Commit dedba6ff authored by Niels Möller's avatar Niels Möller
Browse files

Minor fixes for chacha comments and docs.

parent 85a2b7f2
......@@ -103,7 +103,7 @@ chacha_crypt32(struct chacha_ctx *ctx,
++ctx->state[12];
/* stopping at 2^70 length per nonce is user's responsibility */
/* stopping at 2^38 length per nonce is user's responsibility */
if (length <= CHACHA_BLOCK_SIZE)
{
......
......@@ -3328,7 +3328,7 @@ defines a similar construction but with Salsa20 instead of ChaCha.
Nettle's implementation of ChaCha-Poly1305 follows @cite{RFC 8439},
where the ChaCha cipher is initialized with a 12-byte nonce and a 4-byte
block counter. This allows up to 256 gigabytes of data to be encrypted
using the same key.
using the same key and nonce.
For ChaCha-Poly1305, the ChaCha cipher is initialized with a key, of 256
bits, and a per-message nonce. The first block of the key stream
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment