a Secarta project ...

HTTPsec Authentication Protocol


Preamble

4.6. nonce

The nonce directive in an initialization request allows the requester to send a random value to the responder. This acts as an authentication challenge to the responder, who is challenged to posses the correct private key in order to create a valid signature directive in the initialization response.

This value is a base64 encoded 256 bit cryptographic-quality random value, which MUST be generated afresh by the requester for each new initialization.