Skip to content

Embed salt and KDF parameters in new envelope format #29

@michaelmawhinney

Description

@michaelmawhinney

Parent: #19

Problem

The current API requires callers to store and supply a separate salt. Salt is not secret, but losing it makes ciphertext undecryptable and increases misuse risk.

Tasks

  • Embed salt in the new envelope format
  • Store KDF algorithm identifier
  • Store KDF opslimit
  • Store KDF memlimit
  • Ensure decrypt uses per-ciphertext KDF metadata
  • Add tests for non-default KDF parameters

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions