pub fn lki_decrypt(enckey: &str, pass: &[u8]) -> LkResult<LkIdentity>
decrypt the result of lki_encrypt