Skip to content
lsl.devlsl.devLSL Dev

LlHMAC

Looking for the current API? Open the llHMAC reference →

Function notes

This function supports md5, sha1, sha224, sha256, sha384, sha512 for algorithm.
secret can be any string.

Return value notes

Returns a string that is the Base64-encoded HMAC hash of msg when using hash algorithm algorithm and secret string secret.

Caveats

  • secret is passed in as UTF-8 (though stored in memory as UTF-16 in Mono).
    • If your secret is encoded in Base64 (as is common for HMAC applications), consider llBase64ToString, but be aware of its caveats.
    • If you are generating an HMAC hash on a different platform, you will need to ensure its implementation reads the secret as UTF-8 (or you will need to manually encode it into the correct format beforehand), or else the HMAC hashes will not match.
    • Since secret is not Base64, and LSL does not support "NUL" (U+0000) in strings, this function cannot calculate hashes with secrets that encode into UTF-8/16 as U+0000.

Examples

default
{
    state_entry()
    {
        string secret = "secret key";
        
        // Supported algorithims for llHMAC() include:
        // md5, sha1, sha224, sha256, sha384, sha512
        
        string algorithm = "sha1";
        string msg = "Hello, Avatar!";
        
        string digest = llHMAC(secret, msg, algorithm);
        
        // For the given secret/msg/algorithm, expect the HMAC
        // digest to be 'ffCDntkagRO5mIEtd2tYzM2Bg8I='
        llSay(0, "HMAC digest of message '" + msg + "' using algorithm "
            +  algorithm + " is " + digest);
    }
}

Notes

  • This function performs no checks on secret; it can contain any value, or no value at all. Be sure to check that you are hashing using the correct secret.
  • Since this function uses UTF-8 secrets, you should at a minimum follow "password rules": more entropy is usually better. If you need a guideline, 32+ random characters is likely enough.

See also: functions

Original wiki source

Some wiki templates and tables need their original context. View this article on the Second Life Wiki. Technical wording and examples are retained from the source; historical guidance may differ from current behavior.

From the Second Life Wiki

Community documentation adapted from LlHMAC, by Linden Research, Inc. and contributing residents.View contributors and history.

Imported wiki revision:

  • LlHMAC (revision 1219022, )

Licensed under CC BY-SA 3.0. Last wiki edit: .Formatting and links have been adapted for this site; API metadata follows the LSL definitions.