7 ms·
We have been looking at something very similar (using scrypt and Ed25519) at work for LDAP (SASL) authentication. The primary motivation for us is to move costl
by nmadden 8y ago
We have been looking at something very similar (using scrypt and Ed25519) at work for LDAP (SASL) authentication. The primary motivation for us is to move costly password hashing off the LDAP servers.
Our current design is basically the same, but we generate and store a random salt server-side and present that to the client along with the challenge. Using a deterministic salt based on the username and domain is a nice idea - we actually do something similar if the client presents an incorrect username to avoid leaking whether the account exists (we send salt = HMAC(secret, username) in that case).