Re: openssl hmac and key on the command line

Carson Gaspar <[email protected]>
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
On 6/8/2024 5:12 AM, Neil Horman wrote:
> printf '%s' "hello" | LD_LIBRARY_PATH=$PWD ./apps/openssl dgst -sha1 
> -hmac $(cat key.txt)
> SHA1(stdin)= c3b424548c3dbd02161a9541d89287e689f076d7

That will expose the key in the process args, so is NOT secure.

-- 

Carson
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.