Delphi ActiveX Requires Chilkat v11.6.0+
Delphi ActiveX
Hash a Password with Argon2 (Tuned Options)
Demonstrates Crypt2.Argon2HashPassword with explicit options: the cost parameters, saltLen (how many random salt bytes to generate when no salt is given), and an optional secret (pepper).
Background. For hashing, the salt is optional — when omitted, a random salt of
saltLen bytes (default 16) is generated, which is the normal case. A secret or ad is not stored in the PHC string; the same values must be supplied to Argon2VerifyPassword for the password to verify.Chilkat Delphi ActiveX Downloads
var
crypt: TChilkatCrypt2;
password: WideString;
json: TChilkatJsonObject;
phcHash: WideString;
begin
crypt := TChilkatCrypt2.Create(Self);
// The password should come from a secure source rather than being hard-coded.
password := 'correct horse battery staple';
// The Argon2 options are the same members as Argon2DeriveKey, except the salt is optional for
// hashing. When no "salt" is given, a random salt is generated; "saltLen" (default 16, range 8..1024)
// sets how many random bytes to use.
json := TChilkatJsonObject.Create(Self);
json.UpdateString('variant','argon2id');
json.UpdateInt('memoryCostKb',131072);
json.UpdateInt('iterations',4);
json.UpdateInt('parallelism',2);
json.UpdateInt('saltLen',16);
// A secret (pepper) and/or ad may be used, but neither is stored in the returned PHC string. The
// same values must be supplied to Argon2VerifyPassword for the password to verify.
json.UpdateString('secret','application-wide-pepper');
json.UpdateString('secretEncoding','utf-8');
phcHash := crypt.Argon2HashPassword(password,json.Emit());
if (crypt.LastMethodSuccess = 0) then
begin
Memo1.Lines.Add(crypt.LastErrorText);
Exit;
end;
Memo1.Lines.Add(phcHash);