//#region src/internal/crypto/pbes2.d.ts /** AES-CBC key sizes supported by this PBES2 implementation. */ type Pbes2EncryptionScheme = "AES-128-CBC" | "AES-192-CBC" | "AES-256-CBC"; /** PBKDF2 pseudo-random function choices. `HMAC-SHA-1` is the RFC default; `HMAC-SHA-256` is preferred. */ type Pbes2Prf = "HMAC-SHA-1" | "HMAC-SHA-256"; /** Input for `encryptPbes2`. */ interface Pbes2EncryptionOptions { /** Password fed to PBKDF2 for key derivation. */ readonly password: string; /** PBKDF2 iteration count. Default: `100_000`. */ readonly iterations?: number; /** PBKDF2 salt. Default: 16 cryptographically random bytes. */ readonly salt?: Uint8Array; /** AES-CBC initialization vector. Default: 16 cryptographically random bytes. */ readonly iv?: Uint8Array; /** AES-CBC cipher. Default: `'AES-256-CBC'`. */ readonly cipher?: Pbes2EncryptionScheme; /** PBKDF2 PRF. Default: `'HMAC-SHA-256'`. */ readonly prf?: Pbes2Prf; } /** Resolved PBES2 algorithm parameters, either parsed from DER or built by `encryptPbes2`. */ interface Pbes2Parameters { /** PBKDF2 iteration count. */ readonly iterations: number; /** PBKDF2 salt bytes. */ readonly salt: Uint8Array; /** AES-CBC initialization vector. */ readonly iv: Uint8Array; /** AES-CBC key-size variant. */ readonly cipher: Pbes2EncryptionScheme; /** PBKDF2 pseudo-random function. */ readonly prf: Pbes2Prf; } /** Decodes a DER-encoded PBES2 AlgorithmIdentifier into structured {@linkcode Pbes2Parameters}. */ declare function parsePbes2AlgorithmIdentifier(algorithmIdentifierDer: Uint8Array): Pbes2Parameters; //#endregion export { Pbes2EncryptionOptions, Pbes2EncryptionScheme, Pbes2Parameters, Pbes2Prf, parsePbes2AlgorithmIdentifier }; //# sourceMappingURL=pbes2.d.ts.map