Open Neustradamus opened 5 years ago
Just tried to debug cyrus-sasl. SCRAM-SHA-256 definitely works. But cyrus-sasl's scram plugin has a mechanism prioritization bug. I'll PR them.
@Ri0n: It is done now no? :)
We can compile our own embedded version of cyrus-sasl to make scram working everywhere. Some distros won't accept it though. But at least it will work on Windows
@Ri0n: It is possible to do?
Dear @psi-im and @psi-plus teams, @Ri0n, @Vitozz, @tehnick, @drizt,
It is possible to comment this important Qt ticket about Channel Binding?
It is to needed to have support of SCRAM-SHA-*-PLUS variants.
Recently, we have seen the jabber.ru MITM:
Thanks in advance.
After:
Can you add supports of :
A "big" list has been done in last link of this ticket.
SCRAM-SHA-1(-PLUS):
SCRAM-SHA-256(-PLUS):
SCRAM-SHA-512(-PLUS):
SCRAM-SHA3-512(-PLUS):
SCRAM BIS: Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API Mechanisms:
-PLUS variants:
IMAP:
LDAP:
HTTP:
JMAP:
2FA:
IANA:
Linked to: