Table of Contents

Enum Pbkdf2Prf

Namespace
CryptoHives.Foundation.Security.Cryptography
Assembly
CryptoHives.Foundation.Security.Cryptography.dll

The pseudorandom function PBKDF2 uses when deriving a key from a password.

public enum Pbkdf2Prf

Fields

HmacSha1 = 1

HMAC-SHA-1, the RFC 8018 default. Offered for interoperability with older readers; prefer HmacSha256 or stronger for anything new.

HmacSha256 = 2

HMAC-SHA-256.

HmacSha384 = 3

HMAC-SHA-384.

HmacSha512 = 4

HMAC-SHA-512.

Unknown = 0

No function selected. Rejected by the PbeOptions constructor.

Remarks

Deliberately closed, and deliberately smaller than the set of hashes this library implements. PBES2 encodes the pseudorandom function as an AlgorithmIdentifier inside the file, so a function can only be used here if RFC 8018 assigns it an object identifier. There is no hmacWithBLAKE3 OID, so no amount of naming would let one be written.

This is why the type is an enum rather than a name: the choice is genuinely finite, so an unencodable one should fail to compile rather than throw at export. It is also the reason this does not use System.Security.Cryptography.HashAlgorithmName — that type is an open string wrapper, which would suggest a freedom the format does not have, and Pbkdf2 already avoids it for the same reason where the PRF genuinely is open.

Reading is not limited to this set. The import path maps whatever OID a file carries to a pseudorandom function, so a key written elsewhere with, say, HMAC-SHA-224 still opens.