Re: Plaintext passwords

Peter Saint-Andre <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
Simon Friedberger wrote:
>> c) The DIGEST-MD5 approach:
>>        Pro: The password is not sent over the wire.  The password can be
>> stored as a salted hash (salt is user/realm) in the database (can't use
>> rainbow tables to reverse hash).
>>        Con: If you decide that MD5 isn't cutting it, and you want to use
>> SomeotherHashAlgorithm instead, then you need to ask the user for the
>> plaintext password (or a new username/realm/password hash).
> 
> While I do like this approach you don't seem to be such a big fan
> yourself or am I mistaken? 
> Also, maybe Peter can tell us more about the abandonment by the IETF.

As I understand it, a big part of the problem with DIGEST-MD5 as a SASL
mechanism was the inconsistent documentation and implementation. This
led to many interoperability problems -- so much so that people decided
to abandon it and work on something new, rather try to move forward with
DIGEST-MD5. But I have not studied the details, so there may be more
substantive reasons behind the deprecation.

Peter

-- 
Peter Saint-Andre
https://stpeter.im/

_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.