ic-kdf-0.1.0 has been yanked.
ic-kdf — key derivation
- [
hkdf] — RFC 5869 extract-and-expand (SP 800-56C two-step). - [
pbkdf2()] — SP 800-132 password-based derivation. - [
kbkdf] — SP 800-108 counter-mode KDF over HMAC. - [
argon2()] — RFC 9106 memory-hard password hashing.
The HMAC-based functions are generic over the instantiation, so the same code path serves SHA-256, SHA-384, SHA-512, and the SHA-3 family.
Choosing between the two password KDFs
[pbkdf2()] is the only approved option and is not memory-hard, so a GPU
attacks it far faster than a CPU defends it. [argon2()] is memory-hard and
is what RFC 9106 recommends, but is not FIPS-approved. If you have a FIPS
obligation the choice is made for you; otherwise reach for Argon2id.
use Hkdf;
use Kdf;
use HmacSha256;
let mut key = ;
derive?;
# Ok::