Skip to content

Align with RFC 8018 (obsoletes RFC 2898) #3

@sthagen

Description

@sthagen

As RFC 8018 obsoleted RFC 2898 after being 16 years in "operation" - I propose to ensure, the library also implements the PBKDF2 key derivation function described in the RFC successor.

My inspection of the two RFC's (section 5.2) did not expose any notable difference but in the appendix B.1 as expected, the former single example (default for this implementation as I understood):

An example pseudorandom function for PBKDF2 (Section 5.2) is HMAC-
SHA-1.

is augmented in the new edition (RFC 8018) to:

Examples of pseudorandom function for PBKDF2 (Section 5.2) include
HMAC with SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, and
SHA-512/256. Applications may employ other schemes as well.

So, it might be worth to revisit the default chosen.

The reporter considers the target of this issue as an improvement 😸

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions