Enum Pbkdf2Prf
- Namespace
- CryptoHives.Foundation.Security.Cryptography
- Assembly
- CryptoHives.Foundation.Security.Cryptography.dll
The pseudorandom function PBKDF2 uses when deriving a key from a password.
public enum Pbkdf2Prf
Fields
HmacSha1 = 1HMAC-SHA-1, the RFC 8018 default. Offered for interoperability with older readers; prefer HmacSha256 or stronger for anything new.
HmacSha256 = 2HMAC-SHA-256.
HmacSha384 = 3HMAC-SHA-384.
HmacSha512 = 4HMAC-SHA-512.
Unknown = 0No function selected. Rejected by the PbeOptions constructor.
Remarks
Deliberately closed, and deliberately smaller than the set of hashes this library implements.
PBES2 encodes the pseudorandom function as an AlgorithmIdentifier inside the file, so a
function can only be used here if RFC 8018 assigns it an object identifier. There is no
hmacWithBLAKE3 OID, so no amount of naming would let one be written.
This is why the type is an enum rather than a name: the choice is genuinely finite, so an
unencodable one should fail to compile rather than throw at export. It is also the reason this
does not use System.Security.Cryptography.HashAlgorithmName — that type is an open string
wrapper, which would suggest a freedom the format does not have, and
Pbkdf2 already avoids it for the same reason where the PRF genuinely is open.
Reading is not limited to this set. The import path maps whatever OID a file carries to a pseudorandom function, so a key written elsewhere with, say, HMAC-SHA-224 still opens.