Closed Neustradamus closed 10 months ago
Thank you. I have no plans to add SCRAM methods to the SMTP-server module. Honestly, I don't see any value in SCRAM in the context of TLS and as such, I do not have any time to spend on it. However, I am willing to accept pull requests if you would implement this functionality for the SMTP-server module yourself.
@andris9: It is not only for SMTP, there are IMAP, POP3 too. It is in RFC and it is the best security solution.
You can see here a list of products:
You are in the NOTHING list.
Do not forget to remove all old and unsecure mechanisms for security of users...
I'll gladly accept any pull requests that would add these mechanisms for SMTP, POP3 and IMAP.
Badly, I will not do it, I have informed the @nodemailer team. But for people: ticket closed = it is solved. Currently nodemailer & co are not secure. Time to reopen it.
The entire Nodemailer team is just me. This is why I don't have time to add all these additional features, and I'm expecting PRs from interested parties.
@andris9: I see, I invite you to look to improve and secure the project...
Please to do not close an unsolved ticket.
Dear @nodemailer team,
Can you add supports of :
You can add too:
"When using the SASL SCRAM mechanism, the SCRAM-SHA-256-PLUS variant SHOULD be preferred over the SCRAM-SHA-256 variant, and SHA-256 variants [RFC7677] SHOULD be preferred over SHA-1 variants [RFC5802]".
SCRAM-SHA-1(-PLUS): -- https://tools.ietf.org/html/rfc5802 -- https://tools.ietf.org/html/rfc6120
SCRAM-SHA-256(-PLUS): -- https://tools.ietf.org/html/rfc7677 since 2015-11-02 -- https://tools.ietf.org/html/rfc8600 since 2019-06-21: https://mailarchive.ietf.org/arch/msg/ietf-announce/suJMmeMhuAOmGn_PJYgX5Vm8lNA
SCRAM-SHA-512(-PLUS): -- https://tools.ietf.org/html/draft-melnikov-scram-sha-512
SCRAM-SHA3-512(-PLUS): -- https://tools.ietf.org/html/draft-melnikov-scram-sha3-512
SCRAM BIS: Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API Mechanisms: -- https://tools.ietf.org/html/draft-melnikov-scram-bis
https://xmpp.org/extensions/inbox/hash-recommendations.html
-PLUS variants:
IMAP:
LDAP:
HTTP:
2FA:
IANA:
Linked to: