Unicode C
Unicode C
Manually Duplicate SetSecretKeyViaPassword
Demonstrates how to duplicate the password string to binary secret key computation of SetSecretKeyViaPassword.This is a cryptographically weak way of generating a secret key from a password. The SetSecretKeyViaPassword method is deprecated and should not be used.
Chilkat Unicode C Downloads
#include <C_CkCrypt2W.h>
#include <C_CkStringBuilderW.h>
void ChilkatSample(void)
{
HCkCrypt2W crypt;
const wchar_t *password;
HCkStringBuilderW sb;
const wchar_t *passwordBase64;
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
crypt = CkCrypt2W_Create();
// The password string is transformed to a binary secret key by computing the
// MD5 digest (of the utf-8 password) to obtain 16 bytes.
// If the KeyLength is greater than 16 bytes, then the MD5 digest of the Base64 encoding
// of the utf-8 password is added. A max of 32 bytes of key material is generated, and
// this is truncated to the actual KeyLength required.
CkCrypt2W_putCryptAlgorithm(crypt,L"aes");
CkCrypt2W_putKeyLength(crypt,256);
password = L"this is my password";
CkCrypt2W_SetSecretKeyViaPassword(crypt,password);
// Examine the resulting SecretKey in hex:
wprintf(L"Computed Secret Key = %s\n",CkCrypt2W_getEncodedKey(crypt,L"hex"));
// Now perform the same computation manually:
sb = CkStringBuilderW_Create();
CkCrypt2W_putHashAlgorithm(crypt,L"md5");
CkCrypt2W_putCharset(crypt,L"utf-8");
CkCrypt2W_putEncodingMode(crypt,L"hex");
CkStringBuilderW_Append(sb,CkCrypt2W_hashStringENC(crypt,password));
passwordBase64 = CkCrypt2W_encodeString(crypt,password,L"utf-8",L"base64");
CkStringBuilderW_Append(sb,CkCrypt2W_hashStringENC(crypt,passwordBase64));
wprintf(L"Manually Computed = %s\n",CkStringBuilderW_getAsString(sb));
// The output is:
// Computed Secret Key = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36
// Manually Computed = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36
CkCrypt2W_Dispose(crypt);
CkStringBuilderW_Dispose(sb);
}