rainloop-webmail icon indicating copy to clipboard operation
rainloop-webmail copied to clipboard

SCRAM-SHA-1(-PLUS) + SCRAM-SHA-256(-PLUS) supports

Open Neustradamus opened this issue 6 years ago • 3 comments

Dear @RainLoop team,

There is a big security problem, the missing support of SCRAM-SHA-*.

Can you add supports of :

  • SCRAM-SHA-1
  • SCRAM-SHA-1-PLUS
  • SCRAM-SHA-256
  • SCRAM-SHA-256-PLUS
  • SCRAM-SHA-512
  • SCRAM-SHA-512-PLUS
  • SCRAM-SHA3-512
  • SCRAM-SHA3-512-PLUS

"When using the SASL SCRAM mechanism, the SCRAM-SHA-256-PLUS variant SHOULD be preferred over the SCRAM-SHA-256 variant, and SHA-256 variants [RFC7677] SHOULD be preferred over SHA-1 variants [RFC5802]".

  • SCRAM-SHA-1(-PLUS): -- https://tools.ietf.org/html/rfc5802 -- https://tools.ietf.org/html/rfc6120

  • SCRAM-SHA-256(-PLUS): -- https://tools.ietf.org/html/rfc7677 since 2015-11-02 -- https://tools.ietf.org/html/rfc8600 since 2019-06-21: https://mailarchive.ietf.org/arch/msg/ietf-announce/suJMmeMhuAOmGn_PJYgX5Vm8lNA

  • SCRAM-SHA-512(-PLUS): -- https://tools.ietf.org/html/draft-melnikov-scram-sha-512

  • SCRAM-SHA3-512(-PLUS): -- https://tools.ietf.org/html/draft-melnikov-scram-sha3-512

https://xmpp.org/extensions/inbox/hash-recommendations.html

-PLUS variants:

  • RFC5056: On the Use of Channel Bindings to Secure Channels: https://tools.ietf.org/html/rfc5056
  • RFC5929: Channel Bindings for TLS: https://tools.ietf.org/html/rfc5929
  • Channel-Binding Types: https://www.iana.org/assignments/channel-binding-types/channel-binding-types.xhtml
  • RFC 9266: Channel Bindings for TLS 1.3: https://tools.ietf.org/html/rfc9266

LDAP:

  • RFC5803: Lightweight Directory Access Protocol (LDAP) Schema for Storing Salted: Challenge Response Authentication Mechanism (SCRAM) Secrets: https://tools.ietf.org/html/rfc5803

HTTP:

  • RFC7804: Salted Challenge Response HTTP Authentication Mechanism: https://tools.ietf.org/html/rfc7804

2FA:

  • Extensions to Salted Challenge Response (SCRAM) for 2 factor authentication: https://tools.ietf.org/html/draft-melnikov-scram-2fa

IANA:

  • Simple Authentication and Security Layer (SASL) Mechanisms: https://www.iana.org/assignments/sasl-mechanisms/sasl-mechanisms.xhtml

Linked to:

  • https://github.com/scram-xmpp/info/issues/1

Neustradamus avatar Sep 10 '19 06:09 Neustradamus

@the-djmaze: Thanks for your work!

I have seen today, your commit in SnappyMail!

Maybe you can do a PR for RainLoop?

Neustradamus avatar Jan 08 '22 03:01 Neustradamus

@the-djmaze: I have edited the ticket with more informations (TLS Binding: -PLUS variants and other SCRAM...).

If you are ready to add SCRAM-SHA-512 and SCRAM-SHA3-512 in SnappyMail, you can ^^

I have added SnappyMail in the https://github.com/scram-xmpp/info/issues/1.

Neustradamus avatar Jan 08 '22 03:01 Neustradamus

@the-djmaze: Recently SCRAM hashes have been added in:

  • https://github.com/pear/Auth_SASL
  • https://github.com/pear/Auth_SASL2
  • https://github.com/pear/Net_SMTP

A good job done by @schengawegga.

Maybe you can help for -PLUS variants?

And for repositories:

  • https://github.com/pear/Net_Sieve
  • https://github.com/pear/Net_IMAP
  • https://github.com/pear/Mail_IMAPv2
  • https://github.com/pear/Net_POP3
  • https://github.com/pear/Mail
  • https://github.com/pear/Mail2
  • https://github.com/pear/Auth
  • https://github.com/pear/Auth_HTTP

Neustradamus avatar Dec 12 '23 12:12 Neustradamus