-
-
Notifications
You must be signed in to change notification settings - Fork 146
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SCRAM-SHA-1(-PLUS) + SCRAM-SHA-256(-PLUS) + SCRAM-SHA-512(-PLUS) + SCRAM-SHA3-512(-PLUS) supports #202
Comments
Thank you. I have no plans to add SCRAM methods to the SMTP-server module. Honestly, I don't see any value in SCRAM in the context of TLS and as such, I do not have any time to spend on it. However, I am willing to accept pull requests if you would implement this functionality for the SMTP-server module yourself. |
@andris9: It is not only for SMTP, there are IMAP, POP3 too. You can see here a list of products: You are in the NOTHING list. Do not forget to remove all old and unsecure mechanisms for security of users... |
I'll gladly accept any pull requests that would add these mechanisms for SMTP, POP3 and IMAP. |
Badly, I will not do it, I have informed the @nodemailer team. |
The entire Nodemailer team is just me. This is why I don't have time to add all these additional features, and I'm expecting PRs from interested parties. |
@andris9: I see, I invite you to look to improve and secure the project... Please to do not close an unsolved ticket. |
Dear @nodemailer team,
Can you add supports of :
You can add too:
"When using the SASL SCRAM mechanism, the SCRAM-SHA-256-PLUS variant SHOULD be preferred over the SCRAM-SHA-256 variant, and SHA-256 variants [RFC7677] SHOULD be preferred over SHA-1 variants [RFC5802]".
SCRAM-SHA-1(-PLUS):
-- https://tools.ietf.org/html/rfc5802
-- https://tools.ietf.org/html/rfc6120
SCRAM-SHA-256(-PLUS):
-- https://tools.ietf.org/html/rfc7677 since 2015-11-02
-- https://tools.ietf.org/html/rfc8600 since 2019-06-21: https://mailarchive.ietf.org/arch/msg/ietf-announce/suJMmeMhuAOmGn_PJYgX5Vm8lNA
SCRAM-SHA-512(-PLUS):
-- https://tools.ietf.org/html/draft-melnikov-scram-sha-512
SCRAM-SHA3-512(-PLUS):
-- https://tools.ietf.org/html/draft-melnikov-scram-sha3-512
SCRAM BIS: Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API Mechanisms:
-- https://tools.ietf.org/html/draft-melnikov-scram-bis
https://xmpp.org/extensions/inbox/hash-recommendations.html
-PLUS variants:
IMAP:
LDAP:
HTTP:
2FA:
IANA:
Linked to:
The text was updated successfully, but these errors were encountered: