Skip to main content

Module entropy

Module entropy 

Source
Expand description

Operating-system entropy acquisition.

IronCrypto never uses raw OS bytes as key material directly. The OS source is treated as the entropy input to an SP 800-90A DRBG (ic-drbg), which is the construction FIPS 140-3 expects. This module only has to deliver full-entropy bytes and fail loudly when it cannot.

Backends, chosen at compile time, with no third-party dependencies:

targetmechanism
WindowsBCryptGenRandom with the system-preferred RNG
Unix/dev/urandom
other / no_stdErrorKind::EntropyFailure

On a platform with no backend, supply your own entropy through Drbg::instantiate.

Structs§

OsEntropy
The system entropy source.

Functions§

fill
Fill out with bytes from the operating system entropy source.