[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
CRAM-SHA1 support
From: |
Lothar May |
Subject: |
CRAM-SHA1 support |
Date: |
Fri, 28 Aug 2009 00:19:07 +0200 |
Hi,
I found an old git entry in gsasl:
"* Version 0.2.4 (released 2005-01-01)
** The CRAM-MD5 mechanism is now preferred over DIGEST-MD5.
This decision was based on recent public research that suggest MD5 is
broken, while HMAC-MD5 not immediately compromised, and the lack of
public analysis on what consequences the MD5 break have for
DIGEST-MD5. Support for CRAM-SHA1 is under investigation, to enable
users to avoid MD5 completely."
Any news on this? I would like to use CRAM-SHA1 - DIGEST-MD5 is tagged
as "historic", and CRAM-MD5 "potentially" broken.
Thanks,
Lothar
- CRAM-SHA1 support,
Lothar May <=