<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Digest access authentication</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Digest_access_authentication"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/ext.pygments.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Digest_access_authentication rootpage-Digest_access_authentication skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Digest access authentication</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}
/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1246091330">
/* start https://en.wikipedia.org/ */
.mw-parser-output .sidebar{width:22em;float:right;clear:right;margin:0.5em 0 1em 1em;background:var(--background-color-neutral-subtle,#f8f9fa);border:1px solid var(--border-color-base,#a2a9b1);padding:0.2em;text-align:center;line-height:1.4em;font-size:88%;border-collapse:collapse;display:table}body.skin-minerva .mw-parser-output .sidebar{display:table!important;float:right!important;margin:0.5em 0 1em 1em!important}.mw-parser-output .sidebar-subgroup{width:100%;margin:0;border-spacing:0}.mw-parser-output .sidebar-left{float:left;clear:left;margin:0.5em 1em 1em 0}.mw-parser-output .sidebar-none{float:none;clear:both;margin:0.5em 1em 1em 0}.mw-parser-output .sidebar-outer-title{padding:0 0.4em 0.2em;font-size:125%;line-height:1.2em;font-weight:bold}.mw-parser-output .sidebar-top-image{padding:0.4em}.mw-parser-output .sidebar-top-caption,.mw-parser-output .sidebar-pretitle-with-top-image,.mw-parser-output .sidebar-caption{padding:0.2em 0.4em 0;line-height:1.2em}.mw-parser-output .sidebar-pretitle{padding:0.4em 0.4em 0;line-height:1.2em}.mw-parser-output .sidebar-title,.mw-parser-output .sidebar-title-with-pretitle{padding:0.2em 0.8em;font-size:145%;line-height:1.2em}.mw-parser-output .sidebar-title-with-pretitle{padding:0.1em 0.4em}.mw-parser-output .sidebar-image{padding:0.2em 0.4em 0.4em}.mw-parser-output .sidebar-heading{padding:0.1em 0.4em}.mw-parser-output .sidebar-content{padding:0 0.5em 0.4em}.mw-parser-output .sidebar-content-with-subgroup{padding:0.1em 0.4em 0.2em}.mw-parser-output .sidebar-above,.mw-parser-output .sidebar-below{padding:0.3em 0.8em;font-weight:bold}.mw-parser-output .sidebar-collapse .sidebar-above,.mw-parser-output .sidebar-collapse .sidebar-below{border-top:1px solid #aaa;border-bottom:1px solid #aaa}.mw-parser-output .sidebar-navbar{text-align:right;font-size:115%;padding:0 0.4em 0.4em}.mw-parser-output .sidebar-list-title{padding:0 0.4em;text-align:left;font-weight:bold;line-height:1.6em;font-size:105%}.mw-parser-output .sidebar-list-title-c{padding:0 0.4em;text-align:center;margin:0 3.3em}@media(max-width:640px){body.mediawiki .mw-parser-output .sidebar{width:100%!important;clear:both;float:none!important;margin-left:0!important;margin-right:0!important}}body.skin--responsive .mw-parser-output .sidebar a>img{max-width:none!important}@media screen{html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-list-title,html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle{background:transparent!important}html.skin-theme-clientpref-night .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle a{color:var(--color-progressive)!important}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-list-title,html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle{background:transparent!important}html.skin-theme-clientpref-os .mw-parser-output .sidebar:not(.notheme) .sidebar-title-with-pretitle a{color:var(--color-progressive)!important}}@media print{body.ns-0 .mw-parser-output .sidebar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><table class="sidebar nomobile nowraplinks hlist"><tbody><tr><th class="sidebar-title"><a href="HTTP" title="HTTP">HTTP</a></th></tr><tr><td class="sidebar-image"><span typeof="mw:File"></span></td></tr><tr><td class="sidebar-content">
<ul><li><a href="HTTP_persistent_connection" title="HTTP persistent connection">Persistence</a></li>
<li><a href="HTTP_compression" title="HTTP compression">Compression</a></li>
<li><a href="HTTPS" title="HTTPS">HTTPS</a></li>
<li><a href="QUIC" title="QUIC">QUIC</a></li></ul></td>
</tr><tr><th class="sidebar-heading">
<a href="HTTP#Request_methods" title="HTTP">Request methods</a></th></tr><tr><td class="sidebar-content">
<ul><li><a href="HTTP#Request_methods" title="HTTP">OPTIONS</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">GET</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">HEAD</a></li>
<li><a href="POST_(HTTP)" title="POST (HTTP)">POST</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">PUT</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">DELETE</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">TRACE</a></li>
<li><a href="HTTP#Request_methods" title="HTTP">CONNECT</a></li>
<li><a href="PATCH_(HTTP)" title="PATCH (HTTP)">PATCH</a></li></ul></td>
</tr><tr><th class="sidebar-heading">
<a href="List_of_HTTP_header_fields" title="List of HTTP header fields">Header fields</a></th></tr><tr><td class="sidebar-content">
<ul><li><a href="HTTP_cookie" title="HTTP cookie">Cookie</a></li>
<li><a href="HTTP_ETag" title="HTTP ETag">ETag</a></li>
<li><a href="HTTP_location" title="HTTP location">Location</a></li>
<li><a href="HTTP_referer" title="HTTP referer">HTTP referer</a></li>
<li><a href="Do_Not_Track" title="Do Not Track">DNT</a></li>
<li><a href="X-Forwarded-For" title="X-Forwarded-For">X-Forwarded-For</a></li></ul></td>
</tr><tr><th class="sidebar-heading">
<a href="List_of_HTTP_status_codes" title="List of HTTP status codes">Response status codes</a></th></tr><tr><td class="sidebar-content">
<ul><li><a href="HTTP_301" title="HTTP 301">301 Moved Permanently</a></li>
<li><a href="HTTP_302" title="HTTP 302">302 Found</a></li>
<li><a href="HTTP_303" title="HTTP 303">303 See Other</a></li>
<li><a href="HTTP_403" title="HTTP 403">403 Forbidden</a></li>
<li><a href="HTTP_404" title="HTTP 404">404 Not Found</a></li>
<li><a href="HTTP_451" title="HTTP 451">451 Unavailable for Legal Reasons</a></li></ul></td>
</tr><tr><th class="sidebar-heading">
Security access control methods</th></tr><tr><td class="sidebar-content">
<ul><li><a href="Basic_access_authentication" title="Basic access authentication">Basic access authentication</a></li>
</ul></td>
</tr><tr><th class="sidebar-heading">
Security vulnerabilities</th></tr><tr><td class="sidebar-content">
<ul><li><a href="HTTP_header_injection" title="HTTP header injection">HTTP header injection</a></li>
<li><a href="HTTP_request_smuggling" title="HTTP request smuggling">HTTP request smuggling</a></li>
<li><a href="HTTP_response_splitting" title="HTTP response splitting">HTTP response splitting</a></li>
<li><a href="HTTP_parameter_pollution" title="HTTP parameter pollution">HTTP parameter pollution</a></li></ul></td>
</tr><tr><td class="sidebar-navbar"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}
/* end https://en.wikipedia.org/ */
</style></td></tr></tbody></table>
<p><b>Digest access authentication</b> is one of the agreed-upon methods a <a href="Web_server" title="Web server">web server</a> can use to negotiate credentials, such as username or password, with a user's <a href="Web_browser" title="Web browser">web browser</a>. This can be used to confirm the identity of a user before sending sensitive information, such as online banking transaction history. It applies a <a href="Hash_function" title="Hash function">hash function</a> to the username and <a href="Password" title="Password">password</a> before sending them over the network. In contrast, <a href="Basic_access_authentication" title="Basic access authentication">basic access authentication</a> uses the easily reversible <a href="Base64" title="Base64">Base64</a> encoding instead of hashing, making it non-secure unless used in conjunction with <a href="Transport_Layer_Security" title="Transport Layer Security">TLS</a>.
</p><p>Technically, digest authentication is an application of <a href="Cryptographic_hash" class="mw-redirect" title="Cryptographic hash">cryptographic hashing</a> with usage of <a href="Cryptographic_nonce" title="Cryptographic nonce">nonce</a> values to prevent <a href="Replay_attack" title="Replay attack">replay attacks</a>. It uses the <a href="Hypertext_Transfer_Protocol" class="mw-redirect" title="Hypertext Transfer Protocol">HTTP</a> protocol.
</p><p>DIGEST-MD5 as a <a href="Simple_Authentication_and_Security_Layer" title="Simple Authentication and Security Layer">SASL</a> mechanism specified by <style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc2831">2831</a> is obsolete since July 2011.<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Overview">Overview</h2></div>
<p>Digest access authentication was originally specified by <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc2069">2069</a> (<i>An Extension to HTTP: Digest Access Authentication</i>). RFC 2069 specifies roughly a traditional digest authentication scheme with security maintained by a server-generated <i><a href="Cryptographic_nonce" title="Cryptographic nonce">nonce value</a></i>. The authentication response is formed as follows (where HA1 and HA2 are names of string variables):
</p>
<dl><dd><div class="mw-highlight mw-highlight-lang-text mw-content-ltr" dir="ltr"><pre>HA1 = MD5(username:realm:password)
HA2 = MD5(method:digestURI)
response = MD5(HA1:nonce:HA2)
</pre></div></dd></dl>
<p>An MD5 hash is a 16-byte value. The HA1 and HA2 values used in the computation of the response are the hexadecimal representation (in lowercase) of the MD5 hashes respectively.
</p><p>RFC 2069 was later replaced by <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc2617">2617</a> (<i>HTTP Authentication: Basic and Digest Access Authentication</i>). RFC 2617 introduced a number of optional security enhancements to digest authentication; <b>"quality of protection" (qop)</b>, nonce counter incremented by client, and a client-generated random nonce. These enhancements are designed to protect against, for example, <a href="Chosen-plaintext_attack" title="Chosen-plaintext attack">chosen-plaintext attack</a> <a href="Cryptanalysis" title="Cryptanalysis">cryptanalysis</a>.
</p><p>If the algorithm directive's value is "MD5" or unspecified, then HA1 is
</p>
<dl><dd><div class="mw-highlight mw-highlight-lang-text mw-content-ltr" dir="ltr"><pre>HA1 = MD5(username:realm:password)
</pre></div></dd></dl>
<p>If the algorithm directive's value is "MD5-sess", then HA1 is
</p>
<dl><dd><div class="mw-highlight mw-highlight-lang-text mw-content-ltr" dir="ltr"><pre>HA1 = MD5(MD5(username:realm:password):nonce:cnonce)
</pre></div></dd></dl>
<p>If the qop directive's value is "auth" or is unspecified, then HA2 is
</p>
<dl><dd><div class="mw-highlight mw-highlight-lang-text mw-content-ltr" dir="ltr"><pre>HA2 = MD5(method:digestURI)
</pre></div></dd></dl>
<p>If the qop directive's value is "auth-int", then HA2 is
</p>
<dl><dd><div class="mw-highlight mw-highlight-lang-text mw-content-ltr" dir="ltr"><pre>HA2 = MD5(method:digestURI:MD5(entityBody))
</pre></div></dd></dl>
<p>If the qop directive's value is "auth" or "auth-int", then compute the response as follows:
</p>
<dl><dd><div class="mw-highlight mw-highlight-lang-text mw-content-ltr" dir="ltr"><pre>response = MD5(HA1:nonce:nonceCount:cnonce:qop:HA2)
</pre></div></dd></dl>
<p>If the qop directive is unspecified, then compute the response as follows:
</p>
<dl><dd><div class="mw-highlight mw-highlight-lang-text mw-content-ltr" dir="ltr"><pre>response = MD5(HA1:nonce:HA2)
</pre></div></dd></dl>
<p>The above shows that when qop is not specified, the simpler RFC 2069 standard is followed.
</p><p>In September 2015, RFC 7616 replaced RFC 2617 by adding 4 new <a href="Algorithm" title="Algorithm">algorithms</a>: "SHA-256", "SHA-256-sess", "SHA-512-256" and "SHA-512-256-sess". The encoding is equivalent to "MD5" and "MD5-sess" algorithms, with <a href="MD5" title="MD5">MD5 hashing function</a> replaced with <a href="SHA-256" class="mw-redirect" title="SHA-256">SHA-256</a> and <a href="SHA-256" class="mw-redirect" title="SHA-256">SHA-512-256</a>. However, as of July 2021, none of popular browsers, including Firefox<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> and Chrome,<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> support SHA-256 as the hash function. As of October 2021, Firefox 93<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> officially supports "SHA-256" and "SHA-256-sess" algorithms for digest authentication. However, support for "SHA-512-256", "SHA-512-256-sess" algorithms and username hashing<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> is still lacking.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> As of August 2023, Chromium 117 (then Chrome and Edge) supports "SHA-256".<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Impact_of_MD5_security_on_digest_authentication">Impact of MD5 security on digest authentication</h2></div>
<p>The <a href="MD5" title="MD5">MD5</a> calculations used in HTTP digest authentication is intended to be "<a href="One-way_function" title="One-way function">one way</a>", meaning that it should be difficult to determine the original input when only the output is known. If the password itself is too simple, however, then it may be possible to test all possible inputs and find a matching output (a <a href="Brute-force_attack" title="Brute-force attack">brute-force attack</a>) – perhaps aided by a <a href="Dictionary_attack" title="Dictionary attack">dictionary</a> or <a href="Rainbow_table" title="Rainbow table">suitable look-up list</a>, which for MD5 is readily available.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>
</p><p>The HTTP scheme was designed by <a href="Phillip_Hallam-Baker" title="Phillip Hallam-Baker">Phillip Hallam-Baker</a> at <a href="CERN" title="CERN">CERN</a> in 1993 and does not incorporate subsequent improvements in authentication systems, such as the development of keyed-hash message authentication code (<a href="HMAC" title="HMAC">HMAC</a>). Although the <a href="Cryptography" title="Cryptography">cryptographic</a> construction that is used is based on the MD5 hash function, <a href="Collision_attack" title="Collision attack">collision attacks</a> were in 2004 generally believed to not affect applications where the plaintext (i.e. password) is not known.<sup id="cite_ref-CryptoRes-2004_9-0" class="reference"><a href="#cite_note-CryptoRes-2004-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> However, claims in 2006<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> cause some doubt over other MD5 applications as well.
</p>
<div class="mw-heading mw-heading2"><h2 id="HTTP_digest_authentication_considerations">HTTP digest authentication considerations</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1251242444">
/* start https://en.wikipedia.org/ */
.mw-parser-output .ambox{border:1px solid #a2a9b1;border-left:10px solid #36c;background-color:#fbfbfb;box-sizing:border-box}.mw-parser-output .ambox+link+.ambox,.mw-parser-output .ambox+link+style+.ambox,.mw-parser-output .ambox+link+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+style+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+link+.ambox{margin-top:-1px}html body.mediawiki .mw-parser-output .ambox.mbox-small-left{margin:4px 1em 4px 0;overflow:hidden;width:238px;border-collapse:collapse;font-size:88%;line-height:1.25em}.mw-parser-output .ambox-speedy{border-left:10px solid #b32424;background-color:#fee7e6}.mw-parser-output .ambox-delete{border-left:10px solid #b32424}.mw-parser-output .ambox-content{border-left:10px solid #f28500}.mw-parser-output .ambox-style{border-left:10px solid #fc3}.mw-parser-output .ambox-move{border-left:10px solid #9932cc}.mw-parser-output .ambox-protection{border-left:10px solid #a2a9b1}.mw-parser-output .ambox .mbox-text{border:none;padding:0.25em 0.5em;width:100%}.mw-parser-output .ambox .mbox-image{border:none;padding:2px 0 2px 0.5em;text-align:center}.mw-parser-output .ambox .mbox-imageright{border:none;padding:2px 0.5em 2px 0;text-align:center}.mw-parser-output .ambox .mbox-empty-cell{border:none;padding:0;width:1px}.mw-parser-output .ambox .mbox-image-div{width:52px}@media(min-width:720px){.mw-parser-output .ambox{margin:0 10%}}@media print{body.ns-0 .mw-parser-output .ambox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style>
<div class="mw-heading mw-heading3"><h3 id="Advantages">Advantages</h3></div>
<p>HTTP digest authentication is designed to be more secure than traditional digest authentication schemes, for example "significantly stronger than (e.g.) <a href="CRAM-MD5" title="CRAM-MD5">CRAM-MD5</a> ..." (RFC 2617).
</p><p>Some of the security strengths of HTTP digest authentication are:
</p>
<ul><li>The password is not sent clear to the server.</li>
<li>The password is not used directly in the digest, but rather HA1 = MD5(username:realm:password). This allows some implementations (e.g. <a href="JBoss" class="mw-redirect" title="JBoss">JBoss</a><sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>) to store HA1 rather than the cleartext password (however, see disadvantages of this approach)</li>
<li>Client nonce was introduced in RFC 2617, which allows the client to prevent <a href="Chosen-plaintext_attack" title="Chosen-plaintext attack">chosen-plaintext attacks</a>, such as <a href="Rainbow_table" title="Rainbow table">rainbow tables</a> that could otherwise threaten digest authentication schemes</li>
<li>Server nonce is allowed to contain timestamps. Therefore, the server may inspect nonce attributes submitted by clients, to prevent <a href="Replay_attack" title="Replay attack">replay attacks</a></li>
<li>Server is also allowed to maintain a list of recently issued or used server nonce values to prevent reuse</li>
<li>It prevents <a href="Phishing" title="Phishing">Phishing</a> because the plain password is never sent to any server, be it the correct server or not. (Public key systems rely on the user being able to verify that the URL is correct.)</li></ul>
<div class="mw-heading mw-heading3"><h3 id="Disadvantages">Disadvantages</h3></div>
<p>There are several drawbacks with digest access authentication:
</p>
<ul><li>The website has no control over the user interface presented to the end user.</li>
<li>Many of the security options in RFC 2617 are optional. If quality-of-protection (qop) is not specified by the server, the client will operate in a security-reduced legacy RFC 2069 mode</li>
<li>Digest access authentication is vulnerable to a <a href="Man-in-the-middle_attack" title="Man-in-the-middle attack">man-in-the-middle (MITM) attack</a>. For example, a MITM attacker could tell clients to use basic access authentication or legacy RFC2069 digest access authentication mode. To extend this further, digest access authentication provides no mechanism for clients to verify the server's identity</li>
<li>A server can store HA1 = MD5(username:realm:password) instead of the password itself. However, if the stored HA1 is leaked, an attacker can generate valid responses and access documents in the realm just as easily as if they had access to the password itself. The table of HA1 values must therefore be protected as securely as a file containing plaintext passwords.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup></li>
<li>Digest access authentication prevents the use of a strong password hash (such as <a href="Bcrypt" title="Bcrypt">bcrypt</a>) when storing passwords (since either the password, or the digested username, realm and password must be recoverable)</li></ul>
<p>Also, since the <a href="MD5" title="MD5">MD5 algorithm</a> is not allowed in <a href="FIPS_140-2" title="FIPS 140-2">FIPS</a>, HTTP Digest authentication will not work with FIPS-certified<sup id="cite_ref-FIPS_approved_functions_13-0" class="reference"><a href="#cite_note-FIPS_approved_functions-13"><span class="cite-bracket">[</span>note 1<span class="cite-bracket">]</span></a></sup> crypto modules.
</p>
<div class="mw-heading mw-heading3"><h3 id="Alternative_authentication_protocols">Alternative authentication protocols</h3></div>
<p>By far the most common approach is to use a HTTP+HTML form-based authentication cleartext protocol, or more rarely <a href="Basic_access_authentication" title="Basic access authentication">Basic access authentication</a>. These weak cleartext protocols used together with <a href="HTTPS" title="HTTPS">HTTPS</a> network encryption resolve many of the threats that digest access authentication is designed to prevent. However, this use of HTTPS relies upon the end user to accurately validate that they are accessing the correct URL each time to prevent sending their password to an untrusted server, which results in <a href="Phishing" title="Phishing">phishing</a> attacks.
Users often fail to do this, which is why phishing has become the most common form of security breach.
</p><p>Some strong authentication protocols for web-based applications that are occasionally used include:
</p>
<ul><li><a href="Public_key" class="mw-redirect" title="Public key">Public key</a> authentication (usually implemented with a <a href="HTTPS" title="HTTPS">HTTPS</a> / <a href="Secure_Sockets_Layer" class="mw-redirect" title="Secure Sockets Layer">SSL</a> <a href="Client_certificate" title="Client certificate">client certificate</a>) using a client certificate.</li>
<li><a href="Kerberos_(protocol)" title="Kerberos (protocol)">Kerberos</a> or <a href="SPNEGO" title="SPNEGO">SPNEGO</a> authentication, employed for example by <a href="Microsoft_IIS" class="mw-redirect" title="Microsoft IIS">Microsoft IIS</a> running configured for <a href="Integrated_Windows_Authentication" title="Integrated Windows Authentication">Integrated Windows Authentication</a> (IWA).</li>
<li><a href="Secure_Remote_Password_protocol" title="Secure Remote Password protocol">Secure Remote Password protocol</a> (preferably within the <a href="HTTPS" title="HTTPS">HTTPS</a> / <a href="Transport_Layer_Security" title="Transport Layer Security">TLS</a> layer). However, this is not implemented by any mainstream browsers.</li>
<li><a href="JSON_Web_Token" title="JSON Web Token">JSON Web Token</a> (JWT) is a <a href="JSON" title="JSON">JSON</a>-based standard RFC 7519 for creating <a href="Access_token" title="Access token">access tokens</a> that assert some number of claims.</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Example_with_explanation">Example with explanation</h2></div>
<p>The following example was originally given in RFC 2617 and is expanded here to show the full text expected for each <a href="HTTP_request" class="mw-redirect" title="HTTP request">request</a> and <a href="HTTP_response" class="mw-redirect" title="HTTP response">response</a>. Note that only the "auth" (authentication) quality of protection code is covered – as of April 2005, only the <a href="Opera_(web_browser)" title="Opera (web browser)">Opera</a> and <a href="Konqueror" title="Konqueror">Konqueror</a> web browsers are known to support "auth-int" (authentication with integrity protection). Although the specification mentions HTTP version 1.1, the scheme can be successfully added to a version 1.0 server, as shown here.
</p><p>This typical transaction consists of the following steps:
</p>
<ol><li>The client asks for a page that requires authentication but does not provide a username and password.<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>note 2<span class="cite-bracket">]</span></a></sup> Typically this is because the user simply entered the address or followed a link to the page.</li>
<li>The server responds with the <a href="HTTP_401" class="mw-redirect" title="HTTP 401">401 "Unauthorized"</a> response code, providing the authentication realm and a randomly generated, single-use value called a <i><a href="Cryptographic_nonce" title="Cryptographic nonce">nonce</a></i>.</li>
<li>At this point, the browser will present the authentication realm (typically a description of the computer or system being accessed) to the user and prompt for a username and password. The user may decide to cancel at this point.</li>
<li>Once a username and password have been supplied, the client re-sends the same request but adds an authentication header that includes the response code.</li>
<li>In this example, the server accepts the authentication and the page is returned. If the username is invalid and/or the password is incorrect, the server might return the "401" response code and the client would prompt the user again.</li></ol>
<hr>
<dl><dt>Client request (no authentication)</dt>
<dd></dd></dl>
<div class="mw-highlight mw-highlight-lang-http mw-content-ltr" dir="ltr"><pre><span class="nf">GET</span> <span class="nn">/dir/index.html</span> <span class="kr">HTTP</span><span class="o">/</span><span class="m">1.0</span>
<span class="na">Host</span><span class="o">:</span> <span class="l">localhost</span>
</pre></div>
<p>(followed by a <a href="Newline" title="Newline">new line</a>, in the form of a <a href="Carriage_return" title="Carriage return">carriage return</a> followed by a <a href="Line_feed" class="mw-redirect" title="Line feed">line feed</a>).<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p>
<dl><dt>Server response</dt>
<dd></dd></dl>
<div class="mw-highlight mw-highlight-lang-http mw-content-ltr" dir="ltr"><pre><span class="kr">HTTP</span><span class="o">/</span><span class="m">1.0</span> <span class="m">401</span> <span class="ne">Unauthorized</span>
<span class="na">Server</span><span class="o">:</span> <span class="l">HTTPd/0.9</span>
<span class="na">Date</span><span class="o">:</span> <span class="l">Sun, 10 Apr 2014 20:26:47 GMT</span>
<span class="na">WWW-Authenticate</span><span class="o">:</span> <span class="l">Digest realm="testrealm@host.com",</span>
<span class="l">qop="auth,auth-int",</span>
<span class="l">nonce="dcd98b7102dd2f0e8b11d0f600bfb0c093",</span>
<span class="l">opaque="5ccc069c403ebaf9f0171e9517f40e41"</span>
<span class="na">Content-Type</span><span class="o">:</span> <span class="l">text/html</span>
<span class="na">Content-Length</span><span class="o">:</span> <span class="l">153</span>
<span class="cp"><!DOCTYPE html></span>
<span class="p"><</span><span class="nt">html</span><span class="p">></span>
<span class="p"><</span><span class="nt">head</span><span class="p">></span>
<span class="p"><</span><span class="nt">meta</span> <span class="na">charset</span><span class="o">=</span><span class="s">"UTF-8"</span> <span class="p">/></span>
<span class="p"><</span><span class="nt">title</span><span class="p">></span>Error<span class="p"></</span><span class="nt">title</span><span class="p">></span>
<span class="p"></</span><span class="nt">head</span><span class="p">></span>
<span class="p"><</span><span class="nt">body</span><span class="p">></span>
<span class="p"><</span><span class="nt">h1</span><span class="p">></span>401 Unauthorized.<span class="p"></</span><span class="nt">h1</span><span class="p">></span>
<span class="p"></</span><span class="nt">body</span><span class="p">></span>
<span class="p"></</span><span class="nt">html</span><span class="p">></span>
</pre></div>
<dl><dt>Client request (username "Mufasa", password "Circle Of Life")</dt>
<dd></dd></dl>
<div class="mw-highlight mw-highlight-lang-http mw-content-ltr" dir="ltr"><pre><span class="nf">GET</span> <span class="nn">/dir/index.html</span> <span class="kr">HTTP</span><span class="o">/</span><span class="m">1.0</span>
<span class="na">Host</span><span class="o">:</span> <span class="l">localhost</span>
<span class="na">Authorization</span><span class="o">:</span> <span class="l">Digest username="Mufasa",</span>
<span class="l">realm="testrealm@host.com",</span>
<span class="l">nonce="dcd98b7102dd2f0e8b11d0f600bfb0c093",</span>
<span class="l">uri="/dir/index.html",</span>
<span class="l">qop=auth,</span>
<span class="l">nc=00000001,</span>
<span class="l">cnonce="0a4f113b",</span>
<span class="l">response="6629fae49393a05397450978507c4ef1",</span>
<span class="l">opaque="5ccc069c403ebaf9f0171e9517f40e41"</span>
</pre></div>
<p>(followed by a blank line, as before).
</p>
<dl><dt>Server response</dt>
<dd></dd></dl>
<div class="mw-highlight mw-highlight-lang-http mw-content-ltr" dir="ltr"><pre><span class="kr">HTTP</span><span class="o">/</span><span class="m">1.0</span> <span class="m">200</span> <span class="ne">OK</span>
<span class="na">Server</span><span class="o">:</span> <span class="l">HTTPd/0.9</span>
<span class="na">Date</span><span class="o">:</span> <span class="l">Sun, 10 Apr 2005 20:27:03 GMT</span>
<span class="na">Content-Type</span><span class="o">:</span> <span class="l">text/html</span>
<span class="na">Content-Length</span><span class="o">:</span> <span class="l">7984</span>
</pre></div>
<p>(followed by a blank line and HTML text of the restricted page).
</p>
<hr>
<p>The "response" value is calculated in three steps, as follows. Where values are combined, they are <a href="Delimiter" title="Delimiter">delimited</a> by colons.
</p>
<ol><li>The MD5 hash of the combined username, authentication realm and password is calculated. The result is referred to as HA1.</li>
<li>The MD5 hash of the combined method and digest <a href="Uniform_Resource_Identifier" title="Uniform Resource Identifier">URI</a> is calculated, e.g. of <code>"GET"</code> and <code>"/dir/index.html"</code>. The result is referred to as HA2.</li>
<li>The MD5 hash of the combined HA1 result, server nonce (nonce), request counter (nc), client nonce (cnonce), quality of protection code (qop) and HA2 result is calculated. The result is the "response" value provided by the client.</li></ol>
<p>Since the server has the same information as the client, the response can be checked by performing the same calculation. In the example given above the result is formed as follows, where <code>MD5()</code> represents a function used to calculate an <a href="MD5_hash" class="mw-redirect" title="MD5 hash">MD5 hash</a>, backslashes represent a continuation and the quotes shown are not used in the calculation.
</p><p>Completing the example given in RFC 2617 gives the following results for each step.
</p>
<pre> HA1 = MD5( "Mufasa:testrealm@host.com:Circle Of Life" )
= 939e7578ed9e3c518a452acee763bce9
HA2 = MD5( "GET:/dir/index.html" )
= 39aff3a2bab6126f332b942af96d3366
Response = MD5( "939e7578ed9e3c518a452acee763bce9:\
dcd98b7102dd2f0e8b11d0f600bfb0c093:\
00000001:0a4f113b:auth:\
39aff3a2bab6126f332b942af96d3366" )
= 6629fae49393a05397450978507c4ef1
</pre>
<p>At this point the client may make another request, reusing the server nonce value (the server only issues a new nonce for each <a href="HTTP_401" class="mw-redirect" title="HTTP 401">"401" response</a>) but providing a new client nonce (cnonce). For subsequent requests, the hexadecimal request counter (nc) must be greater than the last value it used – otherwise an attacker could simply "<a href="Replay_attack" title="Replay attack">replay</a>" an old request with the same credentials. It is up to the server to ensure that the counter increases for each of the nonce values that it has issued, rejecting any bad requests appropriately. Obviously changing the method, URI and/or counter value will result in a different response value.
</p><p>The server should remember nonce values that it has recently generated. It may also remember when each nonce value was issued, expiring them after a certain amount of time. If an expired value is used, the server should respond with the "401" status code and add <code>stale=TRUE</code> to the authentication header, indicating that the client should re-send with the new nonce provided, without prompting the user for another username and password.
</p><p>The server does not need to keep any expired nonce values – it can simply assume that any unrecognised values have expired. It is also possible for the server to only allow each nonce value to be returned once, although this forces the client to repeat every request. Note that expiring a server nonce immediately will not work, as the client would never get a chance to use it.
</p>
<div class="mw-heading mw-heading2"><h2 id="The_.htdigest_file">The .htdigest file</h2></div>
<p>.htdigest is a <a href="Flat_file_database" class="mw-redirect" title="Flat file database">flat-file</a> used to store usernames, realm and passwords for digest authentication of <a href="Apache_HTTP_Server" title="Apache HTTP Server">Apache HTTP Server</a>. The name of the file is given in the <a href=".htaccess" title=".htaccess">.htaccess</a> configuration, and can be anything, but ".htdigest" is the canonical name. The file name starts with a dot, because most <a href="Unix-like" title="Unix-like">Unix-like</a> operating systems consider any file that begins with dot to be hidden. This file is often maintained with the <a href="Shell_(computing)" title="Shell (computing)">shell</a> command "htdigest" which can add, and update users, and will properly encode the password for use.
</p><p>The "htdigest" command is found in the <b>apache2-utils</b> package on <a href="Dpkg" title="Dpkg">dpkg</a> package management systems and the <b>httpd-tools</b> package on <a href="RPM_Package_Manager" title="RPM Package Manager">RPM package management</a> systems.
</p><p>The syntax of the htdigest command:<sup id="cite_ref-htdigest_16-0" class="reference"><a href="#cite_note-htdigest-16"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup>
</p>
<pre>htdigest [ -c ] <i>passwdfile realm username</i>
</pre>
<p>The format of the .htdigest file:<sup id="cite_ref-htdigest_16-1" class="reference"><a href="#cite_note-htdigest-16"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup>
</p>
<pre>user1:Realm:5ea41921c65387d904834f8403185412
user2:Realm:734418f1e487083dc153890208b79379
</pre>
<div class="mw-heading mw-heading2"><h2 id="SIP_digest_authentication">SIP digest authentication</h2></div>
<p><a href="Session_Initiation_Protocol" title="Session Initiation Protocol">Session Initiation Protocol</a> (SIP) uses basically the same digest authentication algorithm. It is specified by RFC 3261.
</p>
<div class="mw-heading mw-heading2"><h2 id="Browser_implementation">Browser implementation</h2></div>
<p>Most browsers have substantially implemented the spec, some barring certain features such as auth-int checking or the MD5-sess algorithm. If the server requires that these optional features be handled, clients may not be able to authenticate (though note mod_auth_digest for Apache does not fully implement RFC 2617 either).
</p>
<ul><li><a href="Amaya_(web_browser)" class="mw-redirect" title="Amaya (web browser)">Amaya</a></li>
<li><a href="Gecko_(layout_engine)" class="mw-redirect" title="Gecko (layout engine)">Gecko</a>-based: (not including auth-int<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup>)
<ul><li><a href="Mozilla_Application_Suite" title="Mozilla Application Suite">Mozilla Application Suite</a></li>
<li><a href="Mozilla_Firefox" class="mw-redirect" title="Mozilla Firefox">Mozilla Firefox</a></li>
<li><a href="Netscape_(version_7)" class="mw-redirect" title="Netscape (version 7)">Netscape 7+</a></li></ul></li>
<li><a href="ICab" title="ICab">iCab 3.0.3+</a></li>
<li><a href="KHTML" title="KHTML">KHTML</a>- and <a href="WebKit" title="WebKit">WebKit</a>-based: (not including auth-int<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup>)
<ul><li><a href="ICab" title="ICab">iCab</a> 4</li>
<li><a href="Konqueror" title="Konqueror">Konqueror</a></li>
<li><a href="Google_Chrome" title="Google Chrome">Google Chrome</a></li>
<li><a href="Safari_(web_browser)" title="Safari (web browser)">Safari</a></li></ul></li>
<li><a href="Tasman_(layout_engine)" class="mw-redirect" title="Tasman (layout engine)">Tasman</a>-based:
<ul><li><a href="Internet_Explorer_for_Mac" title="Internet Explorer for Mac">Internet Explorer for Mac</a></li></ul></li>
<li><a href="Trident_(layout_engine)" class="mw-redirect" title="Trident (layout engine)">Trident</a>-based:
<ul><li><a href="Internet_Explorer_5" title="Internet Explorer 5">Internet Explorer 5+</a><sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> (not including auth-int)</li></ul></li>
<li><a href="Presto_(layout_engine)" class="mw-redirect" title="Presto (layout engine)">Presto</a>-based:
<ul><li><a href="Opera_(web_browser)" title="Opera (web browser)">Opera</a> (Opera switched away from Presto in 2013)<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Opera_Mobile" title="Opera Mobile">Opera Mobile</a></li>
<li><a href="Opera_Mini" title="Opera Mini">Opera Mini</a></li>
<li><a href="Nintendo_DS_Browser" title="Nintendo DS Browser">Nintendo DS Browser</a></li>
<li><a href="Nokia_770" class="mw-redirect" title="Nokia 770">Nokia 770</a> Browser</li>
<li><a href="Mylo_(Sony)" title="Mylo (Sony)">Sony Mylo 1</a>'s Browser</li>
<li><a href="Wii_browser" class="mw-redirect" title="Wii browser">Wii Internet Channel Browser</a></li></ul></li></ul>
<div class="mw-heading mw-heading2"><h2 id="Deprecations">Deprecations</h2></div>
<p>Because of the disadvantages of Digest authentication compared to Basic authentication over HTTPS it has been deprecated by a lot of software e.g.:
</p>
<ul><li>Bitbucket<sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup></li>
<li>Symfony PHP framework<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="AKA_(security)" class="mw-redirect" title="AKA (security)">AKA (security)</a></li>
<li><a href="JSON_Web_Token" title="JSON Web Token">JSON Web Token</a> (JWT)</li>
<li><a href="Basic_access_authentication" title="Basic access authentication">Basic access authentication</a></li>
<li>HTTP+HTML form-based authentication</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Notes">Notes</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-FIPS_approved_functions-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-FIPS_approved_functions_13-0">^</a></b></span> <span class="reference-text">The following is a list of FIPS approved algorithms: <cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://csrc.nist.gov/publications/fips/fips140-2/fips1402annexa.pdf">"Annex A: Approved Security Functions for FIPS PUB 140-2, Security Requirements for Cryptographic Modules"</a> <span class="cs1-format">(PDF)</span>. National Institute of Standards and Technology. January 31, 2014.</cite></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text">A client may already have the required username and password without needing to prompt the user, e.g. if they have previously been stored by a web browser.</span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc6331">Moving DIGEST-MD5 to Historic, July 2011</a>.</span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://bugzilla.mozilla.org/show_bug.cgi?id=472823">"Bug 472823: SHA 256 Digest Authentication"</a>. <i>Mozilla Bugzilla</i>.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://bugs.chromium.org/p/chromium/issues/detail?id=1160478">"Issue 1160478: SHA-256 for HTTP Digest Access Authentication in accordance with rfc7616"</a>. <i>Chromium bugs</i>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://bugzilla.mozilla.org/show_bug.cgi?id=472823">"Bug 472823: SHA 256 Digest Authentication"</a>. <i>Mozilla Bugzilla</i>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7616#section-3.4.4">"IETF.org: RFC 7616 Username Hashing"</a>. <i>Ietf Datatracker</i>. 30 September 2015.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://hg.mozilla.org/mozilla-central/rev/7a4994734e00">"Mozilla-central: support SHA-256 HTTP Digest auth"</a>. <i>Mozilla-central</i>.</cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://chromestatus.com/feature/5139896267702272?context=myfeatures">"Chrome Feature: RFC 7616 Digest auth: Support SHA-256 and username hashing"</a>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://project-rainbowcrack.com/table.htm">List of rainbow tables, Project Rainbowcrack</a>. Includes multiple MD5 rainbow tables.</span>
</li>
<li id="cite_note-CryptoRes-2004-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-CryptoRes-2004_9-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20100306180648/http://www.cryptography.com/cnews/hash.html">"Hash Collision Q&A"</a>. <a href="Cryptography_Research" title="Cryptography Research">Cryptography Research</a>. 2005-02-16. Archived from <a rel="nofollow" class="external text" href="http://www.cryptography.com/cnews/hash.html">the original</a> on 2010-03-06.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite id="CITEREFJongsung_KimAlex_BiryukovBart_PreneelSeokhie_Hong" class="citation web cs1">Jongsung Kim; Alex Biryukov; Bart Preneel; Seokhie Hong. <a rel="nofollow" class="external text" href="https://eprint.iacr.org/2006/187.pdf">"On the Security of HMAC and NMAC Based on HAVAL, MD4, MD5, SHA-0 and SHA-1"</a> <span class="cs1-format">(PDF)</span>. <a href="International_Association_for_Cryptologic_Research" title="International Association for Cryptologic Research">IACR</a>.</cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite id="CITEREFScott_Stark2005" class="citation web cs1">Scott Stark (2005-10-08). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20151018155102/https://community.jboss.org/wiki/DIGESTAuth">"DIGEST Authentication (4.0.4+)"</a>. <a href="JBoss" class="mw-redirect" title="JBoss">JBoss</a>. Archived from <a rel="nofollow" class="external text" href="https://community.jboss.org/wiki/DIGESTAuth">the original</a> on 2015-10-18<span class="reference-accessdate">. Retrieved <span class="nowrap">2013-03-04</span></span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite id="CITEREFFranksHallam-BakerHostetlerLawrence1999" class="citation journal cs1">Franks, J.; Hallam-Baker, P.; Hostetler, J.; Lawrence, S.; Leach, P.; Luotonen, A.; Stewart, L. (June 1999). <span class="id-lock-subscription" title="Paid subscription required"><a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc2617#section-4.13">"HTTP Authentication: Basic and Digest Access Authentication: Storing passwords"</a></span>. <a href="IETF" class="mw-redirect" title="IETF">IETF</a>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC2617">10.17487/RFC2617</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:27137261">27137261</a>.</cite> <span class="cs1-visible-error citation-comment"><code class="cs1-code">{{cite journal}}</code>: </span><span class="cs1-visible-error citation-comment">Cite journal requires <code class="cs1-code">|journal=</code> (help)</span></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite id="CITEREFTim_Berners-Lee,_Roy_Fielding,_Henrik_Frystyk_Nielsen1996" class="citation web cs1"><a href="Tim_Berners-Lee" title="Tim Berners-Lee">Tim Berners-Lee</a>, <a href="Roy_Fielding" title="Roy Fielding">Roy Fielding</a>, <a href="Henrik_Frystyk_Nielsen" title="Henrik Frystyk Nielsen">Henrik Frystyk Nielsen</a> (1996-02-19). <a rel="nofollow" class="external text" href="http://www.w3.org/Protocols/HTTP/1.0/spec.html#Request">"Hypertext Transfer Protocol -- HTTP/1.0: Request"</a>. <a href="W3C" class="mw-redirect" title="W3C">W3C</a>.</cite><span class="cs1-maint citation-comment"><code class="cs1-code">{{cite web}}</code>: CS1 maint: multiple names: authors list (link)</span></span>
</li>
<li id="cite_note-htdigest-16"><span class="mw-cite-backlink">^ <a href="#cite_ref-htdigest_16-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-htdigest_16-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://httpd.apache.org/docs/2.2/programs/htdigest.html">"htdigest - manage user files for digest authentication"</a>. <i>apache.org</i>.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite id="CITEREFEmanuel_Corthay2002" class="citation web cs1">Emanuel Corthay (2002-09-16). <a rel="nofollow" class="external text" href="https://bugzilla.mozilla.org/show_bug.cgi?id=168942">"Bug 168942 - Digest authentication with integrity protection"</a>. <i><a href="Mozilla" title="Mozilla">Mozilla</a></i>.</cite></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-18">^</a></b></span> <span class="reference-text"><cite id="CITEREFTimothy_D._Morgan2010" class="citation web cs1">Timothy D. Morgan (2010-01-05). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20140714192236/https://secure.vsecurity.com/download/papers/HTTPDigestIntegrity.pdf">"HTTP Digest Integrity: Another look, in light of recent attacks"</a> <span class="cs1-format">(PDF)</span>. vsecurity.com. Archived from <a rel="nofollow" class="external text" href="https://secure.vsecurity.com/download/papers/HTTPDigestIntegrity.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 2014-07-14.</cite></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://technet.microsoft.com/en-us/library/cc738318(v=ws.10).aspx">"TechNet Digest Authentication"</a>. August 2013.</cite></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-20">^</a></b></span> <span class="reference-text"><cite id="CITEREFAnthony2013" class="citation web cs1">Anthony, Sebastian (February 13, 2013). <a rel="nofollow" class="external text" href="https://www.extremetech.com/computing/148312-opera-drops-presto-switch-to-google-and-apples-webkit-rendering-engine">"Opera admits defeat, switches to Google's Chromium"</a>. <i>Extreme Tech</i>. Ziff Davis<span class="reference-accessdate">. Retrieved <span class="nowrap">19 January</span> 2024</span>.</cite></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite id="CITEREFDeLorenzo2015" class="citation web cs1">DeLorenzo, Ike (2015-04-03). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20240423145906/https://bitbucket.org/blog/fare-thee-well-digest-access-authentication">"Fare-thee-well, Digest access authentication"</a>. <i>Bitbucet</i>. Archived from <a rel="nofollow" class="external text" href="https://bitbucket.org/blog/fare-thee-well-digest-access-authentication">the original</a> on 2024-04-23<span class="reference-accessdate">. Retrieved <span class="nowrap">2025-01-21</span></span>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20231012074234/https://github.com/symfony/symfony/issues/24325">"[RFC] Deprecate HTTP Digest authentication · Issue #24325 · symfony/symfony"</a>. <i>GitHub</i>. Archived from <a rel="nofollow" class="external text" href="https://github.com/symfony/symfony/issues/24325">the original</a> on 2023-10-12<span class="reference-accessdate">. Retrieved <span class="nowrap">2025-01-21</span></span>.</cite></span>
</li>
</ol></div></div>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */
.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Cryptographic_hash_functions_and_message_authentication_codes539" style="padding:3px"><table class="nowraplinks hlist mw-collapsible mw-collapsed navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><div id="Cryptographic_hash_functions_and_message_authentication_codes539" style="font-size:114%;margin:0 4em"><a href="Cryptographic_hash_function" title="Cryptographic hash function">Cryptographic hash functions</a> and <a href="Message_authentication_code" title="Message authentication code">message authentication codes</a></div></th></tr><tr><td class="navbox-abovebelow" colspan="2"><div>
<ul><li><a href="List_of_hash_functions" title="List of hash functions">List</a></li>
<li><a href="Comparison_of_cryptographic_hash_functions" title="Comparison of cryptographic hash functions">Comparison</a></li>
<li><a href="Hash_function_security_summary" title="Hash function security summary">Known attacks</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Common functions</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="MD5" title="MD5">MD5</a> (compromised)</li>
<li><a href="SHA-1" title="SHA-1">SHA-1</a> (compromised)</li>
<li><a href="SHA-2" title="SHA-2">SHA-2</a></li>
<li><a href="SHA-3" title="SHA-3">SHA-3</a></li>
<li><a href="BLAKE_(hash_function)#BLAKE2" title="BLAKE (hash function)">BLAKE2</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="NIST_hash_function_competition" title="NIST hash function competition">SHA-3 finalists</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="BLAKE_(hash_function)" title="BLAKE (hash function)">BLAKE</a></li>
<li><a href="Gr%C3%B8stl" title="Grøstl">Grøstl</a></li>
<li><a href="JH_(hash_function)" title="JH (hash function)">JH</a></li>
<li><a href="Skein_(hash_function)" title="Skein (hash function)">Skein</a></li>
<li><a href="SHA-3" title="SHA-3">Keccak</a> (winner)</li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Other functions</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="BLAKE3" class="mw-redirect" title="BLAKE3">BLAKE3</a></li>
<li><a href="CubeHash" title="CubeHash">CubeHash</a></li>
<li><a href="Elliptic_curve_only_hash" title="Elliptic curve only hash">ECOH</a></li>
<li><a href="Fast_syndrome-based_hash" title="Fast syndrome-based hash">FSB</a></li>
<li><a href="Fugue_(hash_function)" title="Fugue (hash function)">Fugue</a></li>
<li><a href="GOST_(hash_function)" title="GOST (hash function)">GOST</a></li>
<li><a href="HAS-160" title="HAS-160">HAS-160</a></li>
<li><a href="HAVAL" title="HAVAL">HAVAL</a></li>
<li><a href="Kupyna" title="Kupyna">Kupyna</a></li>
<li><a href="LSH_(hash_function)" title="LSH (hash function)">LSH</a></li>
<li><a href="Lane_(hash_function)" title="Lane (hash function)">Lane</a></li>
<li><a href="MASH-1" title="MASH-1">MASH-1</a></li>
<li><a href="MASH-1#MASH2" title="MASH-1">MASH-2</a></li>
<li><a href="MD2_(hash_function)" title="MD2 (hash function)">MD2</a></li>
<li><a href="MD4" title="MD4">MD4</a></li>
<li><a href="MD6" title="MD6">MD6</a></li>
<li><a href="MDC-2" title="MDC-2">MDC-2</a></li>
<li><a href="N-hash" title="N-hash">N-hash</a></li>
<li><a href="RIPEMD" title="RIPEMD">RIPEMD</a></li>
<li><a href="RadioGat%C3%BAn" title="RadioGatún">RadioGatún</a></li>
<li><a href="SIMD_(hash_function)" title="SIMD (hash function)">SIMD</a></li>
<li><a href="SM3_(hash_function)" title="SM3 (hash function)">SM3</a></li>
<li><a href="SWIFFT" title="SWIFFT">SWIFFT</a></li>
<li><a href="Shabal" title="Shabal">Shabal</a></li>
<li><a href="Snefru" title="Snefru">Snefru</a></li>
<li><a href="Streebog" title="Streebog">Streebog</a></li>
<li><a href="Tiger_(hash_function)" title="Tiger (hash function)">Tiger</a></li>
<li><a href="Very_smooth_hash" title="Very smooth hash">VSH</a></li>
<li><a href="Whirlpool_(hash_function)" title="Whirlpool (hash function)">Whirlpool</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Password hashing/<br><a href="Key_stretching" title="Key stretching">key stretching</a> functions</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Argon2" title="Argon2">Argon2</a></li>
<li><a href="Balloon_hashing" title="Balloon hashing">Balloon</a></li>
<li><a href="Bcrypt" title="Bcrypt">bcrypt</a></li>
<li><a href="Catena_(cryptography)" class="mw-redirect" title="Catena (cryptography)">Catena</a></li>
<li><a href="Crypt_(C)" title="Crypt (C)">crypt</a></li>
<li><a href="LAN_Manager#LM_hash_details" title="LAN Manager">LM hash</a></li>
<li><a href="Lyra2" title="Lyra2">Lyra2</a></li>
<li><a href="Makwa_(cryptography)" class="mw-redirect" title="Makwa (cryptography)">Makwa</a></li>
<li><a href="PBKDF2" title="PBKDF2">PBKDF2</a></li>
<li><a href="Scrypt" title="Scrypt">scrypt</a></li>
<li><a href="Yescrypt" title="Yescrypt">yescrypt</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">General purpose<br><a href="Key_derivation_function" title="Key derivation function">key derivation functions</a></th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="HKDF" title="HKDF">HKDF</a></li>
<li>KDF1/KDF2</li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Message_authentication_code" title="Message authentication code">MAC functions</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="CBC-MAC" title="CBC-MAC">CBC-MAC</a></li>
<li><a href="Data_Authentication_Algorithm" title="Data Authentication Algorithm">DAA</a></li>
<li><a href="Galois_Message_Authentication_Code" class="mw-redirect" title="Galois Message Authentication Code">GMAC</a></li>
<li><a href="HMAC" title="HMAC">HMAC</a></li>
<li><a href="NMAC" class="mw-redirect" title="NMAC">NMAC</a></li>
<li><a href="One-key_MAC" title="One-key MAC">OMAC</a>/<a href="One-key_MAC" title="One-key MAC">CMAC</a></li>
<li><a href="PMAC_(cryptography)" title="PMAC (cryptography)">PMAC</a></li>
<li><a href="Poly1305" title="Poly1305">Poly1305</a></li>
<li><a href="SipHash" title="SipHash">SipHash</a></li>
<li><a href="UMAC_(cryptography)" title="UMAC (cryptography)">UMAC</a></li>
<li><a href="VMAC" title="VMAC">VMAC</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Authenticated_encryption" title="Authenticated encryption">Authenticated<br>encryption</a> modes</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="CCM_mode" title="CCM mode">CCM</a></li>
<li><a href="ChaCha20-Poly1305" title="ChaCha20-Poly1305">ChaCha20-Poly1305</a></li>
<li><a href="CWC_mode" title="CWC mode">CWC</a></li>
<li><a href="EAX_mode" title="EAX mode">EAX</a></li>
<li><a href="Galois/Counter_Mode" title="Galois/Counter Mode">GCM</a></li>
<li><a href="IAPM_(mode)" title="IAPM (mode)">IAPM</a></li>
<li><a href="OCB_mode" title="OCB mode">OCB</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Attacks</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Collision_attack" title="Collision attack">Collision attack</a></li>
<li><a href="Preimage_attack" title="Preimage attack">Preimage attack</a></li>
<li><a href="Birthday_attack" title="Birthday attack">Birthday attack</a></li>
<li><a href="Brute-force_attack" title="Brute-force attack">Brute-force attack</a></li>
<li><a href="Rainbow_table" title="Rainbow table">Rainbow table</a></li>
<li><a href="Side-channel_attack" title="Side-channel attack">Side-channel attack</a></li>
<li><a href="Length_extension_attack" title="Length extension attack">Length extension attack</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Design</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Avalanche_effect" title="Avalanche effect">Avalanche effect</a></li>
<li><a href="Hash_collision" title="Hash collision">Hash collision</a></li>
<li><a href="Merkle%E2%80%93Damg%C3%A5rd_construction" title="Merkle–Damgård construction">Merkle–Damgård construction</a></li>
<li><a href="Sponge_function" title="Sponge function">Sponge function</a></li>
<li><a href="HAIFA_construction" title="HAIFA construction">HAIFA construction</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Standardization</th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="CAESAR_Competition" title="CAESAR Competition">CAESAR Competition</a></li>
<li><a href="CRYPTREC" title="CRYPTREC">CRYPTREC</a></li>
<li><a href="NESSIE" title="NESSIE">NESSIE</a></li>
<li><a href="NIST_hash_function_competition" title="NIST hash function competition">NIST hash function competition</a></li>
<li><a href="Password_Hashing_Competition" title="Password Hashing Competition">Password Hashing Competition</a></li>
<li><a href="NSA_Suite_B_Cryptography" title="NSA Suite B Cryptography">NSA Suite B</a></li>
<li><a href="Commercial_National_Security_Algorithm_Suite" title="Commercial National Security Algorithm Suite">CNSA</a></li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%">Utilization</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="Post-quantum_cryptography#Hash-based_cryptography" title="Post-quantum cryptography">Hash-based cryptography</a></li>
<li><a href="Merkle_tree" title="Merkle tree">Merkle tree</a></li>
<li><a href="Message_authentication" title="Message authentication">Message authentication</a></li>
<li><a href="Proof_of_work" title="Proof of work">Proof of work</a></li>
<li><a href="Salt_(cryptography)" title="Salt (cryptography)">Salt</a></li>
<li><a href="Pepper_(cryptography)" title="Pepper (cryptography)">Pepper</a></li></ul>
</div></td></tr></tbody></table></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc7235">RFC 7235</a></li>
<li><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc6331">RFC 6331</a></li>
<li><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc2617">RFC 2617</a> (updated by RFC 7235)</li>
<li><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc2069">RFC 2069</a> (obsolete)</li></ul></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-05-25" href="https://en.wikipedia.org/wiki/?title=Digest_access_authentication&oldid=1292087383">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>