Skip to content

Commit

Permalink
Adding note on password change
Browse files Browse the repository at this point in the history
  • Loading branch information
kevinlewi committed Dec 4, 2023
1 parent 6f98fac commit cbc12f5
Showing 1 changed file with 5 additions and 0 deletions.
5 changes: 5 additions & 0 deletions draft-irtf-cfrg-opaque.md
Original file line number Diff line number Diff line change
Expand Up @@ -1828,6 +1828,11 @@ applications can use to control OPAQUE:
implement this mitigation SHOULD use the same configuration information (such as
the oprf_seed) for all clients; see {{preventing-client-enumeration}}. In settings
where this attack is not a concern, servers may choose to not support this functionality.
- Handling password changes: In the event of a password change, the client and
server can run the offline registration phase using the new password as a
fresh instance (ensuring to resample all random values). The resulting
registration record can then replace the previous record corresponding to
the client's old password registration.

# Implementation Considerations {#implementation-considerations}

Expand Down

0 comments on commit cbc12f5

Please sign in to comment.