Skip to content

adm_crypto

This document contains the API documentation for the adm_crypto package.

A fresh random salt for one password.

Signature:

function generate_password_salt return raw;

Returns: raw


Derives a password hash with PBKDF2-HMAC-SHA512.

Salted and stretched, which the scheme this replaced was neither: it asked uc_crypto for typ => HMAC_SH512 and, because uc_crypto’s HMAC_* and HASH_* constants collide numerically, silently got a bare unsalted SHA-384 with no key at all. Identical passwords produced identical hashes and a leaked table was a rainbow-table lookup.

The pepper from HASH_PRIVATE_KEY is mixed in as well, so a stolen table alone is not enough to attack the hashes offline.

Signature:

function get_password_hash (
p_password in varchar2,
p_salt in raw,
p_iterations in number default c_pwd_iterations
) return raw;

Parameters:

NameDirectionTypeDescription
p_passwordinvarchar2The plain password
p_saltinrawPer-row salt, from generate_password_salt
p_iterationsinnumber default c_pwd_iterationsIteration count; pass the value stored with the hash when verifying

Returns: raw - The derived hash


The pre-26.1 password hash, kept only so a row written under the old scheme can still be verified once and upgraded. Do not use it for anything new.

Signature:

function get_legacy_password_hash (
p_password in varchar2
) return raw;

Parameters:

NameDirectionTypeDescription
p_passwordinvarchar2The plain password

Returns: raw - The old, unsalted hash


Compares two hashes without leaking where they first differ through timing.

Signature:

function hashes_match (
p_left in raw,
p_right in raw
) return boolean;

Parameters:

NameDirectionTypeDescription
p_leftinrawOne hash
p_rightinrawThe other

Returns: boolean - true when they are equal