You could go one step further and have the server store an augmented PAKE authenticator derived from the crypt(3) output.
You could go one step further and have the server store an augmented PAKE authenticator derived from the crypt(3) output.