Skip to content

password-hash: controlling output length from PasswordHasher #505

Description

@tarcieri

Right now the only way to pass an output length to PasswordHasher is via the associated PasswordHasher::Params type.

However, PasswordVerifier needs to pass the length of the password hash (i.e. output/tag) being compared to in order to generate an equivalent-length hash.

PBKDF2 also has an l parameter, so we need to support taking it in via Params (and perhaps we should enforce some mandatory methods on params for transmitting it or a default)

Activity

  1. tarcieri commented on Jan 29, 2021

    @tarcieri
    MemberAuthor

    Separately, if we make make the output length a mandatory parameter, should we do the same for a version instead of using a parameter to PasswordHasher::hash_password?

    Should this further be extended to a default algorithm ID as well?

  2. tarcieri commented on Apr 28, 2021

    @tarcieri
    MemberAuthor

    Fixed in #615

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions