PenguinConverters.CandyStore 3.3.5

dotnet add package PenguinConverters.CandyStore --version 3.3.5
                    
NuGet\Install-Package PenguinConverters.CandyStore -Version 3.3.5
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="PenguinConverters.CandyStore" Version="3.3.5" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="PenguinConverters.CandyStore" Version="3.3.5" />
                    
Directory.Packages.props
<PackageReference Include="PenguinConverters.CandyStore" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add PenguinConverters.CandyStore --version 3.3.5
                    
#r "nuget: PenguinConverters.CandyStore, 3.3.5"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package PenguinConverters.CandyStore@3.3.5
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=PenguinConverters.CandyStore&version=3.3.5
                    
Install as a Cake Addin
#tool nuget:?package=PenguinConverters.CandyStore&version=3.3.5
                    
Install as a Cake Tool

PenguinConverters.CandyStore

The native-interop boundary between managed .NET and the Rust engine. CandyStore is the single managed assembly that P/Invokes keyra_ffi (the Rust cdylib); it binds to the crypto implemented in Rust, it does not implement crypto itself.

Overview

┌──────────────────────────────────────────────────────────────┐
│                    CandyStore (net8.0)                        │
│                    platform-agnostic                          │
├──────────────────────────────────────────────────────────────┤
│                                                              │
│  FFI binding + engine facade          BCL helpers           │
│  ┌────────────────────────────┐   ┌──────────────────────┐  │
│  │ KeyraFfiNative  (P/Invoke) │   │ Crypto               │  │
│  │ KeyraNativeCrypto          │   │  (X509 self-signed   │  │
│  │ KeyraEngine (load/ABI gate)│   │   cert creation)     │  │
│  │ KeyraVaultSession (handle) │   │ KeystrokeEntropy-    │  │
│  │ KeyraSecretCipher          │   │  Collector           │  │
│  │ AesGcmCrypto (facade)      │   └──────────────────────┘  │
│  └─────────────┬──────────────┘                             │
└────────────────┼─────────────────────────────────────────────┘
                 │ P/Invoke (single boundary)
                 ▼
        ┌────────────────────────┐
        │  keyra_ffi (Rust cdylib)│   AES-GCM, Argon2id, HMAC,
        │                        │   SHA-256, HKDF, KDF recipes,
        │                        │   keystore, secretstore,
        │                        │   git, hosting, engine
        └────────────────────────┘

Package Information

Property Value
Package ID PenguinConverters.CandyStore
Target Framework net8.0
Platform Platform-agnostic (binds to the Rust cdylib)
Project references None (graph leaf — P/Invokes keyra_ffi only)

No Windows-native crypto here. DPAPI-NG / CNG / BCrypt / NCrypt interop lives in the KeyStorageProvider.DpapiNg provider (net8.0-windows), not in CandyStore. CandyStore was previously described as hosting that interop; it no longer does — those files moved to the DpapiNg provider, and CandyStore stays net8.0/agnostic.

Components

FFI binding & engine facade

Class Purpose
KeyraFfiNative (Native/) The one P/Invoke surface to keyra_ffi. Loads via an explicit, ACL-protected path (NativeLibrary.SetDllImportResolver), not ambient PATH/CWD.
KeyraEngine Engine gate: loads the cdylib and enforces the ABI-version handshake (refuses to proceed on mismatch). Hosts the EngineMode (Dotnet/Shadow/Rust) switch.
KeyraNativeCrypto Thin managed wrappers over the FFI: AES-GCM, keystore .key load/frame/unframe, secret/folder IO, the KDF recipe executor (RecipeExecute — the single derivation entry point), git, hosting. Byte-in/byte-out; the Rust side owns and zeroizes its intermediates.
KeyraVaultSession IDisposable wrapper over the opaque Rust vault-session handle. The master key never crosses to the managed heap.
KeyraSecretCipher AES-GCM cipher over an already-recovered master key (e.g. a DPAPI-NG key unwrapped in .NET).
AesGcmCrypto Thin AES-GCM encrypt/decrypt facade — delegates to the Rust engine.

Cross-platform BCL helpers

Class Purpose
Crypto X509 self-signed certificate creation (RSA.Create + CertificateRequest — cross-platform BCL).
KeystrokeEntropyCollector Collects keystroke-timing entropy (facade over the engine entropy pool).

Security notes

  • One boundary. CandyStore is the only managed assembly with P/Invoke into the engine; keyra-ffi is the only crate exposing extern "C". Nothing else crosses. See docs/interop.md.
  • ABI handshake. KeyraEngine calls keyra_ffi_abi_version() right after load and refuses to proceed on mismatch with its compiled-in expectation.
  • Secret ownership. Secret buffers are owned and zeroized on the Rust side; the managed side receives opaque handles or writes into fixed-size output buffers it owns — never a raw pointer to live key material on the managed heap.
  • Load-time integrity. The cdylib is native (cannot be strong-named); trust comes from code signing plus a constrained load from the install directory.

License

Proprietary — PenguinConverters

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net8.0

    • No dependencies.

NuGet packages (4)

Showing the top 4 NuGet packages that depend on PenguinConverters.CandyStore:

Package Downloads
PenguinConverters.Keyra.Core

Keyra domain layer: vault, folder, secret, and key contracts, provider and authentication abstractions, key derivation, and the export/import package model. Referenced by the Keyra SDK and every provider.

PenguinConverters.Keyra

Keyra developer SDK: load a vault key from a .keyra package, an armored share (KEYRA: ... :ARYEK), a key.json, or a vault directory, then encrypt and decrypt application secrets and configuration entries (Settings.Secret). Add a KeyStorageProvider package (DpapiNg or AesGcm) for provider-backed keys.

PenguinConverters.Keyra.KeyStorageProvider.DpapiNg

Keyra key storage provider for Windows DPAPI-NG (NCrypt): protects vault master keys with the Windows identity (domain or local SID). Windows-only by design; install alongside the Keyra SDK to open Windows / Active Directory vaults.

PenguinConverters.Keyra.KeyStorageProvider.AesGcm

Keyra key storage provider for password-derived AES-256-GCM keys (Argon2id KEK via the Rust engine). Cross-platform, no OS binding; install alongside the Keyra SDK for provider-backed portable keys.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
3.3.5 63 10/5/2026
3.3.3 115 10/4/2026
3.3.1 129 10/1/2026
3.3.0 145 9/28/2026
3.2.0 139 9/28/2026
3.1.2 142 9/23/2026
3.1.1.9 141 9/23/2026
3.1.1.8 137 9/22/2026
3.1.1 135 9/21/2026
3.0.0 149 9/11/2026
2.23.7 162 9/7/2026
2.23.5 156 9/7/2026
2.23.3 165 9/7/2026
2.22.0 177 9/1/2026
2.21.0 150 8/31/2026
2.20.0 143 8/31/2026
2.19.2 219 8/28/2026
2.19.0 278 8/19/2026
2.18.0 162 8/18/2026
2.17.0 168 8/17/2026