Available on crate feature
alloc only.Expand description
§Password hashing
Implements libsodium’s crypto_pwhash_* functions with Argon2i and
Argon2id. Scrypt is not supported.
String-based password hashes are enabled by default. Disable them by
building without default features, or enable them explicitly with the
base64 feature.
See the libsodium documentation for details.
§Classic API example, key derivation
use base64::Engine as _;
use base64::engine::general_purpose;
use dryoc::classic::crypto_pwhash::*;
use dryoc::constants::{
CRYPTO_PWHASH_MEMLIMIT_INTERACTIVE, CRYPTO_PWHASH_OPSLIMIT_INTERACTIVE,
CRYPTO_PWHASH_SALTBYTES, CRYPTO_SECRETBOX_KEYBYTES,
};
use dryoc::rng::copy_randombytes;
let mut key = [0u8; CRYPTO_SECRETBOX_KEYBYTES];
// Generate a random salt.
let mut salt = [0u8; CRYPTO_PWHASH_SALTBYTES];
copy_randombytes(&mut salt);
let password = b"a long, unique passphrase";
crypto_pwhash(
&mut key,
password,
&salt,
CRYPTO_PWHASH_OPSLIMIT_INTERACTIVE,
CRYPTO_PWHASH_MEMLIMIT_INTERACTIVE,
PasswordHashAlgorithm::Argon2id13,
)
.expect("pwhash failed");
// `key` can now be used as a secret key.
println!("key = {}", general_purpose::STANDARD_NO_PAD.encode(&key));Enums§
- Password
Hash Algorithm - Password hash algorithm implementations.
Functions§
- crypto_
pwhash - Hashes
passwordwithsalt, placing the resulting hash intooutput. - crypto_
pwhash_ str base64 - Hash a password string with a random salt.
- crypto_
pwhash_ str_ alg base64 - Hashes a password with a random salt and the selected algorithm, returning a database-safe encoded string.
- crypto_
pwhash_ str_ needs_ rehash base64 - Checks if the parameters for
hashed_passwordmatch those passed to the function. Returnsfalseif the parameters match, andtrueif the parameters are mismatched (requiring a rehash). - crypto_
pwhash_ str_ verify base64 - Verifies that
hashed_passwordis valid forpassword, assuming the hashed password was encoded usingcrypto_pwhash_str.