[jboss-jira] [JBoss JIRA] (ELY-154) Session based DigestCredential support

Jan Kalina (JIRA) issues at jboss.org
Mon Apr 23 09:37:01 EDT 2018


    [ https://issues.jboss.org/browse/ELY-154?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13565375#comment-13565375 ] 

Jan Kalina edited comment on ELY-154 at 4/23/18 9:36 AM:
---------------------------------------------------------

But questionable if this has some practical meaning, as nonce should be unpredictable from definition.
Only possible usage I see is to have DigestPassword in metal box and mechanism, running outside, could obtain only DigestSessionPassword from it... - but the obtaining would have to be online.


was (Author: honza889):
But questionable if this has some practical meaning, as nonce should be unpredictable from definition.
Only possible usage I see is to have DigestPassword in metal box and mechanism, running outside, could obtain only DigestSessionPassword from it...

> Session based DigestCredential support
> --------------------------------------
>
>                 Key: ELY-154
>                 URL: https://issues.jboss.org/browse/ELY-154
>             Project: WildFly Elytron
>          Issue Type: Sub-task
>          Components: Passwords
>            Reporter: Darran Lofthouse
>
> DigestCredential but where additional information is included such as nonce and cnonce to create a credential applicable to a session.



--
This message was sent by Atlassian JIRA
(v7.5.0#75005)


More information about the jboss-jira mailing list