Skip to content

Latest commit

 

History

History

README.md

Migration Guides

Switch crate-by-crate without hunting through the full API docs. This index covers 35 migration guides.

Each guide shows the smallest useful diff: dep change, import change, and call site change.

If you are evaluating rscrypto, start with the crate you already use. The guide will tell you whether the migration is a one-line replacement, a small API shape change, or not a good fit.

Checksums

From To Status
crc Crc16Ccitt, Crc16Ibm, Crc24OpenPgp, Crc32, Crc32C, Crc64, Crc64Nvme Verified against crc 3.4.0
crc-fast Crc32, Crc32C, Crc64, Crc64Nvme (catalogue subset) Verified against crc-fast 1.10.0
crc32fast Crc32 Output covered by CRC-32 oracle/property tests
crc32c Crc32C Output covered by CRC-32C oracle/property tests
crc64fast Crc64, Crc64Nvme (covers crc64fast-nvme aside) Verified against crc64fast 1.1.0; NVMe oracle coverage uses crc-fast 1.10.0

Hashes

From To Status
blake3 Blake3 Verified against blake3 1.8.5
sha2 (RustCrypto) Sha224, Sha256, Sha384, Sha512, Sha512_256 Verified against sha2 0.11.0
sha3 (RustCrypto) Sha3_224, Sha3_256, Sha3_384, Sha3_512, Shake128, Shake256, Cshake128, Cshake256 Verified against sha3 0.12.0
blake2 (RustCrypto) Blake2b256, Blake2b512, Blake2s128, Blake2s256 Verified against blake2 0.11.0-rc.6
ascon-hash (RustCrypto) AsconHash256, AsconXof, AsconCxof128 Verified against ascon-hash 0.4.0
xxhash-rust Xxh3, Xxh3_128, Xxh3Hasher, Xxh3_128Hasher, Xxh3BuildHasher Verified against xxhash-rust 0.8.16
twox-hash Xxh3, Xxh3_128, Xxh3Hasher, Xxh3_128Hasher, Xxh3BuildHasher API migration guidance; XXH3 output covered by xxhash-rust oracle tests
rapidhash RapidHash, RapidHash128, RapidStreamHasher, RapidHasher, RapidBuildHasher Verified against rapidhash 4.5.1

Auth (MAC + KDF)

From To Status
hmac (RustCrypto) HmacSha256, HmacSha384, HmacSha512, HmacSha3_224, HmacSha3_256, HmacSha3_384, HmacSha3_512 Verified against hmac 0.13.0 and RustCrypto SHA-3 digests
hkdf (RustCrypto) HkdfSha256, HkdfSha384, HkdfSha512 Verified against hkdf 0.13.0
pbkdf2 (RustCrypto) Pbkdf2Sha256, Pbkdf2Sha512 Verified against pbkdf2 0.13.0
sha3-kmac Kmac128, Kmac256 KMAC128/256 covered by NIST and tiny-keccak; KMAC256 also has Wycheproof coverage
tiny-keccak Kmac128, Kmac256, Cshake128, Cshake256 Verified against tiny-keccak 2.0.2

AEAD

From To Status
aes-gcm (RustCrypto) Aes128Gcm, Aes256Gcm Verified against aes-gcm 0.10.3
aes-gcm-siv (RustCrypto) Aes128GcmSiv, Aes256GcmSiv Verified against aes-gcm-siv 0.11.1
chacha20poly1305 (RustCrypto) ChaCha20Poly1305, XChaCha20Poly1305 Verified against chacha20poly1305 0.10.1
ascon-aead (RustCrypto) AsconAead128 Verified against ascon-aead 0.5.2
aegis Aegis256 Verified against aegis 0.9.12

Signatures + Key Exchange

From To Status
p256 / p384 (RustCrypto) EcdsaP256SecretKey, EcdsaP384SecretKey, EcdsaP256PublicKey, EcdsaP384PublicKey, raw/DER signatures Signing and verification tested against RustCrypto p256 0.14.0 / p384 0.13.1
ed25519-dalek Ed25519SecretKey, Ed25519PublicKey, Ed25519Signature, Ed25519Keypair Verified against ed25519-dalek 2.2.0
rsa (RustCrypto) RsaPublicKey, RsaPrivateKey, RSA-PSS, RSASSA-PKCS1-v1_5, OAEP Partial; verified through CAVP, Wycheproof, and RustCrypto/ring/OpenSSL oracles
x25519-dalek X25519SecretKey, X25519PublicKey, X25519SharedSecret Verified against x25519-dalek 2.0.1

Password Hashing

From To Status
argon2 (RustCrypto) Raw Argon2{d,i,id} KDFs; bounded Argon2idPassword records Verified against argon2 0.6.0-rc.8
scrypt (RustCrypto) Raw Scrypt KDF; bounded ScryptPassword records Verified against scrypt 0.12.0

Stack Migrations

From To Status
aws-lc-rs AEAD, SHA-2, HMAC, HKDF, PBKDF2, ECDSA, Ed25519, X25519, RSA verify Partial; shape-compatible surfaces only
aws-lc-sys none directly Not a direct migration; replace the safe wrapper API instead
dryoc Ed25519, X25519, BLAKE2, Argon2id/Argon2i-adjacent surfaces Partial; libsodium-style APIs are not one-to-one
ring AEAD, SHA-2, HMAC, HKDF, PBKDF2, ECDSA, Ed25519, RSA verify Partial; ring is protocol-shaped in several areas
openssl selected hash, MAC, AEAD, RSA operations Partial; rscrypto does not replace TLS, PKI, engines, or providers