gnutls_srp_set_server_fake_salt_seed(3) — Linux manual page



NAME         top

       gnutls_srp_set_server_fake_salt_seed - API function

SYNOPSIS         top

       #include <gnutls/gnutls.h>

       cred, const gnutls_datum_t * seed, unsigned int salt_length);

ARGUMENTS         top

       gnutls_srp_server_credentials_t cred
                   is a gnutls_srp_server_credentials_t type

       const gnutls_datum_t * seed
                   is the seed data, only needs to be valid until the
                   function returns; size of the seed must be greater
                   than zero

       unsigned int salt_length
                   is the length of the generated fake salts

DESCRIPTION         top

       This function sets the seed that is used to generate salts for
       invalid (non-existent) usernames.

       In order to prevent attackers from guessing valid usernames, when
       a user does not exist gnutls generates a salt and a verifier and
       proceeds with the protocol as usual.  The authentication will
       ultimately fail, but the client cannot tell whether the username
       is valid (exists) or invalid.

       If an attacker learns the seed, given a salt (which is part of
       the handshake) which was generated when the seed was in use, it
       can tell whether or not the authentication failed because of an
       unknown username.  This seed cannot be used to reveal application
       data or passwords.

        salt_length should represent the salt length your application
       uses.  Generating fake salts longer than 20 bytes is not

       By default the seed is a random value, different each time a
       gnutls_srp_server_credentials_t is allocated and fake salts are
       16 bytes long.

SINCE         top


REPORTING BUGS         top

       Report bugs to <>.
       Home page:

COPYRIGHT         top

       Copyright © 2001- Free Software Foundation, Inc., and others.
       Copying and distribution of this file, with or without
       modification, are permitted in any medium without royalty
       provided the copyright notice and this notice are preserved.

SEE ALSO         top

       The full documentation for gnutls is maintained as a Texinfo
       manual.  If the /usr/share/doc/gnutls/ directory does not contain
       the HTML form visit 

COLOPHON         top

       This page is part of the GnuTLS (GnuTLS Transport Layer Security
       Library) project.  Information about the project can be found at
       ⟨⟩.  If you have a bug report for this
       manual page, send it to  This page was obtained
       from the tarball gnutls-3.7.2.tar.xz fetched from
       ⟨⟩ on 2021-08-27.  If you
       discover any rendering problems in this HTML version of the page,
       or you believe there is a better or more up-to-date source for
       the page, or you have corrections or improvements to the
       information in this COLOPHON (which is not part of the original
       manual page), send a mail to

gnutls                           g3n.u7t.l2s_srp_set_server_fake_salt_seed(3)