From d597c62367000e00125ed5aa376ba268717da69a Mon Sep 17 00:00:00 2001 From: HimbeerserverDE Date: Fri, 17 Feb 2023 22:42:04 +0100 Subject: include salt in client proof --- srp/src/server.rs | 3 +++ 1 file changed, 3 insertions(+) (limited to 'srp/src/server.rs') diff --git a/srp/src/server.rs b/srp/src/server.rs index 08c0475..e48c8e8 100644 --- a/srp/src/server.rs +++ b/srp/src/server.rs @@ -121,11 +121,13 @@ impl<'a, D: Digest> SrpServer<'a, D> { /// Process client reply to the handshake. /// b is a random value, + /// s is the salt, /// v is the provided during initial user registration pub fn process_reply( &self, username: &str, b: &[u8], + s: &[u8], v: &[u8], a_pub: &[u8], ) -> Result, SrpAuthError> { @@ -152,6 +154,7 @@ impl<'a, D: Digest> SrpServer<'a, D> { let m1 = compute_m1::( self.params, username_hash.as_slice(), + s, &a_pub.to_bytes_be(), &b_pub.to_bytes_be(), &key.to_bytes_be(), -- cgit v1.2.3