OtpHashAlgorithm Enum
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- OtpHashAlgorithm.cs
Specifies the HMAC hash algorithm used to derive one-time-password codes, as permitted by the HOTP (RFC 4226) and TOTP (RFC 6238) specifications.
public enum OtpHashAlgorithm
- Extension Methods
Fields
Sha1 = 0HMAC-SHA-1. The RFC 4226 default and the most widely supported authenticator algorithm.
Sha256 = 1HMAC-SHA-256.
Sha512 = 2HMAC-SHA-512.
Remarks
The three members correspond exactly to the algorithms admitted by RFC 6238 and to the algorithm label used
in the otpauth:// provisioning URI (SHA1, SHA256, SHA512). No other hash algorithm is
valid for one-time passwords, so - unlike HashAlgorithmName - this
closed enumeration cannot express an unsupported choice.
Sha1 is the default because RFC 4226 mandates HMAC-SHA-1 and it remains the algorithm most widely interoperable with authenticator applications; its use here is a message-authentication construction, not a collision-resistance one, so SHA-1 carries no practical weakness in this role.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |