Sample code for 30+ languages & platforms
Xbase++

Manually Duplicate SetSecretKeyViaPassword

Demonstrates how to duplicate the password string to binary secret key computation of SetSecretKeyViaPassword.

This is a cryptographically weak way of generating a secret key from a password. The SetSecretKeyViaPassword method is deprecated and should not be used.

Chilkat Xbase++ Downloads

Xbase++
LOCAL oCrypt
LOCAL cPassword
LOCAL oSb
LOCAL cPasswordBase64

//  This example assumes the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oCrypt := CreateObject("Chilkat.Crypt2")

//  The password string is transformed to a binary secret key by computing the 
//  MD5 digest (of the utf-8 password) to obtain 16 bytes.  
//  If the KeyLength is greater than 16 bytes, then the MD5 digest of the Base64 encoding 
//  of the utf-8 password is added.  A max of 32 bytes of key material is generated, and 
//  this is truncated to the actual KeyLength required.

oCrypt:CryptAlgorithm := "aes"
oCrypt:KeyLength := 256

cPassword := "this is my password"
oCrypt:SetSecretKeyViaPassword(cPassword)

//  Examine the resulting SecretKey in hex:
? "Computed Secret Key = " + oCrypt:GetEncodedKey("hex")

//  Now perform the same computation manually:
oSb := CreateObject("Chilkat.StringBuilder")

oCrypt:HashAlgorithm := "md5"
oCrypt:Charset := "utf-8"
oCrypt:EncodingMode := "hex"
oSb:Append(oCrypt:HashStringENC(cPassword))

cPasswordBase64 := oCrypt:EncodeString(cPassword, "utf-8", "base64")
oSb:Append(oCrypt:HashStringENC(cPasswordBase64))

? "Manually Computed = " + oSb:GetAsString()

//  The output is:
//  Computed Secret Key = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36
//  Manually Computed = 210D53992DFF432EC1B1A9698AF9DA16C7E90518F90E24828F78EC9E0A413B36

oCrypt:destroy()
oSb:destroy()