import { ErrorResult, Micro509Error } from "../result/result.js"; //#region src/pkcs/pkcs12-mac.d.ts /** Input for {@linkcode createPkcs12MacData}. */ interface Pkcs12MacOptions { /** Password used to derive the HMAC key via the PKCS#12 KDF. */ readonly password: string; /** PKCS#12 KDF iteration count. Default: `2048`. */ readonly iterations?: number; /** Random salt. Default: 16 cryptographically random bytes. */ readonly salt?: Uint8Array; } /** Decoded PKCS#12 MacData block returned by {@linkcode parsePkcs12MacData}. */ interface ParsedPkcs12MacData { /** OID of the digest algorithm (currently always SHA-256). */ readonly digestAlgorithmOid: string; /** Human-readable digest algorithm name (currently `"SHA-256"`). */ readonly digestAlgorithmName: string; /** Hex-encoded MAC digest value. */ readonly digestHex: string; /** Hex-encoded salt bytes used during key derivation. */ readonly saltHex: string; /** Number of PKCS#12 KDF iterations. */ readonly iterations: number; /** * MAC verification outcome: `'unchecked'` when no password was supplied * during parsing, otherwise `'valid'` or `'invalid'`. */ readonly verification: "valid" | "invalid" | "unchecked"; } /** * Computes a PKCS#12 HMAC-SHA-256 MAC over the AuthenticatedSafe and returns * the DER-encoded MacData block alongside its parsed representation. */ declare function createPkcs12MacData(authenticatedSafe: Uint8Array, options: Pkcs12MacOptions): Promise<{ /** DER-encoded MacData SEQUENCE. */ readonly der: Uint8Array; /** Structured representation of the MAC parameters and digest. */ readonly parsed: ParsedPkcs12MacData; }>; /** Machine-readable failure reason for {@linkcode parsePkcs12MacData}. */ type ParsePkcs12MacDataErrorCode = "malformed"; /** Structured failure payload for MacData parsing. */ interface ParsePkcs12MacDataFailure extends Micro509Error { /** Always `false` for failures. */ readonly ok: false; } /** Success-or-failure result from {@linkcode parsePkcs12MacData}. */ type ParsePkcs12MacDataResult = { readonly ok: true; readonly value: ParsedPkcs12MacData; } | ErrorResult, ParsePkcs12MacDataFailure>; /** * Throwing core for {@linkcode parsePkcs12MacData}. When `password` is * provided, verifies the MAC and reports the outcome in `verification`. */ declare function parsePkcs12MacDataOrThrow(der: Uint8Array, authenticatedSafe: Uint8Array, password?: string): Promise; /** * Decodes a DER-encoded MacData block. When `password` is provided, verifies * the MAC and reports the outcome in `verification`. * * Returns a typed failure (`code: 'malformed'`) on malformed input. For the * throwing form use {@linkcode parsePkcs12MacDataOrThrow}. */ declare function parsePkcs12MacData(der: Uint8Array, authenticatedSafe: Uint8Array, password?: string): Promise; //#endregion export { ParsePkcs12MacDataErrorCode, ParsePkcs12MacDataFailure, ParsePkcs12MacDataResult, ParsedPkcs12MacData, Pkcs12MacOptions, createPkcs12MacData, parsePkcs12MacData, parsePkcs12MacDataOrThrow }; //# sourceMappingURL=pkcs12-mac.d.ts.map