5.1 Security Considerations for Implementers

The server should ensure that the nonce that it generates is short-lived, and cannot be used by any client after a short period of time.<1>