Documentation
¶
Overview ¶
Package aesutil provides authenticated AES-GCM encryption utilities, including writing and reading encrypted files.
Ciphertext is a random 96-bit nonce followed by the GCM-sealed data and its 16-byte authentication tag, so decryption detects tampering and wrong keys. Keys must be 16, 24, or 32 bytes (AES-128, AES-192, or AES-256), and a key must not encrypt more than 2^32 messages, to keep random nonce collisions negligible.
Before v0.75.0 this package used unauthenticated AES-CFB over a base64 encoding of the plaintext. Ciphertext produced by those versions cannot be decrypted by this version.
Index ¶
- func DecryptAES(ciphertext []byte, key []byte) ([]byte, error)
- func DecryptAESBase58(ciphertext []byte, key []byte) ([]byte, error)
- func DecryptAESBase58JSON(ciphertext []byte, key []byte, item any) error
- func DecryptAESBase64String(ciphertextBase64 string, key []byte) ([]byte, error)
- func EncryptAES(plaintext []byte, key []byte) ([]byte, error)
- func EncryptAESBase58(plaintext []byte, key []byte) ([]byte, error)
- func EncryptAESBase58JSON(plainitem any, key []byte) ([]byte, error)
- func EncryptDirectoryFilesAES(dirUnc string, dirEnc string, perm os.FileMode, key []byte) error
- func EncryptFileAES(filenameUnc string, filenameEnc string, perm os.FileMode, key []byte) error
- func ReadFileAES(filename string, key []byte) ([]byte, error)
- func WriteFileAES(filename string, baFileUnc []byte, perm os.FileMode, key []byte) error
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func DecryptAES ¶ added in v0.47.0
DecryptAES decrypts ciphertext produced by EncryptAES. It returns an error if the ciphertext is truncated, was modified, or was encrypted under a different key. The ciphertext slice is not modified.
func DecryptAESBase58 ¶ added in v0.47.0
func DecryptAESBase58JSON ¶ added in v0.47.0
func DecryptAESBase64String ¶ added in v0.47.0
func EncryptAES ¶ added in v0.47.0
EncryptAES encrypts plaintext with AES-GCM under key, returning the nonce followed by the sealed ciphertext and authentication tag.
func EncryptAESBase58 ¶ added in v0.47.0
func EncryptAESBase58JSON ¶ added in v0.47.0
func EncryptDirectoryFilesAES ¶ added in v0.47.0
func EncryptFileAES ¶ added in v0.47.0
Types ¶
This section is empty.
Directories
¶
| Path | Synopsis |
|---|---|
|
cmd/aesargon
command
|
|
|
aesecb provides ECB (Electronic Codebook) mode for AES.
|
aesecb provides ECB (Electronic Codebook) mode for AES. |
|
aesopenssl implements AES that is compatible with `aes-256-cbc -salt`.
|
aesopenssl implements AES that is compatible with `aes-256-cbc -salt`. |
|
cmd/aesopenssl
command
|