hash` is "SHA-1" and the default value for `digits` is 6. Returns `hotp-obj`.
(kdf algo out-len secret salt &opt label)Performs a key derviation function (such as “HKDF(SHA-384)”) over the provided secret, salt and label values. Returns a value of the specified length.
(mac/clear mac-obj)Reset the state of `mac` back to clean, as if no key and input has been supplied. Returns `mac-obj`.
(mac/get-keyspec mac-obj)Return the key spec of the `mac` in format of [max-key-length min-key-length mod-key-length].
(mac/new name)Creates a MAC of the given name, e.g., "HMAC(SHA-384)".Returns `mac-obj`.
(mac/set-key mac-obj key)Set the `key` for the MAC calculation. Returns `mac-obj`.
(mac/set-nonce mac-obj key)Set the `nonce` for the MAC calculation. Returns `mac-obj`.Note that not all MAC algorithms require a nonce. If a nonce is required, the function has to be called before the data is processed.
(mpi/add mpi-obj x)Add x to `mpi-obj` and return the new `mpi-obj`. `x` can be either `mpi-obj` or u32 number.
(mpi/clear-bit mpi-obj bit)Clears the specified `bit` of `mpi-obj`. Returns `mpi-obj`.
(mpi/div mpi-obj-1 mpi-obj-2)Divide `mpi-obj-1` by `mpi-obj-2`. Create new quotient `mpi-obj` and remainder `mpi-obj`. Return quotient `mpi-obj` and remainder `mpi-obj` in tuple.
(mpi/gcd mpi-obj mpi-obj2)Return a new `mpi-obj` representing the greatest common divisor of `mpi-obj` and `mpi-obj2`.
(mpi/get-bit mpi-obj bit)Returns 0 if the specified `bit` of `mpi-obj` is not set, 1 if it is set.
(mpi/inverse-mod mpi-obj modulus)Create the inverse of `mpi-obj` modulo `modulus`, or nil if no inverse exists. Returns new `mpi-obj`.
(mpi/is-negative mpi-obj)Return true if `mpi-obj` is less than zero, otherwise return false.
(mpi/is-positive mpi-obj)Return true if `mpi-obj` is greater than or equal to zero. otherwise return false.
(mpi/is-prime mpi-obj rng &opt prob)Return true if `mpi-obj` is prime, otherwise returns false. Default value of prob is 128.
(mpi/lshift mpi-obj shift)Left shift by specified `shift` bit count. Return new `mpj-obj`.
(mpi/mod-mul mpi-obj mpi-obj2 modulus)Return a new `mpi-obj` representing (`mpi-obj` * `mpi-obj2`) modulo `modulus`. `mpi-obj2` and `modulus` are also `mpi-obj` objects.
(mpi/mul mpi-obj-1 mpi-obj-2)Multiply two `mpi-obj` and return the new `mpi-obj` as a result.
(mpi/new &opt value radix)Create a new MPI object with optional `value` and `radix`:
(mpi/new-random bits &opt rng)Create a `bits` sizes random MPI object. Use `rng` if provided. Returns `mpi-obj`.
(mpi/new-random-range lower upper &opt rng)Create a random MPI in the range [lower, upper]. Returns `mpi-obj`.
(mpi/num-bytes mpi-obj)Return the number of significant bytes in the `mpi-obj`.
(mpi/pow-mod mpi-obj exponent modulus)Return a new `mpi-obj` representing (`mpi-obj` ^ `exponent`) mod `modulus`.`exponent` and `modulus` are also `mpi-obj` objects.
(mpi/rshift mpi-obj shift)Right shift by specified `shift` bit count. Return new `mpj-obj`.
(mpi/set-bit mpi-obj bit)Set the specified `bit` of `mpi-obj`. Returns `mpi-obj`.
(mpi/sub mpi-obj x)Subtract x from `mpi-obj` and return the new `mpi-obj`. `x` can be either `mpi-obj` or u32 number.
(mpi/swap mpi-obj-1 mpi-obj-2)Swap `mpi-obj-1` and `mpi-obj-2` values, Return `mpi-obj-1`.
(mpi/to-hex mpi-obj)Convert the `mpi-obj` to a hex string and return as a string.
(mpi/to-int mpi-obj)Convert the `mpi-obj` to an integer string and return as a string.
(mpi/to-u32 mpi-obj)Convert the `mpi-obj` to a uint32_t, if possible. Fails if `mpi-obj` is negative or too large.
(nist-key-unwrap kek wrapped &opt cipher)This unwraps the result of nist-key-wrap. If omitted, "AES" is used for `cipher`.
(nist-key-wrap kek key &opt cipher)This performs KW (key wrap) mode. The input must be a multiple of 8 bytes long. If omitted, "AES" is used for `cipher`.
(oid/from-string str)Create an OID from a string, either dot notation (e.g. '1.2.3.4') or a registered name (e.g. 'RSA'). Returns the `oid-obj`.
(oid/register oid-obj name)Register an OID so that it may later be retrieved by name. Returns the `oid-obj` itself.
(oid/to-name oid-obj)Returns the OID as a name if it has one, otherwise as dot notation.
(pbkdf algo passphrase out-len &opt iterations salt)Derive a key from a `passphrase` for a number of `iterations`(default 100000) using the given PBKDF algorithm, e.g., "PBKDF2(SHA-512)". The `salt` can be provided or otherwise is randomly chosen. Returns `out-len` bytes of output (or potentially less depending on the algorithm and the size of the request). Returns tuple of salt, iterations, and psk
(pbkdf-timed algo passphrase out-len &opt ms-to-run salt)Derive a key from a `passphrase` for a number of Runs for as many iterations as needed to consumed `ms-to-run` milliseconds on whatever we’re running on. Returns tuple of salt, iterations, and psk. Default value of `ms-to-run` is 300 and `salt` is 12 bytes of random values.
(pk-decrypt/decrypt pk-decrypt-obj message)Decrypt the `message` using `pk-decrypt-obj`. Returns the plaintext.
(pk-decrypt/new privkey padding)Create a new operation object which can be used to decrypt using `privkey` and the specified `padding` scheme (such as "OAEP(SHA-256)" for use with RSA). Returns `pk-decrypt-obj`.
(pk-encrypt/encrypt pk-encrypt-obj message &opt rng)Encrypt the `message` using `pk-encrypt-obj`. Returns the ciphertext. New rng is used by default, if `rng` is not provided.
(pk-encrypt/new pubkey padding)Create a new operation object which can be used to encrypt using `pubkey` and the specified `padding` scheme (such as "OAEP(SHA-256)" for use with RSA). Returns `pk-encrypt-obj`.
(pk-kem-decrypt/decrypt-shared-key pk-kem-decrypt-obj salt desired-key-len encapsulated-key)Decrypt the `encapsulated-key`. Returns the shared secret.
(pk-kem-decrypt/new privkey kdf)Create a KEM operation, decrypt version, using the `privkey` and the specified `kdf`. Returns `pk-kem-decrypt-obj`.
(pk-kem-decrypt/shared-key-length pk-kem-decrypt-obj desired-shared-key-length)Returns the output shared key length, assuming `desired-shared-key-length` is provided.
Normally this will just return `desired-shared-key-length` but may return a different value if a "Raw" KDF is used (returning the unhashed output), or potentially depending on KDF limitations.
(pk-kem-encrypt/create-shared-key pk-kem-encrypt-obj salt desired-key-len &opt rng)Create a new encapsulated key. Returns the tuple of (shared-key, encapsulated-key). New rng is used by default, if `rng` is not provided.
(pk-kem-encrypt/encapsulated-key-length pk-kem-encrypt-obj)Returns the length of the encapsulated key.
(pk-kem-encrypt/new pubkey kdf)Create a KEM operation, encrypt version, using the `pubkey` and the specified `kdf`. Returns `pk-kem-encrypt-obj`.
(pk-kem-encrypt/shared-key-length pk-kem-encrypt-obj desired-shared-key-length)Returns the output shared key length, assuming `desired-shared-key-length` is provided.
Normally this will just return `desired-shared-key-length` but may return a different value if a "Raw" KDF is used (returning the unhashed output), or potentially depending on KDF limitations.
(pk-key-agreement/agree pk-key-agreement-obj other-key salt &opt key-len)Returns a key derived by the KDF. If `key-len` is omitted, default agreement size will be used.
(pk-key-agreement/new privkey kdf)Set up to perform key derivation using the `privkey` and the specified `kdf`. Returns `pk-key-agreement-obj`.
(pk-key-agreement/public-value pk-key-agreement-obj)Returns the public value to be passed to the other party.
(pk-sign/finish pk-sign-obj &opt rng)Returns a signature over all of the messages provided. Afterwards, the `pk-sign-obj` is reset and may be used to sign a new message. New rng is used by default, if `rng` is not provided.
(pk-sign/new privkey hash-and-padding)Create a signature operator for the `privkey`. The `hash-and-padding` string specifies what hash function and padding should be used, for example "PKCS1v15(SHA-256)" for PKCS #1 v1.5 padding (used with RSA) or "SHA-384". Generally speaking only RSA has special padding modes; for other algorithms like ECDSA one just names the hash. Returns `pk-sign-obj`.
(pk-sign/update pk-sign-obj message)Add the `message` to be signed. Returns `pk-sign-obj`.
(pk-verify/finish pk-verify-obj signature)Verify if the `signature` provided matches with the message provided. Returns boolean.
(pk-verify/new pubkey hash-and-padding)Create a verification operator for the `pubkey`. The `hash-and-padding` string specifies what hash function and padding should be used, for example "PKCS1v15(SHA-256)" for PKCS #1 v1.5 padding (used with RSA) or "SHA-384". Generally speaking only RSA has special padding modes; for other algorithms like ECDSA one just names the hash. Returns `pk-verify-obj`.
(pk-verify/update pk-verify-obj message)Add the `message` to be verified. Returns `pk-verify-obj`.
(privkey/check-key privkey rng &opt weak)Test the key for consistency. If `weak` is true then less expensive tests are performed.
(privkey/export privkey &opt format)Exports the private key in PKCS8 format. `format` is :pem for a PEM encoded string or :der for a binary DER value, defaulting to :der. The key will not be encrypted.
(privkey/get-ec-group privkey)Return the EC Group object of an EC private key. Fails if `privkey` is not an EC key.
(privkey/get-ec-private-key privkey)Return the EC scalar object representing the private key value of an EC private key. Fails if `privkey` is not an EC key.
(privkey/get-field privkey field-name)Return an integer field related to the private key. The valid field names vary depending on the algorithm. For example first RSA secret prime can be extracted with `(privkey/get-field key "p")`. This function can also be used to extract the public parameters.
(privkey/load blob &opt password)Return a private key (DER or PEM formats accepted). No `password` indicate no encryption expected.
(privkey/load-classic-mceliece key mode)Load a Classic McEliece private key with the given `mode`.
(privkey/load-dh p g x)`p`, `g`, `x` are MPI objects.Return a private DH key.
(privkey/load-dsa p q g x)`p`, `q`, `g`, `x` are MPI objects.Return a private DSA key.
(privkey/load-ecdh curve x)`x` is an MPI object.Return a private ECDH key.
(privkey/load-ecdsa curve x)`x` is an MPI object.Return a private ECDSA key.
(privkey/load-ed25519 key)Return a private ed25519 key created from a 32-byte raw key value.
(privkey/load-elgamal p g x)`p`, `g`, `x` are MPI objects.Return a private ElGamal key.
(privkey/load-frodokem key mode)Load a FrodoKEM private key with the given `mode`.
(privkey/load-ml-dsa key mode)Load a ML-DSA private key with the given `mode`, e.g., "ML-DSA-65".
(privkey/load-ml-kem key mode)Return a private ML-KEM key based on the given mode.
(privkey/load-rsa p q e)`p`, `q`, `e` are MPI objects.Return a private RSA key.
(privkey/load-slh-dsa key mode)Load a SLH-DSA private key with the given `mode`.
(privkey/new algo &opt param rng)Creates a new private key. The `param` type/value depends on the algorithm. For "rsa" it is the size of the key in bits. For "ecdsa" and "ecdh" it is a group name (for instance "secp256r1"). For "ecdh" there is also a special case for group "curve25519" (which is actually a completely distinct key type with a non-standard encoding). For "Ed25519", `param` can be omitted. Use `rng` if provided.
(privkey/new-ec algo ec-group &opt rng)Creates a new EC Group private key. Use `rng` if provided.
(privkey/remaining-operations privkey)Return the number of remaining operations. If the key is not stateful, an error will be occurred.
(privkey/stateful-operation privkey)Checks whether a key is stateful. Return a boolean.
(privkey/to-der privkey)Return the unencrypted DER encoding of the private key.
(privkey/to-encrypted-der privkey passphrase)Return the DER encoding of the private key encrypted with `passphrase`.
(privkey/to-encrypted-pem privkey passphrase)Return the PEM encoding of the private key encrypted with `passphrase`.
(privkey/to-pem privkey)Return the unencrypted PEM encoding of the private key.
(privkey/to-raw privkey)Return the unencrypted canonical raw encoding of the private key. This might not be defined for all key types.
(pubkey/check-key pubkey rng &opt weak)Test the key for consistency. If `weak` is true then less expensive tests are performed.
(pubkey/estimated-strength pubkey)Returns the estimated strength of this key against known attacks (NFS, Pollard’s rho, etc)
(pubkey/export pubkey &opt format)Exports the public key using the usual X.509 SPKI representation. `format` is :pem for a PEM encoded string or :der for a binary DER value, defaulting to :der.
(pubkey/fingerprint pubkey &opt hash)Returns a hash of the public key. "SHA-256" is used as a default hash, if `hash` is not provided.
(pubkey/get-ec-group pubkey)Return the EC Group object of an EC public key. Fails if `pubkey` is not an EC key.
(pubkey/get-field pubkey field-name)Return an integer field related to the public key. The valid field names vary depending on the algorithm. For example RSA public modulus can be extracted with (pubkey/get-field "n").
(pubkey/load-classic-mceliece key mode)Load a Classic McEliece public key with the given `mode`.
(pubkey/load-dsa p q g y)`p`, `q`, `g`, `y` are MPI objects.Return a public DSA key.
(pubkey/load-ecdh curve x y)`x`, `y` are MPI objects.Return a public ECDH key.
(pubkey/load-ecdh-sec1 curve sec1)`sec1` is a byte string.Return a public ECDH key.
(pubkey/load-ecdsa curve x y)`x`, `y` are MPI objects.Return a public ECDSA key.
(pubkey/load-ecdsa-sec1 curve sec1)`sec1` is a byte string.Return a public ECDSA key.
(pubkey/load-elgamal p g y)`p`, `g`, `y` are MPI objects.Return a public ElGamal key.
(pubkey/load-frodokem key mode)Load a FrodoKEM public key with the given `mode`.
(pubkey/load-ml-dsa key mode)Load a ML-DSA public key with the given `mode`, e.g., "ML-DSA-65".
(pubkey/load-ml-kem key mode)Return a public ML-KEM key based on the given mode.
(pubkey/load-rsa n e)Load an RSA public key giving the modulus and public exponent as integers.
(pubkey/load-slh-dsa key mode)Load a SLH-DSA public key with the given `mode`.
(pubkey/load-sm2 curve x y)`x`, `y` are MPI objects.Return a public SM2 key.
(pubkey/load-sm2-sec1 curve sec1)`sec1` is a byte string.Return a public SM2 key.
(pubkey/to-raw pubkey)Return the unencrypted canonical raw encoding of the public key. This might not be defined for all key types.
(rng/add-entropy rng-obj seed)Adds the provided `seed` array or tuple to the `rng`. Returns `rng-obj`.
(rng/get rng-obj len)Returns random bytes of length `len` from a random number generator `rng-obj`.
(rng/get-with-input rng-obj len addl-input)Returns `len` random bytes from `rng-obj`. For a DRBG, the additional input is mixed in before generating. Other RNG types (e.g. system RNG, RDRAND) ignore `addl-input`.
(rng/new &opt type)Initialize a random number generator from the given `type`:
(rng/new-drbg name seed)Initialize a deterministic random bit generator (DRBG) of the given `name` (e.g. "HMAC_DRBG(SHA-256)") seeded with `seed`. The seed is interpreted as `entropy || nonce || personalization_string`. Returns `rng-obj`.
(rng/reseed rng-obj bits)Reseeds the random number generator `rng` with bits number of `bits` from the System-RNG. Returns `rng-obj`.
(rng/reseed-from-rng rng-obj src bits)Reseeds the random number generator `rng` with bits number of `bits` taken from given the source rng `src`. Returns `rng-obj`.
(scrypt out-len password salt &opt N r p)Runs Scrypt key derivation function over the specified password and salt using Scrypt parameters N, r, p. If omitted, the default values of N=1024, r=8, p=8 are used.
(spake2p-derive-secret spake2p-params-obj password prover-id verifier-id salt)Derive a SPAKE2+ (RFC 9383) prover secret from a password, using Argon2id. The returned secret is password equivalent, and must be protected accordingly. It is used with `spake2p-registration-record` and `spake2p-prover/new`.
(spake2p-params/confirmation-size spake2p-params-obj)Return the size in bytes of a SPAKE2+ key confirmation message (confirmP or confirmV).
(spake2p-params/new ciphersuite)Creates a new SPAKE2+ system parameters object from an RFC 9383 `ciphersuite` name, one of "P256-SHA256", "P256-SHA512", "P384-SHA256", "P384-SHA512" or "P521-SHA512". Returns `spake2p-params-obj`.
(spake2p-params/new-custom ec-group-obj seed hash)Creates a new SPAKE2+ system parameters object for an arbitrary group. `seed` is a byte string from which the M/N group elements are derived using hash to curve, which not all groups support. `hash` is a hash function name (e.g., "SHA-256"). Both peers must use the same group, seed and hash. Returns `spake2p-params-obj`.
(spake2p-params/share-size spake2p-params-obj)Return the size in bytes of a SPAKE2+ key share (shareP or shareV).
(spake2p-prover/generate-message spake2p-prover-obj &opt rng)Generate the prover's key share, which is sent to the verifier. Can be called only once. New rng is used by default, if `rng` is not provided.
(spake2p-prover/new spake2p-params-obj secret prover-id verifier-id context)Creates a SPAKE2+ prover, the side which knows the password. `secret` is the prover secret from `spake2p-derive-secret`. The identities and context must be agreed upon by both parties. Returns `spake2p-prover-obj`.
(spake2p-prover/process-message spake2p-prover-obj peer-message &opt rng)Consume the verifier's response and return the prover's key confirmation, which is sent to the verifier. Returns nil if the verifier's key confirmation is wrong, typically meaning the passwords do not match. New rng is used by default, if `rng` is not provided.
(spake2p-prover/shared-secret spake2p-prover-obj)Return the shared secret. Only valid after `spake2p-prover/process-message` succeeded.
(spake2p-registration-record spake2p-params-obj secret &opt rng)Compute a SPAKE2+ registration record from a prover secret. The registration record is provided to the verifier during registration. New rng is used by default, if `rng` is not provided.
(spake2p-verifier/new spake2p-params-obj record prover-id verifier-id context)Creates a SPAKE2+ verifier, the side which stores only the registration record derived from the password. `record` is the registration record from `spake2p-registration-record`. The identities and context must be agreed upon by both parties. Returns `spake2p-verifier-obj`.
(spake2p-verifier/process-message spake2p-verifier-obj peer-message &opt rng)Consume the prover's key share and return the verifier's response (its own key share followed by a key confirmation), which is sent to the prover. Can be called only once. New rng is used by default, if `rng` is not provided.
(spake2p-verifier/shared-secret spake2p-verifier-obj)Return the shared secret. Only valid after `spake2p-verifier/verify-confirmation` succeeded, or after `spake2p-verifier/skip-confirmation`.
(spake2p-verifier/skip-confirmation spake2p-verifier-obj)Skip checking the prover's key confirmation, allowing `spake2p-verifier/shared-secret` to be called without `spake2p-verifier/verify-confirmation`. After calling this, no evidence has been received that the peer knows the password; it is intended solely for protocols which embed SPAKE2+ and perform the prover's key confirmation themselves. Returns `spake2p-verifier-obj`.
(spake2p-verifier/verify-confirmation spake2p-verifier-obj confirmation)Check the prover's key confirmation. Returns false if the confirmation is wrong, meaning the prover does not know the password.
(srp6-client-agree username password group-id hash salt B &opt rng)The client receives these parameters from the server, except for the `username` and `password` which are provided by the user. The parameter B is the output of step1.
The client agreement step outputs a shared symmetric key along with the parameter A which is returned to the server (and allows it the compute the shared key).
(srp6-generate-verifier identifier password salt group-id hash)Generates a new verifier using the specified `password` and `salt`. This is stored by the server. The salt must also be stored. Later, the given username(`identifier`) and `password` are used to by the client during the key agreement step.
(srp6-server-session/new group-id)Create srp6 server session object along with `group-id`.
(srp6-server-session/step1 srp6-obj verifier hash rng)Takes a verifier (generated by srp6-generate-verifier) along with the group-id, and output a value B which is provided to the client.
(srp6-server-session/step2 srp6-obj A)Takes the parameter A generated by srp6-client-agree, and return the shared secret key.
In the event of an impersonation attack (or wrong username/password, etc) no error occurs, but the key returned will be different on the two sides. The two sides must verify each other, for example by using the shared secret to key an HMAC and then exchanging authenticated messages.
(totp/check totp-obj code &opt timestamp acceptable-drift)Return true if the provided OTP `code` is correct for the provided `timestamp`. If required, use clock `acceptable-drift` to deal with the client and server having slightly different clocks. If omitted, current timestamp is used for `timestamp` and the default value for `acceptable-drift` is 0.
(totp/generate totp-obj &opt timestamp)Generate an TOTP code for the provided `timestamp`. If omitted, current timestamp is used.
(totp/new key &opt hash digits timestep)Instantiate a new TOTP instance with the given parameters. If omitted, the default value for `hash` is "SHA-1", the default value for `digits` is 6 and the default value for `timestep` is 30. Returns `totp-obj`.
(version-datestamp)Returns the date this version was released as an integer YYYYMMDD,or 0 if an unreleased version.
(x509-cert/allowed-ext-usage cert-obj oid)Check if the certificate allows the specified extended usage OID. The `oid` parameter can be either a canonical OID string or identifiers like "PKIX.ServerAuth", "PKIX.ClientAuth", "PKIX.CodeSigning", "PKIX.OCSPSigning". Returns true if the certificate allows the usage.
(x509-cert/allowed-usage cert-obj cert-usage)Test if the certificate is allowed for a particular usage. The cert-usage argument should be one of the following keywords:
(x509-cert/authority-key-id cert-obj)Return the authority key ID set in the certificate, which may be empty.
(x509-cert/create-self-signed key &keys {:rng rng :hash hash :expire-time expire-time :is-ca is-ca :CN cn :C c :O o :OU ou :ST st :L l :email email :dns dns :ip ip :uri uri :serial-number serial-number :key-usage key-usage :ext-key-usage ext-key-usage})Create a self-signed X.509 certificate.
(x509-cert/dup cert-obj)Create a new object that refers to the same certificate.
(x509-cert/ext-as-blocks-asnum cert-obj)Get the AS numbers from the AS Blocks extension.
Returns :inherit if the AS numbers are inherited from the issuer, or nil if the extension or the field is absent. Otherwise returns a tuple of [min max] ranges, for example [[0 999] [65536 65551]].
(x509-cert/ext-as-blocks-rdi cert-obj)Get the routing domain identifiers from the AS Blocks extension. Returns :inherit if the identifiers are inherited from the issuer, or nil if the extension or the field is absent. Otherwise returns a tuple of [min max] ranges, for example [[0 999] [65536 65551]].
(x509-cert/ext-ip-addr-blocks cert-obj)Get values from the IP Address Blocks extension.
Returns a tuple of address families, or nil if the extension is absent. Each family is a struct with the following keys:
(x509-cert/fingerprint cert-obj &opt hash-algo)Return a fingerprint for the certificate, which is basically just a hash of the binary contents. Normally "SHA-1" or "SHA-256" is used, but any hash function is allowed. If omitted, "SHA-256" is used.
(x509-cert/hostname-match cert-obj hostname)Return true if the certificate matches a given `hostname`. If SAN DNS entries are present, only those are checked. Otherwise falls back to Common Name (CN). Supports wildcard matching.
(x509-cert/is-ca cert-obj)Return true if the certificate is a CA certificate.
(x509-cert/issue subject-key ca-cert ca-key not-before not-after &keys {:rng rng :hash hash :is-ca is-ca :CN cn :C c :O o :OU ou :ST st :L l :email email :dns dns :ip ip :uri uri :serial-number serial-number :key-usage key-usage :ext-key-usage ext-key-usage})Issue a new X.509 certificate signed by a CA.
(x509-cert/issuer-dn cert-obj key &opt index)Get a value from the issuer DN field. `key` is one of :CN, :C, :O, :OU, :ST, :L, :serial-number. If `index` is given, returns the value at that zero-based index. If omitted, returns a tuple of all values for that field.
(x509-cert/load blob)Load an X.509 certificate from the DER or PEM encoded `blob`.
(x509-cert/not-after cert-obj)Return the time the certificate expires, as seconds since epoch.
(x509-cert/not-before cert-obj)Return the time the certificate becomes valid, as seconds since epoch.
(x509-cert/san cert-obj type &opt index)Get a value from the Subject Alternative Name extension. `type` is one of :dns, :email, :uri, :ip. If `index` is given, returns the value at that zero-based index (nil if not found). If omitted, returns a tuple of all values for that type.
(x509-cert/serial-number cert-obj)Return the serial number of the certificate.
(x509-cert/subject-dn cert-obj key &opt index)Get a value from the subject DN field. `key` is one of :CN, :C, :O, :OU, :ST, :L, :serial-number. If `index` is given, returns the value at that zero-based index. If omitted, returns a tuple of all values for that field.
(x509-cert/subject-key-id cert-obj)Return the subject key ID set in the certificate, which may be empty.
(x509-cert/subject-public-key cert-obj)Get the public key included in this certificate as an object of `pubkey`.
(x509-cert/subject-public-key-bits cert-obj)Get the serialized representation of the public key included in this certificate.
(x509-cert/to-string cert-obj)Return a free-form string representation of this certificate
(x509-cert/validation-status error-code)Return an informative string explaining the verification return code.
(x509-cert/verify cert-obj &keys {:intermediates intermediates :trusted trusted :trusted-path trusted-path :required-strength required-strength :hostname hostname :reference-time reference-time :crls crls})Verify a certificate. Returns 0 if validation was successful, returns a positive error code if the validation was unsuccessful.
(x509-crl-entry/create cert reason)Create a CRL entry for the given certificate with a revocation reason.
(x509-crl-entry/reason crl-entry)Return the revocation reason code for the CRL entry.
0: Unspecified
1: Key Compromise
2: CA Compromise
3: Affiliation Changed
4: Superseded
5: Cessation of Operation
6: Certificate Hold
8: Remove from CRL
9: Privilege Withdrawn
10: AA Compromise
(x509-crl-entry/revocation-date crl-entry)Return the revocation date as seconds since epoch.
(x509-crl-entry/serial-number crl-entry)Return the serial number of the revoked certificate.
(x509-crl/create ca-cert ca-key issue-time next-update &keys {:rng rng :hash hash :padding padding})Create a new empty CRL signed by the given CA.
(x509-crl/entries-count crl-obj)Return the number of entries in the CRL.
(x509-crl/get-entry crl-obj index)Return the CRL entry at the given `index`. Use `x509-crl/entries-count` to get the number of entries.
(x509-crl/is-revoked crl-obj cert-obj)Check if the given `cert-obj` is revoked on the given `crl-obj`. Return true when the certificate is revoked.
(x509-crl/next-update crl-obj)Return the time the next CRL update is expected, as seconds since epoch. Return `nil` if the CRL has no nextUpdate field, which is optional.
(x509-crl/revoke crl ca-cert ca-key issue-time next-update entries &keys {:rng rng :hash hash :padding padding})Update a CRL with new revoked entries, creating a new CRL. The original CRL is not modified.
(x509-crl/this-update crl-obj)Return the time the CRL was issued, as seconds since epoch.
(x509-crl/verify crl-obj pubkey)Verify the CRL signature against the given public key. Returns true if the signature is valid.
(xof/accepts-input xof-obj)Return true if the XOF is still accepting input bytes. Typically, XOFs don't accept input as soon as the first output bytes were requested.
(xof/copy xof-obj)Return a new XOF object copied from `xof-obj`. Returns new `xof-obj`.
(xof/new name)Creates a XOF of the given name, e.g., "SHAKE-128", "Ascon-XOF128". Returns `xof-obj`.
(xof/output xof-obj out-len)Generate `out-len` bytes of output from the XOF and return the output.
(zfec-decode k n indexes inputs)Decode some FEC shares. `k` is the number of shares required to recover the original. `n` is the total number of shares. The `indexes` is the list that specifies which shares are present in `inputs`. `inputs` is the list of the input shares (e.g. from a previous call to `zfec-encode`) which all must be the same length. Return a list of strings containing the original shares decoded from the provided shares (in `inputs`).
(zfec-encode k n input)Perform forward error correction encoding. `k` is the number of shares required to recover the original. `n` is the total number of shares. The `input` length must be a multiple of `k` bytes. Return a list of `n` strings, each one containing a single share.