the CookieAuthentication section in our spec seems to assume we're

still using the v0 control protocol.


svn:r6559
This commit is contained in:
Roger Dingledine 2006-06-07 06:53:43 +00:00
parent 8cf45df230
commit 003561fa64

View File

@ -771,6 +771,11 @@ $Id$
file named "control_auth_cookie" into its data directory. To authenticate,
the controller must send the contents of this file.
[With the v1 controller protocol, what we really mean is that you should
send the base16 of the contents of this file. Is this it, or is there
more to it? Should we write a control_auth_cookie.asc file too that
makes this step easier for people doing it manually? -RD]
If the 'HashedControlPassword' option is set, it must contain the salted
hash of a secret password. The salted hash is computed according to the
S2K algorithm in RFC 2440 (OpenPGP), and prefixed with the s2k specifier.