pub(super) fn pbes2(password: &str, salt: &[u8], iterations: u32) -> [u8; 32]
PBKDF2-HMAC-SHA256 producing 32 bytes. Callers check the method first.