aesutil

package
v0.75.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: MIT Imports: 7 Imported by: 0

Documentation

Overview

Package aesutil provides authenticated AES-GCM encryption utilities, including writing and reading encrypted files.

Ciphertext is a random 96-bit nonce followed by the GCM-sealed data and its 16-byte authentication tag, so decryption detects tampering and wrong keys. Keys must be 16, 24, or 32 bytes (AES-128, AES-192, or AES-256), and a key must not encrypt more than 2^32 messages, to keep random nonce collisions negligible.

Before v0.75.0 this package used unauthenticated AES-CFB over a base64 encoding of the plaintext. Ciphertext produced by those versions cannot be decrypted by this version.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func DecryptAES added in v0.47.0

func DecryptAES(ciphertext []byte, key []byte) ([]byte, error)

DecryptAES decrypts ciphertext produced by EncryptAES. It returns an error if the ciphertext is truncated, was modified, or was encrypted under a different key. The ciphertext slice is not modified.

func DecryptAESBase58 added in v0.47.0

func DecryptAESBase58(ciphertext []byte, key []byte) ([]byte, error)

func DecryptAESBase58JSON added in v0.47.0

func DecryptAESBase58JSON(ciphertext []byte, key []byte, item any) error

func DecryptAESBase64String added in v0.47.0

func DecryptAESBase64String(ciphertextBase64 string, key []byte) ([]byte, error)

func EncryptAES added in v0.47.0

func EncryptAES(plaintext []byte, key []byte) ([]byte, error)

EncryptAES encrypts plaintext with AES-GCM under key, returning the nonce followed by the sealed ciphertext and authentication tag.

func EncryptAESBase58 added in v0.47.0

func EncryptAESBase58(plaintext []byte, key []byte) ([]byte, error)

func EncryptAESBase58JSON added in v0.47.0

func EncryptAESBase58JSON(plainitem any, key []byte) ([]byte, error)

func EncryptDirectoryFilesAES added in v0.47.0

func EncryptDirectoryFilesAES(dirUnc string, dirEnc string, perm os.FileMode, key []byte) error

func EncryptFileAES added in v0.47.0

func EncryptFileAES(filenameUnc string, filenameEnc string, perm os.FileMode, key []byte) error

func ReadFileAES added in v0.47.0

func ReadFileAES(filename string, key []byte) ([]byte, error)

func WriteFileAES added in v0.47.0

func WriteFileAES(filename string, baFileUnc []byte, perm os.FileMode, key []byte) error

Types

This section is empty.

Directories

Path Synopsis
cmd/aesargon command
aesecb provides ECB (Electronic Codebook) mode for AES.
aesecb provides ECB (Electronic Codebook) mode for AES.
aesopenssl implements AES that is compatible with `aes-256-cbc -salt`.
aesopenssl implements AES that is compatible with `aes-256-cbc -salt`.
cmd/aesopenssl command

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL