View Issue Details

IDProjectCategoryView StatusLast Update
0004869SOGopublic2024-11-07 15:43
ReporterNeustradamus Assigned To 
PriorityimmediateSeverityfeatureReproducibilityalways
Status newResolutionopen 
Summary0004869: SCRAM-SHA-1(-PLUS) to SCRAM-SHA-512(-PLUS) supports
Description

Can you add SHA-SCRAM support?

RFC6331: Moving DIGEST-MD5 to Historic

"When using the SASL SCRAM mechanism, the SCRAM-SHA-256-PLUS variant SHOULD be preferred over the SCRAM-SHA-256 variant, and SHA-256 variants [RFC7677] SHOULD be preferred over SHA-1 variants [RFC5802]".

After SCRAM-SHA-1(-PLUS):

Now there is SCRAM-SHA-256(-PLUS):

-PLUS variants:

LDAP:

  • RFC5803: Lightweight Directory Access Protocol (LDAP) Schema for Storing Salted: Challenge Response Authentication Mechanism (SCRAM) Secrets: https://tools.ietf.org/html/rfc5803

HTTP:

IANA: https://www.iana.org/assignments/sasl-mechanisms/sasl-mechanisms.xhtml

  • SCRAM-SHA-1
  • SCRAM-SHA-1-PLUS
  • SCRAM-SHA-224
  • SCRAM-SHA-224-PLUS
  • SCRAM-SHA-256
  • SCRAM-SHA-256-PLUS
  • SCRAM-SHA-384
  • SCRAM-SHA-384-PLUS
  • SCRAM-SHA-512
  • SCRAM-SHA-512-PLUS

Linked to:

Steps To Reproduce

.

Additional Information

.

TagsNo tags attached.

Activities

Christian Mack

Christian Mack

2019-11-04 13:44

developer   ~0013880

Changed to feature request.

Neustradamus

Neustradamus

2020-10-31 16:34

reporter   ~0014912

Good news, there are new informations:

Note, after SCRAM-SHA-1(-PLUS):

Thanks a lot in advance.

the_nic

the_nic

2020-11-01 08:29

reporter   ~0014913

What is the use case? If you have tls, the usefulness seems quite low

Neustradamus

Neustradamus

2022-08-18 05:10

reporter   ~0016172

Have you progressed on it?

Current secure servers do not work with SOGo.

Neustradamus

Neustradamus

2024-11-07 14:25

reporter   ~0017935

Dear @sebastien, @Christian Mack,

Can you add the support for security?

Thanks in advance.

sebastien

sebastien

2024-11-07 14:54

administrator   ~0017937

Hello, our roadmap is already booked (https://bugs.sogo.nu/roadmap_page.php), so not in the next release

Sebastien

Neustradamus

Neustradamus

2024-11-07 15:43

reporter   ~0017939

@sebastien: Thanks for your answer!
I understand but when?

Can you add this important feature?

SCRAM supports exist in Auth_SASL/Auth_SASL2 from PEAR:

Issue History

Date Modified Username Field Change
2019-11-02 13:51 Neustradamus New Issue
2019-11-04 13:44 Christian Mack Note Added: 0013880
2019-11-04 13:44 Christian Mack Severity block => feature
2020-10-31 16:34 Neustradamus Note Added: 0014912
2020-11-01 08:29 the_nic Note Added: 0014913
2022-08-18 05:10 Neustradamus Note Added: 0016172
2024-11-07 14:25 Neustradamus Note Added: 0017935
2024-11-07 14:54 sebastien Note Added: 0017937
2024-11-07 15:43 Neustradamus Note Added: 0017939