Sample code for 30+ languages & platforms
SQL Server

Manually Duplicate SetSecretKeyViaPassword

Demonstrates how to duplicate the password string to binary secret key computation of SetSecretKeyViaPassword.

This is a cryptographically weak way of generating a secret key from a password. The SetSecretKeyViaPassword method is deprecated and should not be used.

Chilkat SQL Server Downloads

SQL Server
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
    DECLARE @hr int
    -- Important: Do not use nvarchar(max).  See the warning about using nvarchar(max).
    DECLARE @sTmp0 nvarchar(4000)
    -- This example assumes the Chilkat API to have been previously unlocked.
    -- See Global Unlock Sample for sample code.

    DECLARE @crypt int
    EXEC @hr = sp_OACreate 'Chilkat.Crypt2', @crypt OUT
    IF @hr <> 0
    BEGIN
        PRINT 'Failed to create ActiveX component'
        RETURN
    END

    -- The password string is transformed to a binary secret key by computing the 
    -- MD5 digest (of the utf-8 password) to obtain 16 bytes.  
    -- If the KeyLength is greater than 16 bytes, then the MD5 digest of the Base64 encoding 
    -- of the utf-8 password is added.  A max of 32 bytes of key material is generated, and 
    -- this is truncated to the actual KeyLength required.

    EXEC sp_OASetProperty @crypt, 'CryptAlgorithm', 'aes'
    EXEC sp_OASetProperty @crypt, 'KeyLength', 256

    DECLARE @password nvarchar(4000)
    SELECT @password = 'this is my password'
    EXEC sp_OAMethod @crypt, 'SetSecretKeyViaPassword', NULL, @password

    -- Examine the resulting SecretKey in hex:

    EXEC sp_OAMethod @crypt, 'GetEncodedKey', @sTmp0 OUT, 'hex'
    PRINT 'Computed Secret Key = ' + @sTmp0

    -- Now perform the same computation manually:
    DECLARE @sb int
    EXEC @hr = sp_OACreate 'Chilkat.StringBuilder', @sb OUT

    EXEC sp_OASetProperty @crypt, 'HashAlgorithm', 'md5'
    EXEC sp_OASetProperty @crypt, 'Charset', 'utf-8'
    EXEC sp_OASetProperty @crypt, 'EncodingMode', 'hex'
    DECLARE @success int
    EXEC sp_OAMethod @crypt, 'HashStringENC', @sTmp0 OUT, @password
    EXEC sp_OAMethod @sb, 'Append', @success OUT, @sTmp0

    DECLARE @passwordBase64 nvarchar(4000)
    EXEC sp_OAMethod @crypt, 'EncodeString', @passwordBase64 OUT, @password, 'utf-8', 'base64'
    EXEC sp_OAMethod @crypt, 'HashStringENC', @sTmp0 OUT, @passwordBase64
    EXEC sp_OAMethod @sb, 'Append', @success OUT, @sTmp0


    EXEC sp_OAMethod @sb, 'GetAsString', @sTmp0 OUT
    PRINT 'Manually Computed = ' + @sTmp0

    -- The output is:
    -- Computed Secret Key = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36
    -- Manually Computed = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36

    EXEC @hr = sp_OADestroy @crypt
    EXEC @hr = sp_OADestroy @sb


END
GO