Pineconium / OpenVideoHosting

A new video hosting engine!
GNU General Public License v3.0
3 stars 1 forks source link

SCRAM-SHA-1(-PLUS) + SCRAM-SHA-256(-PLUS) + SCRAM-SHA-512(-PLUS) + SCRAM-SHA3-512(-PLUS) supports #2

Open Neustradamus opened 4 days ago

Neustradamus commented 4 days ago

Dear @Pineconium,

Your project is very good!

For have a perfect security point of view, can you add supports of :

"When using the SASL SCRAM mechanism, the SCRAM-SHA-256-PLUS variant SHOULD be preferred over the SCRAM-SHA-256 variant, and SHA-256 variants [RFC7677] SHOULD be preferred over SHA-1 variants [RFC5802]".

https://xmpp.org/extensions/inbox/hash-recommendations.html

-PLUS variants:

IMAP:

LDAP:

HTTP:

2FA:

IANA:

Linked to:

Pineconium commented 4 days ago

I guess I can look into that sooner or later, I'll probably do the rest of the stuff first then do security stuff