Add requirements for random value entropy #2411
Labels
3) awaiting proposal
There is some discussion in issue and reach to some results but it's not concluded with clear propos
V6
_5.0 - prep
This needs to be addressed to prepare 5.0
Several standards and other references have requirements about entropy of random values.
NIST sp800-63n:
NIST sp800-63c about Federated user ID (eg. OpenID Connect "sub" claims):
OAuth 2.1 draft:
This would apply to
challenge_verifier
, OIDCnonce
, generatedclient_secret
, etc.FAPI 2.0:
Percival's Cryptographic Right Answers (2009):
Ptacek's Cryptographic Right Answers (2015):
Latacora's Cryptographic Right Answers (2018):
Latacora's Cryptographic Right Answer: Post Quantum Edition (2024):
Possible options:
The text was updated successfully, but these errors were encountered: