… of the integer g, most significant octet first. Hi() is, essentially, PBKDF2 [ RFC2898 ] with HMAC() as the Pseudorandom Function (PRF) and with dkLen == output length of HMAC() == output length of H(). Melnikov Experimental [Page 5] RFC 7804 HTTP SCRAM March 2016 . SCRAM Algori…
…iginal method. Change PBKDF2 to conform to SP800-132 instead of the older PKCS5 RFC2898 This checks that the salt length is at least 128 bits, the derived key length is at least 112 bits, and that the iteration count is at least 1000. For backwards compatibility these checks are …
…591 4 10} DEFINITIONS ::= BEGIN IMPORTS ALGORITHM-IDENTIFIER FROM PKCS5v2-0 -- [RFC2898] { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs-5(5) modules(16) pkcs5v2-0(1) } ; id-scrypt OBJECT IDENTIFIER ::= {1 3 6 1 4 1 11591 4 11} Scrypt-params ::= SEQUENCE { salt OCTET …
…591 4 10} DEFINITIONS ::= BEGIN IMPORTS ALGORITHM-IDENTIFIER FROM PKCS5v2-0 -- [RFC2898] { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs-5(5) modules(16) pkcs5v2-0(1) } ; id-scrypt OBJECT IDENTIFIER ::= {1 3 6 1 4 1 11591 4 11} Scrypt-params ::= SEQUENCE { salt OCTET …