ejabberd
ejabberd copied to clipboard
Make Scram password storage the default in default config files
All modern clients should now support SCRAM, we can consider, SCRAM password storage should be added to the default config file.
Modern clients like Monal support SCRAM only if SASL2 is supported, will this be added too?
You can actually offer SASL PLAIN login with scram-hashed password storage. I think the reason we sticked to plain-text passwords was just that SIP and (traditional) TURN authentication requires those.
@aamelnikov has always said me that original SCRAM RFC is for SIP too.