<?xml version="1.0" encoding="iso-8859-1"?>
<!-- $Revision: 1.2 $ -->
<section id="mcrypt.constants">
 &reftitle.constants;
 &extension.constants;
 <para>
  Mcrypt can operate in four block cipher modes (CBC, OFB, CFB, and
  ECB). If linked against libmcrypt-2.4.x or higher the functions can also operate
  in the block cipher mode nOFB and in STREAM mode. Below you find a list
  with all supported encryption modes together with the constants that are
  defines for the encryption mode.  For a more complete reference and
  discussion see &book.applied.cryptography;.
  <itemizedlist>
   <listitem>
    <simpara>
     MCRYPT_MODE_ECB (electronic codebook) is suitable for random data,
     such as encrypting other keys. Since data there is short and random,
     the disadvantages of ECB have a favorable negative effect.
    </simpara>
   </listitem>
   <listitem>
    <simpara>
     MCRYPT_MODE_CBC (cipher block chaining) is especially suitable for
     encrypting files where the security is increased over ECB
     significantly.
    </simpara>
   </listitem>
   <listitem>
    <simpara>
     MCRYPT_MODE_CFB (cipher feedback) is the best mode for encrypting byte
     streams where single bytes must be encrypted.
    </simpara>
   </listitem>
   <listitem>
    <simpara>
     MCRYPT_MODE_OFB (output feedback, in 8bit) is comparable to CFB, but
     can be used in applications where error propagation cannot
     be tolerated. It's insecure (because it operates in 8bit
     mode) so it is not recommended to use it.
    </simpara>
   </listitem>
   <listitem>
    <simpara>
     MCRYPT_MODE_NOFB (output feedback, in nbit) is comparable to OFB, but
     more secure because it operates on the block size of the algorithm.
    </simpara>
   </listitem> 
   <listitem>
    <simpara>
     MCRYPT_MODE_STREAM is an extra mode to include some stream algorithms
     like WAKE or RC4.
    </simpara>
   </listitem> 
  </itemizedlist>
 </para>

 <para>
  Some other mode and random device constants:
  <variablelist>
   <varlistentry>
    <term>
     <constant>MCRYPT_ENCRYPT</constant> 
     (<type>integer</type>)
    </term>
    <listitem>
     <simpara>
      
     </simpara>
    </listitem>
   </varlistentry>
   <varlistentry>
    <term>
     <constant>MCRYPT_DECRYPT</constant> 
     (<type>integer</type>)
    </term>
    <listitem>
     <simpara>
      
     </simpara>
    </listitem>
   </varlistentry>
   <varlistentry>
    <term>
     <constant>MCRYPT_DEV_RANDOM</constant> 
     (<type>integer</type>)
    </term>
    <listitem>
     <simpara>
      
     </simpara>
    </listitem>
   </varlistentry>
   <varlistentry>
    <term>
     <constant>MCRYPT_DEV_URANDOM</constant> 
     (<type>integer</type>)
    </term>
    <listitem>
     <simpara>
      
     </simpara>
    </listitem>
   </varlistentry>
   <varlistentry>
    <term>
     <constant>MCRYPT_RAND</constant> 
     (<type>integer</type>)
    </term>
    <listitem>
     <simpara>
      
     </simpara>
    </listitem>
   </varlistentry>
  </variablelist>
 </para>
</section>

<!-- Keep this comment at the end of the file
Local variables:
mode: sgml
sgml-omittag:t
sgml-shorttag:t
sgml-minimize-attributes:nil
sgml-always-quote-attributes:t
sgml-indent-step:1
sgml-indent-data:t
indent-tabs-mode:nil
sgml-parent-document:nil
sgml-default-dtd-file:"../../../manual.ced"
sgml-exposed-tags:nil
sgml-local-catalogs:nil
sgml-local-ecat-files:nil
End:
-->