Fwd: [kitten] Call for adoption: draft-bouchez-scram-mcf-02 (Ends 2026-06-17)
Dave Cridland <[email protected]> Mon, 22 Jun 2026 12:36:02 +0100
| Newsgroups | gmane.network.jabber.standards-jig |
|---|---|
| Message-ID | <CAKHUCzzTtJviRtXWKyXUe1vEfKHH25-5=XBDX1=F7YNX=zc1kA@mail.gmail.com> |
--===============3677775468833761034== Content-Type: multipart/alternative; boundary="000000000000ba9bbc0654d60cd1" --000000000000ba9bbc0654d60cd1 Content-Type: text/plain; charset="UTF-8" Is there any interest in the XMPP community for an MCF-based SCRAM? If so, is there any interest in working on this within the Kitten IETF Working Group? Dave. ---------- Forwarded message --------- From: Alexey Melnikov via Datatracker <[email protected]> Date: Wed, 3 Jun 2026 at 16:19 Subject: [kitten] Call for adoption: draft-bouchez-scram-mcf-02 (Ends 2026-06-17) To: <[email protected]>, <[email protected]>, < [email protected]> As some interest was expressed in this document, this message starts a kitten WG Call for Adoption of: draft-bouchez-scram-mcf-02. This Working Group Call for Adoption ends on 2026-06-17 Abstract: This document specifies SCRAM-MCF, an extension to the Salted Challenge Response Authentication Mechanism (SCRAM) family of SASL mechanisms ([RFC5802]) and HTTP Digest extensions ([RFC7616], [RFC7677]). The extension replaces the PBKDF2-specific iteration count attributes i= and s= in the server-first-message with a generic Modular Crypt Format (MCF) descriptor f=. This allows servers to use modern memory- hard key derivation functions such as Argon2, SCrypt, or bcrypt while preserving the full security properties and message flow of SCRAM. The change is fully backward compatible: servers can continue sending i= and s= for legacy clients and only send f= (or both) when the client advertises support. This document is intended to be discussed and potentially adopted by the KITTEN working group. Feedback from the KITTEN WG is welcome on the [email protected] mailing list. Please reply to this message and indicate whether or not you support adoption of this Internet-Draft by the kitten WG. Comments to explain your preference are greatly appreciated. Please reply to all recipients of this message and include this message in your response. Authors, and WG participants in general, are reminded of the Intellectual Property Rights (IPR) disclosure obligations described in BCP 79 [2]. Appropriate IPR disclosures required for full conformance with the provisions of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any. Sanctions available for application to violators of IETF IPR Policy can be found at [3]. Thank you. [1] https://datatracker.ietf.org/doc/bcp78/ [2] https://datatracker.ietf.org/doc/bcp79/ [3] https://datatracker.ietf.org/doc/rfc6701/ The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-bouchez-scram-mcf/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-bouchez-scram-mcf-02.html A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-bouchez-scram-mcf-02 _______________________________________________ Kitten mailing list -- [email protected] To unsubscribe send an email to [email protected] --000000000000ba9bbc0654d60cd1 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Is there any interest in the XMPP community for an MCF-bas= ed SCRAM?<div><br></div><div>If so, is there any interest in working on thi= s within the Kitten IETF Working Group?</div><div><br></div><div>Dave.<br><= br><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class= =3D"gmail_attr">---------- Forwarded message ---------<br>From: <strong cla= ss=3D"gmail_sendername" dir=3D"auto">Alexey Melnikov via Datatracker</stron= g> <span dir=3D"auto"><<a href=3D"mailto:[email protected]">noreply@ietf.= org</a>></span><br>Date: Wed, 3 Jun 2026 at 16:19<br>Subject: [kitten] C= all for adoption: draft-bouchez-scram-mcf-02 (Ends 2026-06-17)<br>To: <= ;<a href=3D"mailto:[email protected]">[email protected]</a>>, <<a href= =3D"mailto:[email protected]">[email protected]</a>>, <<a = href=3D"mailto:[email protected]">draft-bouchez-scram-mcf@ie= tf.org</a>><br></div><br><br>As some interest was expressed in this docu= ment,<br> this message starts a kitten WG Call for Adoption of:<br> draft-bouchez-scram-mcf-02.<br> <br> This Working Group Call for Adoption ends on 2026-06-17<br> <br> Abstract:<br> =C2=A0 =C2=A0This document specifies SCRAM-MCF, an extension to the Salted<= br> =C2=A0 =C2=A0Challenge Response Authentication Mechanism (SCRAM) family of = SASL<br> =C2=A0 =C2=A0mechanisms ([RFC5802]) and HTTP Digest extensions ([RFC7616],<= br> =C2=A0 =C2=A0[RFC7677]).<br> <br> =C2=A0 =C2=A0The extension replaces the PBKDF2-specific iteration count att= ributes<br> =C2=A0 =C2=A0i=3D and s=3D in the server-first-message with a generic Modul= ar Crypt<br> =C2=A0 =C2=A0Format (MCF) descriptor f=3D. This allows servers to use moder= n memory-<br> =C2=A0 =C2=A0hard key derivation functions such as Argon2, SCrypt, or bcryp= t while<br> =C2=A0 =C2=A0preserving the full security properties and message flow of SC= RAM.<br> <br> =C2=A0 =C2=A0The change is fully backward compatible: servers can continue = sending<br> =C2=A0 =C2=A0i=3D and s=3D for legacy clients and only send f=3D (or both) = when the<br> =C2=A0 =C2=A0client advertises support.<br> <br> =C2=A0 =C2=A0This document is intended to be discussed and potentially adop= ted by<br> =C2=A0 =C2=A0the KITTEN working group.=C2=A0 Feedback from the KITTEN WG is= welcome on<br> =C2=A0 =C2=A0the <a href=3D"mailto:[email protected]" target=3D"_blank">kitte= [email protected]</a> mailing list.<br> <br> Please reply to this message and indicate whether or not you support adopti= on<br> of this Internet-Draft by the kitten WG. Comments to explain your preferenc= e<br> are greatly appreciated. Please reply to all recipients of this message and= <br> include this message in your response.<br> <br> Authors, and WG participants in general, are reminded of the Intellectual<b= r> Property Rights (IPR) disclosure obligations described in BCP 79 [2].<br> Appropriate IPR disclosures required for full conformance with the provisio= ns<br> of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.<br> Sanctions available for application to violators of IETF IPR Policy can be<= br> found at [3].<br> <br> Thank you.<br> [1] <a href=3D"https://datatracker.ietf.org/doc/bcp78/" rel=3D"noreferrer" = target=3D"_blank">https://datatracker.ietf.org/doc/bcp78/</a><br> [2] <a href=3D"https://datatracker.ietf.org/doc/bcp79/" rel=3D"noreferrer" = target=3D"_blank">https://datatracker.ietf.org/doc/bcp79/</a><br> [3] <a href=3D"https://datatracker.ietf.org/doc/rfc6701/" rel=3D"noreferrer= " target=3D"_blank">https://datatracker.ietf.org/doc/rfc6701/</a><br> <br> The IETF datatracker status page for this Internet-Draft is:<br> <a href=3D"https://datatracker.ietf.org/doc/draft-bouchez-scram-mcf/" rel= =3D"noreferrer" target=3D"_blank">https://datatracker.ietf.org/doc/draft-bo= uchez-scram-mcf/</a><br> <br> There is also an HTML version available at:<br> <a href=3D"https://www.ietf.org/archive/id/draft-bouchez-scram-mcf-02.html"= rel=3D"noreferrer" target=3D"_blank">https://www.ietf.org/archive/id/draft= -bouchez-scram-mcf-02.html</a><br> <br> A diff from the previous version is available at:<br> <a href=3D"https://author-tools.ietf.org/iddiff?url2=3Ddraft-bouchez-scram-= mcf-02" rel=3D"noreferrer" target=3D"_blank">https://author-tools.ietf.org/= iddiff?url2=3Ddraft-bouchez-scram-mcf-02</a><br> <br> _______________________________________________<br> Kitten mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank"= >[email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" ta= rget=3D"_blank">[email protected]</a><br> </div></div></div> --000000000000ba9bbc0654d60cd1-- --===============3677775468833761034== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Standards mailing list -- [email protected] To unsubscribe send an email to [email protected] --===============3677775468833761034==--