Sample code for 30+ languages & platforms
Lianja

Manually Duplicate SetSecretKeyViaPassword

Demonstrates how to duplicate the password string to binary secret key computation of SetSecretKeyViaPassword.

This is a cryptographically weak way of generating a secret key from a password. The SetSecretKeyViaPassword method is deprecated and should not be used.

Chilkat Lianja Downloads

Lianja
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

loCrypt = createobject("CkCrypt2")

// The password string is transformed to a binary secret key by computing the 
// MD5 digest (of the utf-8 password) to obtain 16 bytes.  
// If the KeyLength is greater than 16 bytes, then the MD5 digest of the Base64 encoding 
// of the utf-8 password is added.  A max of 32 bytes of key material is generated, and 
// this is truncated to the actual KeyLength required.

loCrypt.CryptAlgorithm = "aes"
loCrypt.KeyLength = 256

lcPassword = "this is my password"
loCrypt.SetSecretKeyViaPassword(lcPassword)

// Examine the resulting SecretKey in hex:
? "Computed Secret Key = " + loCrypt.GetEncodedKey("hex")

// Now perform the same computation manually:
loSb = createobject("CkStringBuilder")

loCrypt.HashAlgorithm = "md5"
loCrypt.Charset = "utf-8"
loCrypt.EncodingMode = "hex"
loSb.Append(loCrypt.HashStringENC(lcPassword))

lcPasswordBase64 = loCrypt.EncodeString(lcPassword,"utf-8","base64")
loSb.Append(loCrypt.HashStringENC(lcPasswordBase64))

? "Manually Computed = " + loSb.GetAsString()

// The output is:
// Computed Secret Key = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36
// Manually Computed = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36


release loCrypt
release loSb