Hash Generator Guide

Pick the hash that matches the job. Checksums and password hashes are not interchangeable.

RookHash at rookvpn.com/hash computes digests in the browser. The text or file is not uploaded. That is the property you want when the input is a password, a private build, or an unreleased file. It is not a reason to use the wrong algorithm.

Checksums

Use SHA-256 when a download page prints SHA-256. Use SHA-512 only when the publisher printed SHA-512. The hex lengths differ, and a mismatch of length means you used the wrong page, not that the file is corrupt.

MD5 is only for a legacy publisher that printed MD5 and nothing stronger. A matching MD5 is a weak integrity check. It is not a signature, and it is not a password hash.

Drop the file on rookvpn.com/hash/file. Compare the hex to the publisher, including a second download if the first digest fails. A trailing newline changes a pasted string. Hash the bytes you actually have.

Passwords

Password storage uses bcrypt on rookvpn.com/hash/bcrypt. Set the cost to the cost your application uses. A hash at cost 4 will verify in a test and will be too cheap in production. Copy the whole modular crypt string. SHA-256 of a password is the mistake this split exists to prevent, because SHA-256 is fast on purpose.

Generate the password itself on rookvpn.com/pass if you do not already have one. Do not invent one in the hash field.

Keys

RSA key generation stays in the browser. Copy the private key into the store that will use it, and send only the public key. A private key in a ticket is a failed generation. This is a convenience for a lab, not a substitute for a machine that already holds production keys.

What a match does not mean

A checksum match means the bytes are the bytes that were hashed. It does not mean the publisher is trustworthy. Get the expected digest from a channel you already trust, not from the same mirror as the file if that mirror is the thing you doubt.