adm_crypto
This document contains the API documentation for the adm_crypto package.
Functions and Procedures
Section titled “Functions and Procedures”generate_password_salt
Section titled “generate_password_salt”A fresh random salt for one password.
Signature:
function generate_password_salt return raw;Returns: raw
get_password_hash
Section titled “get_password_hash”Derives a password hash with PBKDF2-HMAC-SHA512.
Salted and stretched, which the scheme this replaced was neither: it asked uc_crypto for typ => HMAC_SH512 and, because uc_crypto’s HMAC_* and HASH_* constants collide numerically, silently got a bare unsalted SHA-384 with no key at all. Identical passwords produced identical hashes and a leaked table was a rainbow-table lookup.
The pepper from HASH_PRIVATE_KEY is mixed in as well, so a stolen table alone is not enough to attack the hashes offline.
Signature:
function get_password_hash ( p_password in varchar2, p_salt in raw, p_iterations in number default c_pwd_iterations) return raw;Parameters:
| Name | Direction | Type | Description |
|---|---|---|---|
p_password | in | varchar2 | The plain password |
p_salt | in | raw | Per-row salt, from generate_password_salt |
p_iterations | in | number default c_pwd_iterations | Iteration count; pass the value stored with the hash when verifying |
Returns: raw - The derived hash
get_legacy_password_hash
Section titled “get_legacy_password_hash”The pre-26.1 password hash, kept only so a row written under the old scheme can still be verified once and upgraded. Do not use it for anything new.
Signature:
function get_legacy_password_hash ( p_password in varchar2) return raw;Parameters:
| Name | Direction | Type | Description |
|---|---|---|---|
p_password | in | varchar2 | The plain password |
Returns: raw - The old, unsalted hash
hashes_match
Section titled “hashes_match”Compares two hashes without leaking where they first differ through timing.
Signature:
function hashes_match ( p_left in raw, p_right in raw) return boolean;Parameters:
| Name | Direction | Type | Description |
|---|---|---|---|
p_left | in | raw | One hash |
p_right | in | raw | The other |
Returns: boolean - true when they are equal