diff --git a/base64-decode.c b/base64-decode.c
new file mode 100644
index 0000000000000000000000000000000000000000..e1e614de1ef7257765fafaf8ee085679cf55ce25
--- /dev/null
+++ b/base64-decode.c
@@ -0,0 +1,135 @@
+/* base64-encode.c
+ *
+ */
+
+/* nettle, low-level cryptographics library
+ *
+ * Copyright (C) 2002 Niels Möller
+ *  
+ * The nettle library is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU Lesser General Public License as published by
+ * the Free Software Foundation; either version 2.1 of the License, or (at your
+ * option) any later version.
+ * 
+ * The nettle library is distributed in the hope that it will be useful, but
+ * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
+ * or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU Lesser General Public
+ * License for more details.
+ * 
+ * You should have received a copy of the GNU Lesser General Public License
+ * along with the nettle library; see the file COPYING.LIB.  If not, write to
+ * the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
+ * MA 02111-1307, USA.
+ */
+
+#include "base64.h"
+
+#include <assert.h>
+#include <stdlib.h>
+
+#define TABLE_INVALID -1
+#define TABLE_SPACE -2
+#define TABLE_END -3
+
+static const signed char
+decode_table[0x100] =
+{
+  -1, -1, -1, -1, -1, -1, -1, -1, -1, -2, -2, -1, -1, -2, -1, -1, 
+  -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
+  -2, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, 62, -1, -1, -1, 63,
+  52, 53, 54, 55, 56, 57, 58, 59, 60, 61, -1, -1, -1, -3, -1, -1,
+  -1,  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14,
+  15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, -1, -1, -1, -1, -1,
+  -1, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40,
+  41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, -1, -1, -1, -1, -1,
+  -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
+  -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
+  -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
+  -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
+  -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
+  -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
+  -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
+  -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
+};
+
+void
+base64_decode_init(struct base64_decode_ctx *ctx)
+{
+  ctx->word = ctx->bits = 0;
+  ctx->status = BASE64_DECODE_OK;
+}
+
+unsigned
+base64_decode_update(struct base64_decode_ctx *ctx,
+		     uint8_t *dst,
+		     unsigned length,
+		     const uint8_t *src)
+{
+  unsigned done = 0;
+  unsigned i;
+  
+  if (ctx->status == BASE64_DECODE_ERROR)
+    return 0;
+
+  for (i = 0; i<length; i++)
+    {
+      int data = decode_table[src[i]];
+
+      switch(data)
+	{
+	default:
+	  assert(data >= 0 && data < 0x40);
+	  
+	  if (ctx->status != BASE64_DECODE_OK)
+	    goto invalid;
+	  
+	  ctx->word = ctx->word << 6 | data;
+	  ctx->bits += 6;
+
+	  if (ctx->bits >= 8)
+	    {
+	      ctx->bits -= 8;
+	      dst[done++] = ctx->word >> ctx->bits;
+	    }
+	  break;
+
+	case TABLE_INVALID:
+	invalid:
+	  ctx->status = BASE64_DECODE_ERROR;
+	  return done;
+
+	case TABLE_SPACE:
+	  /* Ignore */
+	  break;
+
+	case TABLE_END:
+	  if (!ctx->bits)
+	    goto invalid;
+	  if (ctx->word & ( (1<<ctx->bits) - 1))
+	    /* We shouldn't have any leftover bits */
+	    goto invalid;
+	  
+	  ctx->status = BASE64_DECODE_END;
+	  ctx->bits -= 2;
+	  break;
+	}
+    }
+
+  assert(done <= BASE64_DECODE_LENGTH(length));
+  
+  return done;
+}
+
+int
+base64_decode_status(struct base64_decode_ctx *ctx)
+{
+  switch (ctx->status)
+    {
+    case BASE64_DECODE_END:
+    case BASE64_DECODE_OK:
+      return ctx->bits == 0;
+    case BASE64_DECODE_ERROR:
+      return 0;
+    }
+  abort();
+}
diff --git a/base64-encode.c b/base64-encode.c
new file mode 100644
index 0000000000000000000000000000000000000000..13b625268e5273171d3b854f771b5f7391cd05b1
--- /dev/null
+++ b/base64-encode.c
@@ -0,0 +1,226 @@
+/* base64-encode.c
+ *
+ */
+
+/* nettle, low-level cryptographics library
+ *
+ * Copyright (C) 2002 Niels Möller
+ *  
+ * The nettle library is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU Lesser General Public License as published by
+ * the Free Software Foundation; either version 2.1 of the License, or (at your
+ * option) any later version.
+ * 
+ * The nettle library is distributed in the hope that it will be useful, but
+ * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
+ * or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU Lesser General Public
+ * License for more details.
+ * 
+ * You should have received a copy of the GNU Lesser General Public License
+ * along with the nettle library; see the file COPYING.LIB.  If not, write to
+ * the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston,
+ * MA 02111-1307, USA.
+ */
+
+#include "base64.h"
+
+#include <assert.h>
+#include <stdlib.h>
+
+
+static const uint8_t encode_table[64] =
+  "ABCDEFGHIJKLMNOPQRSTUVWXYZ"
+  "abcdefghijklmnopqrstuvwxyz"
+  "0123456789+/";
+
+#define ENCODE(x) (encode_table[0x3F & (x)])
+
+void
+base64_encode_raw(uint8_t *dst, unsigned length, const uint8_t *src)
+{
+  const uint8_t *in = src + length;;
+  uint8_t *out = dst + BASE64_ENCODE_RAW_LENGTH(length);
+
+  unsigned left_over = length % 3;
+
+  if (left_over)
+    {
+      in -= left_over;
+      *--out = '=';
+      switch(left_over)
+	{
+	case 1:
+	  *--out = '=';
+	  *--out = ENCODE(in[0] << 4);
+	  break;
+	  
+	case 2:
+	  *--out = ENCODE( in[1] << 2);
+	  *--out = ENCODE((in[0] << 4) | (in[1] >> 4));
+	  break;
+
+	default:
+	  abort();
+	}
+      *--out = ENCODE(in[0] >> 2);
+    }
+  
+  while (in > src)
+    {
+      in -= 3;
+      *--out = ENCODE( in[2]);
+      *--out = ENCODE((in[1] << 2) | (in[2] >> 6));
+      *--out = ENCODE((in[0] << 4) | (in[1] >> 4));
+      *--out = ENCODE( in[0] >> 2);      
+    }
+  assert(in == src);
+  assert(out == dst);
+}
+
+#if 0
+unsigned 
+base64_encode(uint8_t *dst,
+	      unsigned src_length,
+	      const uint8_t *src)
+{
+  unsigned dst_length = BASE64_ENCODE_RAW_LENGTH(src_length);
+  unsigned n = src_length / 3;
+  unsigned left_over  = src_length % 3;
+  unsigned done = 0;
+  
+  if (left_over)
+    {
+      const uint8_t *in = src + n * 3;
+      uint8_t *out = dst + dst_length;
+
+      switch(left_over)
+	{
+	case 1:
+	  *--out = '=';
+	  *--out = ENCODE(in[0] << 4);
+	  break;
+	  
+	case 2:
+	  *--out = ENCODE( in[1] << 2);
+	  *--out = ENCODE((in[0] << 4) | (in[1] >> 4));
+	  break;
+
+	default:
+	  abort();
+	}
+      *--out = ENCODE(in[0] >> 2);
+
+      done = 4;
+    }
+  base64_encode_raw(n, dst, src);
+  done += n * 4;
+
+  assert(done == dst_length);
+
+  return done;
+}
+#endif
+
+void
+base64_encode_group(uint8_t *dst, uint32_t group)
+{
+  *dst++ = ENCODE(group >> 18);
+  *dst++ = ENCODE(group >> 12);
+  *dst++ = ENCODE(group >> 6);
+  *dst++ = ENCODE(group);
+}
+
+void
+base64_encode_init(struct base64_encode_ctx *ctx)
+{
+  ctx->word = ctx->bits = 0;
+}
+
+/* Encodes a single byte. */
+unsigned
+base64_encode_single(struct base64_encode_ctx *ctx,
+		     uint8_t *dst,
+		     uint8_t src)
+{
+  unsigned done = 0;
+  unsigned word = ctx->word << 8 | src;
+  unsigned bits = ctx->bits + 8;
+  
+  while (bits >= 6)
+    {
+      bits -= 6;
+      dst[done++] = ENCODE(word >> bits);
+    }
+
+  ctx->bits = bits;
+  ctx->word = word;
+
+  assert(done <= 2);
+  
+  return done;
+}
+
+/* Returns the number of output characters. DST should point to an
+ * area of size at least BASE64_ENCODE_LENGTH(length). */
+unsigned
+base64_encode_update(struct base64_encode_ctx *ctx,
+		     uint8_t *dst,
+		     unsigned length,
+		     const uint8_t *src)
+{
+  unsigned done = 0;
+  unsigned left = length;
+  unsigned left_over;
+  unsigned bulk;
+  
+  while (ctx->bits && left)
+    {
+      left--;
+      done += base64_encode_single(ctx, dst + done, *src++);
+    }
+  
+  left_over = left % 3;
+  bulk = left - left_over;
+  
+  if (bulk)
+    {
+      assert(!(bulk % 3));
+      
+      base64_encode_raw(dst + done, bulk, src);
+      done += BASE64_ENCODE_RAW_LENGTH(bulk);
+      src += bulk;
+      left = left_over;
+    }
+
+  while (left)
+    {
+      left--;
+      done += base64_encode_single(ctx, dst + done, *src++);
+    }
+
+  assert(done <= BASE64_ENCODE_LENGTH(length));
+
+  return done;
+}
+
+/* DST should point to an area of size at least
+ * BASE64_ENCODE_FINAL_SIZE */
+unsigned
+base64_encode_final(struct base64_encode_ctx *ctx,
+		    uint8_t *dst)
+{
+  unsigned done = 0;
+  unsigned bits = ctx->bits;
+  
+  if (bits)
+    {
+      dst[done++] = ENCODE(ctx->word << (6 - ctx->bits));
+      for (; bits < 6; bits += 2)
+	dst[done++] = '=';
+
+      ctx->bits = 0;
+    }
+
+  assert(done <= BASE64_ENCODE_FINAL_LENGTH);
+  return done;
+}