Now we're allowing a lower bound for auth_len, ensure we