Sample code for 30+ languages & platforms
Classic ASP

Manually Duplicate SetSecretKeyViaPassword

Demonstrates how to duplicate the password string to binary secret key computation of SetSecretKeyViaPassword.

This is a cryptographically weak way of generating a secret key from a password. The SetSecretKeyViaPassword method is deprecated and should not be used.

Chilkat Classic ASP Downloads

Classic ASP
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<%
' This example assumes the Chilkat API to have been previously unlocked.
' See Global Unlock Sample for sample code.

set crypt = Server.CreateObject("Chilkat.Crypt2")

' The password string is transformed to a binary secret key by computing the 
' MD5 digest (of the utf-8 password) to obtain 16 bytes.  
' If the KeyLength is greater than 16 bytes, then the MD5 digest of the Base64 encoding 
' of the utf-8 password is added.  A max of 32 bytes of key material is generated, and 
' this is truncated to the actual KeyLength required.

crypt.CryptAlgorithm = "aes"
crypt.KeyLength = 256

password = "this is my password"
crypt.SetSecretKeyViaPassword password

' Examine the resulting SecretKey in hex:
Response.Write "<pre>" & Server.HTMLEncode( "Computed Secret Key = " & crypt.GetEncodedKey("hex")) & "</pre>"

' Now perform the same computation manually:
set sb = Server.CreateObject("Chilkat.StringBuilder")

crypt.HashAlgorithm = "md5"
crypt.Charset = "utf-8"
crypt.EncodingMode = "hex"
success = sb.Append(crypt.HashStringENC(password))

passwordBase64 = crypt.EncodeString(password,"utf-8","base64")
success = sb.Append(crypt.HashStringENC(passwordBase64))

Response.Write "<pre>" & Server.HTMLEncode( "Manually Computed = " & sb.GetAsString()) & "</pre>"

' The output is:
' Computed Secret Key = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36
' Manually Computed = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36

%>
</body>
</html>