Additionally, with SRP (like SSL), the only thing common between the client and the server
is the session key. So if there is any need to do password verification semantics, you
have to do it on the session key.
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4097012#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...