Sample code for 30+ languages & platforms
C

Manually Duplicate SetSecretKeyViaPassword

Demonstrates how to duplicate the password string to binary secret key computation of SetSecretKeyViaPassword.

This is a cryptographically weak way of generating a secret key from a password. The SetSecretKeyViaPassword method is deprecated and should not be used.

Chilkat C Downloads

C
#include <C_CkCrypt2.h>
#include <C_CkStringBuilder.h>

void ChilkatSample(void)
    {
    HCkCrypt2 crypt;
    const char *password;
    HCkStringBuilder sb;
    const char *passwordBase64;

    //  This example assumes the Chilkat API to have been previously unlocked.
    //  See Global Unlock Sample for sample code.

    crypt = CkCrypt2_Create();

    //  The password string is transformed to a binary secret key by computing the 
    //  MD5 digest (of the utf-8 password) to obtain 16 bytes.  
    //  If the KeyLength is greater than 16 bytes, then the MD5 digest of the Base64 encoding 
    //  of the utf-8 password is added.  A max of 32 bytes of key material is generated, and 
    //  this is truncated to the actual KeyLength required.

    CkCrypt2_putCryptAlgorithm(crypt,"aes");
    CkCrypt2_putKeyLength(crypt,256);

    password = "this is my password";
    CkCrypt2_SetSecretKeyViaPassword(crypt,password);

    //  Examine the resulting SecretKey in hex:
    printf("Computed Secret Key = %s\n",CkCrypt2_getEncodedKey(crypt,"hex"));

    //  Now perform the same computation manually:
    sb = CkStringBuilder_Create();

    CkCrypt2_putHashAlgorithm(crypt,"md5");
    CkCrypt2_putCharset(crypt,"utf-8");
    CkCrypt2_putEncodingMode(crypt,"hex");
    CkStringBuilder_Append(sb,CkCrypt2_hashStringENC(crypt,password));

    passwordBase64 = CkCrypt2_encodeString(crypt,password,"utf-8","base64");
    CkStringBuilder_Append(sb,CkCrypt2_hashStringENC(crypt,passwordBase64));

    printf("Manually Computed = %s\n",CkStringBuilder_getAsString(sb));

    //  The output is:
    //  Computed Secret Key = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36
    //  Manually Computed = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36


    CkCrypt2_Dispose(crypt);
    CkStringBuilder_Dispose(sb);

    }