Skip to main content

Module crypto_pwhash

Module crypto_pwhash 

Source
Available on crate feature alloc only.
Expand description

§Password hashing

Implements libsodium’s crypto_pwhash_* functions with Argon2i and Argon2id. Scrypt is not supported.

String-based password hashes are enabled by default. Disable them by building without default features, or enable them explicitly with the base64 feature.

See the libsodium documentation for details.

§Classic API example, key derivation

use base64::Engine as _;
use base64::engine::general_purpose;
use dryoc::classic::crypto_pwhash::*;
use dryoc::constants::{
    CRYPTO_PWHASH_MEMLIMIT_INTERACTIVE, CRYPTO_PWHASH_OPSLIMIT_INTERACTIVE,
    CRYPTO_PWHASH_SALTBYTES, CRYPTO_SECRETBOX_KEYBYTES,
};
use dryoc::rng::copy_randombytes;

let mut key = [0u8; CRYPTO_SECRETBOX_KEYBYTES];

// Generate a random salt.
let mut salt = [0u8; CRYPTO_PWHASH_SALTBYTES];
copy_randombytes(&mut salt);

let password = b"a long, unique passphrase";

crypto_pwhash(
    &mut key,
    password,
    &salt,
    CRYPTO_PWHASH_OPSLIMIT_INTERACTIVE,
    CRYPTO_PWHASH_MEMLIMIT_INTERACTIVE,
    PasswordHashAlgorithm::Argon2id13,
)
.expect("pwhash failed");

// `key` can now be used as a secret key.
println!("key = {}", general_purpose::STANDARD_NO_PAD.encode(&key));

Enums§

PasswordHashAlgorithm
Password hash algorithm implementations.

Functions§

crypto_pwhash
Hashes password with salt, placing the resulting hash into output.
crypto_pwhash_strbase64
Hash a password string with a random salt.
crypto_pwhash_str_algbase64
Hashes a password with a random salt and the selected algorithm, returning a database-safe encoded string.
crypto_pwhash_str_needs_rehashbase64
Checks if the parameters for hashed_password match those passed to the function. Returns false if the parameters match, and true if the parameters are mismatched (requiring a rehash).
crypto_pwhash_str_verifybase64
Verifies that hashed_password is valid for password, assuming the hashed password was encoded using crypto_pwhash_str.