Cyrus SASL and SCRAM etc.

- Neustradamus - neustradamus at hotmail.com
Fri Dec 6 00:01:59 EST 2019


Hi all,

I have done a PR about some changes, and about missing SCRAM in files...
- https://github.com/cyrusimap/cyrus-sasl/pull/589
Can you validate it?

Good job from Alexey Melnikov and Ken Murchison about SCRAM changes some months ago.
Do not forget that CRAM-MD5 and DIGEST-MD5 are historical and unsecured.

Some people inform that there is a problem with Debian, there is no SCRAM-SHA-1 and SCRAM-SHA-1-PLUS which have been added a long time ago.
Same for SCRAM-SHA-256 and SCRAM-SHA-256-PLUS which have been added in last Cyrus SASL version 2.1.27.
For example: https://bugs.exim.org/show_bug.cgi?id=2349#c6

A new release for Cyrus SASL?
Last has been released more one year.
There are a lot of improvements.
There is a ticket here: https://github.com/cyrusimap/cyrus-sasl/issues/580.

In the same time, there are some tickets and other PR:

For SASL:
- https://github.com/cyrusimap/cyrus-sasl/
- https://github.com/cyrusimap/cyrus-sasl/issues
- https://github.com/cyrusimap/cyrus-sasl/pulls

For IMAPD:
- https://github.com/cyrusimap/cyrus-imapd
- https://github.com/cyrusimap/cyrus-imapd/issues
- https://github.com/cyrusimap/cyrus-imapd/pulls

About the doc:
- https://github.com/cyrusimap/cyrusimap.github.io/issues

------------
I recall:
It is possible to see for not up-to-date doc?
- https://www.cyrusimap.org/dev/sasl/authentication_mechanisms.html
- https://www.cyrusimap.org/2.5/sasl/authentication_mechanisms.html

Redirection?

Please note that there is a SSL certificate problem for https://cyrusimap.web.cmu.edu/

Solution?
- Redirection of http(s)://cyrusimap.web.cmu.edu/ to https://cyrusimap.org/ ?

And in the same time http(s)://www.cyrusimap.org/ to https://cyrusimap.org/ ?
------------

Thanks in advance.

Regards,

Neustradamus


More information about the Cyrus-sasl mailing list