Menu

MariaDB SHA2() Function

Learn MariaDB SHA2() syntax, supported digest lengths, NULL behavior, and why a fast SHA-2 digest is not a password hash.

Posted on By Updated on
On this page

MariaDB SHA2(str, hash_len) computes a digest from the SHA-2 family. The supported lengths are 224, 256, 384, and 512 bits; 0 is equivalent to 256. The result is a hexadecimal string, or NULL if the input is NULL or the hash length is invalid. MariaDB notes that SHA2() requires TLS support in the server build. See the official SHA2() documentation.

Syntax

SHA2(str, hash_len)

Examples

Calculate a SHA-256 digest:

SELECT SHA2('Hello, World!', 256);

Result:

dffd6021bb2bd5b0af676290809ec3a53191dd81c7f70a4b28688a362182986f

Using 0 selects the same 256-bit digest:

SELECT SHA2('Hello, World!', 0);

SHA2() is a fast, general-purpose hash function. It can be useful for checksums and digest comparisons, but it is not a password-hashing function. Do not store application passwords using SHA2(password, 256); an attacker with the digest can test guesses quickly. Use an adaptive password-hashing library such as Argon2id, bcrypt, or PBKDF2 instead. See the OWASP Password Storage Cheat Sheet.

Summary

Use SHA2() when you need a digest from the SHA-2 family. It does not encrypt data and should not be used alone to store application passwords.