Open Neustradamus opened 5 years ago
SCRAM-SHA-256 and SCRAM-SHA-512 have been added:
@Neustradamus, We don't have plans to implement SASL SCRAM soon yet, but will put it into our roadmap. If you implement SASL SCRAM by yourself, it will be very appreciated.
@maximthomas: I do not understand, it is in OpenDJ no?
@Neustradamus yes, it is OpenDJ
@maximthomas: Not up-to-date?
"When using the SASL SCRAM mechanism, the SCRAM-SHA-256-PLUS variant SHOULD be preferred over the SCRAM-SHA-256 variant, and SHA-256 variants [RFC7677] SHOULD be preferred over SHA-1 variants [RFC5802]".
Can you add support for?
SCRAM-SHA-1(-PLUS): -- https://tools.ietf.org/html/rfc5802 -- https://tools.ietf.org/html/rfc6120
SCRAM-SHA-256(-PLUS): -- https://tools.ietf.org/html/rfc7677 since 2015-11-02 -- https://tools.ietf.org/html/rfc8600 since 2019-06-21: https://mailarchive.ietf.org/arch/msg/ietf-announce/suJMmeMhuAOmGn_PJYgX5Vm8lNA
LDAP:
I add SCRAM-SHA-512(-PLUS): https://xmpp.org/extensions/inbox/hash-recommendations.html
Linked to: