xref: /freebsd/crypto/openssl/doc/man7/EVP_KDF-PBKDF1.pod (revision b077aed33b7b6aefca7b17ddb250cf521f938613)
1*b077aed3SPierre Pronchery=pod
2*b077aed3SPierre Pronchery
3*b077aed3SPierre Pronchery=head1 NAME
4*b077aed3SPierre Pronchery
5*b077aed3SPierre ProncheryEVP_KDF-PBKDF1 - The PBKDF1 EVP_KDF implementation
6*b077aed3SPierre Pronchery
7*b077aed3SPierre Pronchery=head1 DESCRIPTION
8*b077aed3SPierre Pronchery
9*b077aed3SPierre ProncherySupport for computing the B<PBKDF1> password-based KDF through the B<EVP_KDF>
10*b077aed3SPierre ProncheryAPI.
11*b077aed3SPierre Pronchery
12*b077aed3SPierre ProncheryThe EVP_KDF-PBKDF1 algorithm implements the PBKDF1 password-based key
13*b077aed3SPierre Proncheryderivation function, as described in RFC 8018; it derives a key from a password
14*b077aed3SPierre Proncheryusing a salt and iteration count.
15*b077aed3SPierre Pronchery
16*b077aed3SPierre Pronchery=head2 Identity
17*b077aed3SPierre Pronchery
18*b077aed3SPierre Pronchery"PBKDF1" is the name for this implementation; it
19*b077aed3SPierre Proncherycan be used with the EVP_KDF_fetch() function.
20*b077aed3SPierre Pronchery
21*b077aed3SPierre Pronchery=head2 Supported parameters
22*b077aed3SPierre Pronchery
23*b077aed3SPierre ProncheryThe supported parameters are:
24*b077aed3SPierre Pronchery
25*b077aed3SPierre Pronchery=over 4
26*b077aed3SPierre Pronchery
27*b077aed3SPierre Pronchery=item "pass" (B<OSSL_KDF_PARAM_PASSWORD>) <octet string>
28*b077aed3SPierre Pronchery
29*b077aed3SPierre Pronchery=item "salt" (B<OSSL_KDF_PARAM_SALT>) <octet string>
30*b077aed3SPierre Pronchery
31*b077aed3SPierre Pronchery=item "iter" (B<OSSL_KDF_PARAM_ITER>) <unsigned integer>
32*b077aed3SPierre Pronchery
33*b077aed3SPierre ProncheryThis parameter has a default value of 0 and should be set.
34*b077aed3SPierre Pronchery
35*b077aed3SPierre Pronchery=item "properties" (B<OSSL_KDF_PARAM_PROPERTIES>) <UTF8 string>
36*b077aed3SPierre Pronchery
37*b077aed3SPierre Pronchery=item "digest" (B<OSSL_KDF_PARAM_DIGEST>) <UTF8 string>
38*b077aed3SPierre Pronchery
39*b077aed3SPierre ProncheryThese parameters work as described in L<EVP_KDF(3)/PARAMETERS>.
40*b077aed3SPierre Pronchery
41*b077aed3SPierre Pronchery=back
42*b077aed3SPierre Pronchery
43*b077aed3SPierre Pronchery=head1 NOTES
44*b077aed3SPierre Pronchery
45*b077aed3SPierre ProncheryA typical application of this algorithm is to derive keying material for an
46*b077aed3SPierre Proncheryencryption algorithm from a password in the "pass", a salt in "salt",
47*b077aed3SPierre Proncheryand an iteration count.
48*b077aed3SPierre Pronchery
49*b077aed3SPierre ProncheryIncreasing the "iter" parameter slows down the algorithm which makes it
50*b077aed3SPierre Proncheryharder for an attacker to perform a brute force attack using a large number
51*b077aed3SPierre Proncheryof candidate passwords.
52*b077aed3SPierre Pronchery
53*b077aed3SPierre ProncheryNo assumption is made regarding the given password; it is simply treated as a
54*b077aed3SPierre Proncherybyte sequence.
55*b077aed3SPierre Pronchery
56*b077aed3SPierre Pronchery=head1 CONFORMING TO
57*b077aed3SPierre Pronchery
58*b077aed3SPierre ProncheryRFC 8018
59*b077aed3SPierre Pronchery
60*b077aed3SPierre Pronchery=head1 SEE ALSO
61*b077aed3SPierre Pronchery
62*b077aed3SPierre ProncheryL<EVP_KDF(3)>,
63*b077aed3SPierre ProncheryL<EVP_KDF_CTX_new(3)>,
64*b077aed3SPierre ProncheryL<EVP_KDF_CTX_free(3)>,
65*b077aed3SPierre ProncheryL<EVP_KDF_CTX_set_params(3)>,
66*b077aed3SPierre ProncheryL<EVP_KDF_derive(3)>,
67*b077aed3SPierre ProncheryL<EVP_KDF(3)/PARAMETERS>
68*b077aed3SPierre Pronchery
69*b077aed3SPierre Pronchery=head1 HISTORY
70*b077aed3SPierre Pronchery
71*b077aed3SPierre ProncheryThis functionality was added in OpenSSL 3.0.
72*b077aed3SPierre Pronchery
73*b077aed3SPierre Pronchery=head1 COPYRIGHT
74*b077aed3SPierre Pronchery
75*b077aed3SPierre ProncheryCopyright 2021 The OpenSSL Project Authors. All Rights Reserved.
76*b077aed3SPierre Pronchery
77*b077aed3SPierre ProncheryLicensed under the Apache License 2.0 (the "License").  You may not use
78*b077aed3SPierre Proncherythis file except in compliance with the License.  You can obtain a copy
79*b077aed3SPierre Proncheryin the file LICENSE in the source distribution or at
80*b077aed3SPierre ProncheryL<https://www.openssl.org/source/license.html>.
81*b077aed3SPierre Pronchery
82*b077aed3SPierre Pronchery=cut
83