04-18-2019, 08:26 PM
the domain is actually not used in computing the response and therefore can be skipped/ignored/anything, but the client challenge must be specified (e.g. 338d08f8e26de93300000000000000000000000000000000 in the example hash) if used (not empty).