SQL Server Requires Chilkat v11.6.0+
SQL Server
Verify a Password against an Argon2 Hash
Demonstrates Crypt2.Argon2VerifyPassword, which verifies a password against a PHC-format Argon2 hash string. The cost parameters are read from the hash string, so none need to be supplied.
Background. The method returns an integer:
1 if the password matched, 0 if it did not match, and -1 if the verification could not be performed at all (the hash string was invalid, its parameters were out of range, or an internal failure occurred, with the reason in LastErrorText). Always test for a match with == 1, never with != 0.Chilkat SQL Server Downloads
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
DECLARE @hr int
DECLARE @sTmp0 nvarchar(4000)
DECLARE @crypt int
EXEC @hr = sp_OACreate 'Chilkat.Crypt2', @crypt OUT
IF @hr <> 0
BEGIN
PRINT 'Failed to create ActiveX component'
RETURN
END
-- The password should come from a secure source rather than being hard-coded.
DECLARE @password nvarchar(4000)
SELECT @password = 'correct horse battery staple'
-- A PHC-format Argon2 hash string previously produced by Argon2HashPassword. All cost options
-- (variant, version, memory cost, iterations, parallelism, salt, hash length) are read from this
-- string, so none need to be supplied.
DECLARE @phcHash nvarchar(4000)
SELECT @phcHash = '$argon2id$v=19$m=65536,t=3,p=1$c29tZXJhbmRvbXNhbHQ$3fJ7v1qKcVJ0lHqXjBQZ8mYm3sNTfSPRt0bqDl9kEyM'
-- Verify the password. Pass an empty options string when no secret (pepper) or ad was used.
-- The method returns one of three values: 1 = the password matched, 0 = it did not match, and
-- -1 = the verification could not be performed (the hash string was invalid or unusable).
-- Always test for a match with == 1.
DECLARE @verifyResult int
EXEC sp_OAMethod @crypt, 'Argon2VerifyPassword', @verifyResult OUT, @password, '', @phcHash
IF @verifyResult = 1
BEGIN
PRINT 'The password is verified.'
END
ELSE
BEGIN
IF @verifyResult = 0
BEGIN
PRINT 'The password does not match.'
END
ELSE
BEGIN
EXEC sp_OAGetProperty @crypt, 'LastErrorText', @sTmp0 OUT
PRINT 'The verification could not be performed: ' + @sTmp0
END
END
EXEC @hr = sp_OADestroy @crypt
END
GO