Change argon2 salt length to recommended value (16 bytes) (#275)
This commit changes the `Ksf` implementation for Argon2 and sets the salt length to 16 bytes, the value recommended in section 3.1 of the Argon2 specification.
This commit is contained in:
+5
-1
@@ -11,6 +11,10 @@ use generic_array::{ArrayLength, GenericArray};
|
|||||||
|
|
||||||
use crate::errors::InternalError;
|
use crate::errors::InternalError;
|
||||||
|
|
||||||
|
/// Recommended salt length for argon2-based password hashing.
|
||||||
|
#[cfg(feature = "argon2")]
|
||||||
|
const ARGON2_RECOMMENDED_SALT_LEN: usize = 16;
|
||||||
|
|
||||||
/// Used for the key stretching function in OPAQUE
|
/// Used for the key stretching function in OPAQUE
|
||||||
pub trait Ksf: Default {
|
pub trait Ksf: Default {
|
||||||
/// Computes the key stretching function
|
/// Computes the key stretching function
|
||||||
@@ -40,7 +44,7 @@ impl Ksf for argon2::Argon2<'_> {
|
|||||||
input: GenericArray<u8, L>,
|
input: GenericArray<u8, L>,
|
||||||
) -> Result<GenericArray<u8, L>, InternalError> {
|
) -> Result<GenericArray<u8, L>, InternalError> {
|
||||||
let mut output = GenericArray::default();
|
let mut output = GenericArray::default();
|
||||||
self.hash_password_into(&input, &[0; argon2::MIN_SALT_LEN], &mut output)
|
self.hash_password_into(&input, &[0; ARGON2_RECOMMENDED_SALT_LEN], &mut output)
|
||||||
.map_err(|_| InternalError::KsfError)?;
|
.map_err(|_| InternalError::KsfError)?;
|
||||||
Ok(output)
|
Ok(output)
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user