Skip to main content

Cipher

Enum Cipher 

Source
#[non_exhaustive]
pub enum Cipher { None, Aes128Cbc, Aes192Cbc, Aes256Cbc, Aes128Ctr, Aes192Ctr, Aes256Ctr, Aes128Gcm, Aes256Gcm, ChaCha20Poly1305, TdesCbc, }
Expand description

Cipher algorithms.

A “cipher” within the scope of SSH was originally described in RFC4253 § 6.3 as a part of of the packet encryption protocol, where it refers to the combination of a symmetric block cipher, such as AES or 3DES, with a particular mode of operation, such as CBC or CTR.

This has been subsequently expanded by other standards documents, and now includes modern authenticated or “AEAD” modes such as AES-GCM and ChaCha20Poly1305, which we recommend and are marked with a ✅ in the table below.

Below is a table of the ciphers we support and what standards document defines them, along with which crate feature needs to be enabled to perform encryption with a given algorithm:

Cipher nameFeatureAEADAlgorithmStandard
3des-cbctdes3DES-CBCRFC4253 § 6.3
aes128‑cbcaesAES-128-CBCRFC4253 § 6.3
aes192‑cbcaesAES-192-CBCRFC4253 § 6.3
aes256‑cbcaesAES-256-CBCRFC4253 § 6.3
aes128‑ctraesAES-128-CTRRFC4344
aes192‑ctraesAES-192-CTRRFC4344
aes256‑ctraesAES-256-CTRRFC4344
aes128‑gcm@openssh.comaesAES-128-GCMRFC5647
aes256‑gcm@openssh.comaesAES-256-GCMRFC5647
chacha20‑poly1305@openssh.comchacha20poly1305ChaCha20Poly1305†PROTOCOL.chacha20poly1305

† The construction called “ChaCha20Poly1305” as used by OpenSSH is different from other constructions with that name including the one defined in RFC8439 and the one found in NaCl variants like libsodium. See ChaCha20Poly1305 for more information.

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

None

none: no cipher.

§

Aes128Cbc

aes128-cbc: AES-128 in cipher block chaining (CBC) mode.

§

Aes192Cbc

aes192-cbc: AES-192 in cipher block chaining (CBC) mode.

§

Aes256Cbc

aes256-cbc: AES-256 in cipher block chaining (CBC) mode.

§

Aes128Ctr

aes128-ctr: AES-128 in counter (CTR) mode.

§

Aes192Ctr

aes192-ctr: AES-192 in counter (CTR) mode.

§

Aes256Ctr

aes256-ctr: AES-256 in counter (CTR) mode.

§

Aes128Gcm

aes128-gcm@openssh.com: AES-128 in Galois/Counter Mode (GCM).

§

Aes256Gcm

aes256-gcm@openssh.com: AES-256 in Galois/Counter Mode (GCM).

§

ChaCha20Poly1305

chacha20-poly1305@openssh.com: ChaCha20-Poly1305

§

TdesCbc

3des-cbc: TripleDES in block chaining (CBC) mode

Implementations§

Source§

impl Cipher

Source

pub fn new(ciphername: &str) -> Result<Self, LabelError>

Decode cipher algorithm from the given ciphername.

§Supported cipher names
  • aes128-cbc
  • aes192-cbc
  • aes256-cbc
  • aes128-ctr
  • aes192-ctr
  • aes256-ctr
  • aes128-gcm@openssh.com
  • aes256-gcm@openssh.com
  • chacha20-poly1305@openssh.com
  • 3des-cbc
§Errors

Returns LabelError if the provided ciphername is unknown.

Source

pub fn as_str(self) -> &'static str

Get the string identifier which corresponds to this algorithm.

Source

pub fn key_and_iv_size(self) -> Option<(usize, usize)>

Get the key and IV size for this cipher in bytes.

Source

pub fn block_size(self) -> usize

Get the block size for this cipher in bytes.

Source

pub fn padding_len(self, input_size: usize) -> usize

Compute the length of padding necessary to pad the given input to the block size.

Source

pub fn has_tag(self) -> bool

Does this cipher have an authentication tag? (i.e. is it an AEAD mode?)

Source

pub fn is_none(self) -> bool

Is this cipher none?

Source

pub fn is_some(self) -> bool

Is the cipher anything other than none?

Source

pub fn decrypt( self, key: &[u8], iv: &[u8], buffer: &mut [u8], tag: Option<Tag>, ) -> Result<()>

Decrypt the ciphertext in the buffer in-place using this cipher.

§Errors

Returns Error::Length in the event that buffer is not a multiple of the cipher’s block size.

Source

pub fn decryptor<C>(self, key: &[u8], iv: &[u8]) -> Result<Decryptor<C>>
where C: BlockCipher,

Available on crate features aes or tdes only.

Get a stateful block_cipher::Decryptor for the given key and IV.

Only applicable to unauthenticated modes (e.g. AES-CBC, AES-CTR). Not usable with authenticated modes which are inherently one-shot (AES-GCM, ChaCha20Poly1305).

§Errors

Propagates errors from block_cipher::Decryptor::new.

Source

pub fn encrypt( self, key: &[u8], iv: &[u8], buffer: &mut [u8], ) -> Result<Option<Tag>>

Encrypt the ciphertext in the buffer in-place using this cipher.

§Errors

Returns Error::Length in the event that buffer is not a multiple of the cipher’s block size.

Source

pub fn encryptor<C>(self, key: &[u8], iv: &[u8]) -> Result<Encryptor<C>>
where C: BlockCipher,

Available on crate features aes or tdes only.

Get a stateful block_cipher::Encryptor for the given key and IV.

Only applicable to unauthenticated modes (e.g. AES-CBC, AES-CTR). Not usable with authenticated modes which are inherently one-shot (AES-GCM, ChaCha20Poly1305).

§Errors

Propagates errors from block_cipher::Encryptor::new.

Trait Implementations§

Source§

impl AsRef<str> for Cipher

Source§

fn as_ref(&self) -> &str

Converts this type into a shared reference of the (usually inferred) input type.
Source§

impl Clone for Cipher

Source§

fn clone(&self) -> Cipher

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Cipher

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for Cipher

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl FromStr for Cipher

Source§

type Err = LabelError

The associated error which can be returned from parsing.
Source§

fn from_str(ciphername: &str) -> Result<Self, LabelError>

Parses a string s to return a value of this type. Read more
Source§

impl Hash for Cipher

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl Ord for Cipher

Source§

fn cmp(&self, other: &Cipher) -> Ordering

This method returns an Ordering between self and other. Read more
1.21.0 (const: unstable) · Source§

fn max(self, other: Self) -> Self
where Self: Sized,

Compares and returns the maximum of two values. Read more
1.21.0 (const: unstable) · Source§

fn min(self, other: Self) -> Self
where Self: Sized,

Compares and returns the minimum of two values. Read more
1.50.0 (const: unstable) · Source§

fn clamp(self, min: Self, max: Self) -> Self
where Self: Sized,

Restrict a value to a certain interval. Read more
Source§

impl PartialEq for Cipher

Source§

fn eq(&self, other: &Cipher) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl PartialOrd for Cipher

Source§

fn partial_cmp(&self, other: &Cipher) -> Option<Ordering>

This method returns an ordering between self and other values if one exists. Read more
1.0.0 (const: unstable) · Source§

fn lt(&self, other: &Rhs) -> bool

Tests less than (for self and other) and is used by the < operator. Read more
1.0.0 (const: unstable) · Source§

fn le(&self, other: &Rhs) -> bool

Tests less than or equal to (for self and other) and is used by the <= operator. Read more
1.0.0 (const: unstable) · Source§

fn gt(&self, other: &Rhs) -> bool

Tests greater than (for self and other) and is used by the > operator. Read more
1.0.0 (const: unstable) · Source§

fn ge(&self, other: &Rhs) -> bool

Tests greater than or equal to (for self and other) and is used by the >= operator. Read more
Source§

impl Copy for Cipher

Source§

impl Eq for Cipher

Source§

impl Label for Cipher

Source§

impl StructuralPartialEq for Cipher

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> Decode for T
where T: Label,

Source§

type Error = Error

Type returned in the event of a decoding error.
Source§

fn decode(reader: &mut impl Reader) -> Result<T, Error>

Attempt to decode a value of this type using the provided Reader. Read more
Source§

impl<T> Encode for T
where T: Label,

Source§

fn encoded_len(&self) -> Result<usize, Error>

Get the length of this type encoded in bytes, prior to Base64 encoding. Read more
Source§

fn encode(&self, writer: &mut impl Writer) -> Result<(), Error>

Encode this value using the provided Writer. Read more
Source§

fn encoded_len_prefixed(&self) -> Result<usize, Error>

Return the length of this type after encoding when prepended with a uint32 length prefix. Read more
Source§

fn encode_prefixed(&self, writer: &mut impl Writer) -> Result<(), Error>

Encode this value, first prepending a uint32 length prefix set to Encode::encoded_len. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.