Skip to content

Hashing the premaster key in SRP #204

@r4v3n6101

Description

@r4v3n6101

Hello! I've noticed some SRP uses the premaster secret (aka S) directly even though both SRP-related RFCs define the session key as K = H(S).
Here they are:
RFC 2945: https://www.rfc-editor.org/rfc/rfc2945
RFC 5054: https://www.rfc-editor.org/rfc/rfc5054

Are there any reasons this isn’t the default behavior? Back-compatibility or something else?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions