(PHP 5 >= 5.5.0, PHP 7, PHP 8)
openssl_pbkdf2 — Generates a PKCS5 v2 PBKDF2 string
$password,$salt,$key_length,$iterations,$digest_algo = "sha1"openssl_pbkdf2() computes PBKDF2 (Password-Based Key Derivation Function 2), a key derivation function defined in PKCS5 v2.
passwordPassword from which the derived key is generated.
saltPBKDF2 recommends a crytographic salt of at least 64 bits (8 bytes).
key_lengthLength of desired output key.
iterationsThe number of iterations desired. » NIST recommends at least 10,000.
digest_algoOptional hash or digest algorithm from openssl_get_md_methods(). Defaults to SHA-1.
Returns raw binary string or false on failure.
Example #1 openssl_pbkdf2() example
<?php
$password = 'password';
$salt = openssl_random_pseudo_bytes(16);
$keyLength = 20;
$iterations = 600000;
$generated_key = openssl_pbkdf2($password, $salt, $keyLength, $iterations, 'sha256');
echo bin2hex($generated_key)."\n";
echo base64_encode($generated_key)."\n";
?>