Commit27536ba0Recorded4 May 2026Repositorysigil-crypto
test: fix RFC 7914 PBKDF2-SHA256 vector 1 fixture (Group E)
Message
The %rfc7914-vec1 fixture had the correct first 32 bytes of the RFC 7914 § 11 reference vector but the wrong last 32 bytes. The pbkdf2-sha256 implementation produces the canonical RFC 7914 output:
55ac046e 56e3089f ec1691c2 2544b605
f9418521 6dde0465 e68b9d57 c20dacbc
49ca9ccc f179b645 991664b3 9d77ef31
7c71b845 b1e30bd5 09112041 d3a19783Cross-checked vec 2 (Password/NaCl/c=80000/dkLen=64) against RFC 7914 § 11 in passing — implementation matches there too. The bug was purely in the test fixture; pbkdf2-sha256 was correct.
Changed
test/test-crypto.sgl | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)Diff
test/test-crypto.sglmodified
@@ -154,8 +154,8 @@
154
;; PBKDF2-HMAC-SHA-256 ("passwd", "salt", 1, 64) = 155
;; 55ac046e 56e3089f ec1691c2 2544b605 156
;; f9418521 6dde0465 e68b9d57 c20dacbc−157
;; 8c92a0d0 0db1ed46 d6df2cee 2e96d3da−158
;; 5ec1c01f a82c4f04 1ee2070d e64df97a+157
;; 49ca9ccc f179b645 991664b3 9d77ef31+158
;; 7c71b845 b1e30bd5 09112041 d3a19783 159
160
(define %rfc7914-vec1 161
(bytevector@@ -163,10 +163,10 @@
163
#xec #x16 #x91 #xc2 #x25 #x44 #xb6 #x05 164
#xf9 #x41 #x85 #x21 #x6d #xde #x04 #x65 165
#xe6 #x8b #x9d #x57 #xc2 #x0d #xac #xbc−166
#x8c #x92 #xa0 #xd0 #x0d #xb1 #xed #x46−167
#xd6 #xdf #x2c #xee #x2e #x96 #xd3 #xda−168
#x5e #xc1 #xc0 #x1f #xa8 #x2c #x4f #x04−169
#x1e #xe2 #x07 #x0d #xe6 #x4d #xf9 #x7a))+166
#x49 #xca #x9c #xcc #xf1 #x79 #xb6 #x45+167
#x99 #x16 #x64 #xb3 #x9d #x77 #xef #x31+168
#x7c #x71 #xb8 #x45 #xb1 #xe3 #x0b #xd5+169
#x09 #x11 #x20 #x41 #xd3 #xa1 #x97 #x83)) 170
171
(test-group "pbkdf2-sha256" 172