Skip to content

SCRAM-SHA-1(-PLUS) + SCRAM-SHA-256(-PLUS) + SCRAM-SHA-512(-PLUS) supports #57

Description

@Neustradamus

Can you add the SCRAM supports?

For example Rouncube has needed: roundcube/roundcubemail#6917


Cyrus SASL supports:

  • SCRAM-SHA-1
  • SCRAM-SHA-1-PLUS
  • SCRAM-SHA-224
  • SCRAM-SHA-224-PLUS
  • SCRAM-SHA-256
  • SCRAM-SHA-256-PLUS
  • SCRAM-SHA-384
  • SCRAM-SHA-384-PLUS
  • SCRAM-SHA-512
  • SCRAM-SHA-512-PLUS

-> https://cyrusimap.org/sasl/sasl/authentication_mechanisms.html
-> https://github.com/cyrusimap/cyrus-sasl/commits/master

Dovecot SASL supports:

  • SCRAM-SHA-1
  • SCRAM-SHA-256

-> https://doc.dovecot.org/configuration_manual/authentication/password_schemes/

GNU SASL supports:

  • SCRAM-SHA-1
  • SCRAM-SHA-1-PLUS
  • SCRAM-SHA-256
  • SCRAM-SHA-256-PLUS

-> http://www.gnu.org/software/gsasl/


"When using the SASL SCRAM mechanism, the SCRAM-SHA-256-PLUS variant SHOULD be preferred over the SCRAM-SHA-256 variant, and SHA-256 variants [RFC7677] SHOULD be preferred over SHA-1 variants [RFC5802]".

https://xmpp.org/extensions/inbox/hash-recommendations.html

-PLUS variants:

IMAP:

LDAP:

  • RFC5803: Lightweight Directory Access Protocol (LDAP) Schema for Storing Salted: Challenge Response Authentication Mechanism (SCRAM) Secrets: https://tools.ietf.org/html/rfc5803

HTTP:

2FA:

IANA:

Linked to:

Activity

  1. jparise commented on Nov 30, 2019

    @jparise
    Member

    I don't have any plans to implement this myself, but I would gladly review a patch that adds this support.

  2. Neustradamus commented on Oct 31, 2020

    @Neustradamus
    Author
  3. changed the title [-]SCRAM-SHA-1(-PLUS) + SCRAM-SHA-256(-PLUS) supports[/-] [+]SCRAM-SHA-1-PLUS + SCRAM-SHA-256-PLUS + SCRAM-SHA-512-PLUS supports[/+] on Nov 1, 2020
  4. changed the title [-]SCRAM-SHA-1-PLUS + SCRAM-SHA-256-PLUS + SCRAM-SHA-512-PLUS supports[/-] [+]SCRAM-SHA-1(-PLUS) + SCRAM-SHA-256(-PLUS) + SCRAM-SHA-512(-PLUS) supports[/+] on Nov 1, 2020
  5. jparise commented on Mar 18, 2021

    @jparise
    Member

    As I said earlier, I'd be glad to review a Pull Request that adds support for these new algorithms.

  6. schengawegga commented on Sep 29, 2022

    @schengawegga
    Contributor

    @Neustradamus I have developed a first draft of SCRAM support, but i have to test it first before i can create a pull request. Do you have a docker container within a SMTP server wich supports any or all kinds of SCRAM?

  7. Neustradamus commented on Oct 11, 2022

    @Neustradamus
    Author
  8. mbhangui commented on Oct 12, 2022

    @mbhangui

    indimail has docker images at https://hub.docker.com/r/cprogrammer/indimail. Some documentation is here.

    The steps would be to

    1. Create a domain using vadddomain
    2. create an user using vadduser
    3. Modify user password using vmoduser for SCRAM-SHA1, or SCRAM-SHA-256 (and the PLUS methods).

    You can reach out to me privately if you need any help in setting up accounts using indimail docker.

    gsasl also has a tiny smtp server in the examples directory. One can compile it and do a basic test. AFAIK, The gsasl utility too can act as a server using the --server option. But I have never tried those option. But I have used the client options to test SCRAM auth methods against indimail server.

  9. Neustradamus commented on Oct 14, 2022

    @Neustradamus
    Author
  10. schengawegga commented on Oct 18, 2022

    @schengawegga
    Contributor

    @Neustradamus @mbhangui
    Yes, i´ve seen @mbhangui comment.
    Thanks you for the detailed instructions.
    But my time is very short at the moment.
    I will have a closer look on the docker container when i´m not so busy anymore.

  11. schengawegga commented on Mar 26, 2023

    @schengawegga
    Contributor

    @mbhangui now i tried about 4 hours to run and configure indimail to test my developement, but it won´t work on my own.
    It is possible, that you can give me a fully configured indimail server within an .vbox image?
    My problem at the moment is a mysql certificate error on vadduser command.

  12. mbhangui commented on Mar 30, 2023

    @mbhangui

    @mbhangui now i tried about 4 hours to run and configure indimail to test my developement, but it won´t work on my own. It is possible, that you can give me a fully configured indimail server within an .vbox image? My problem at the moment is a mysql certificate error on vadduser command.

    Which image did you use? Sure I can give a full configured indimail server with .vbox image, but that could take me a day or two.

  13. mbhangui commented on Mar 30, 2023

    @mbhangui

    So I tried this and it worked. You can repeat the steps exactly as below

    1. Pull the image
      $ podman pull ghcr.io/mbhangui/indimail:rockylinux8

    2. List the image
      $ podman images|grep rocky
      ghcr.io/mbhangui/indimail rockylinux8 274da2d2b6d7 2 months ago 1.09 GB

    3. Run docker or podman command. This will run SMTP on port 25 without authentication and on port 587 with authentication. You can use port 2587 on the host where you run podman command to use SMTP for testing SCRAM methods.

    $ podman run --rm -d --publish-all --name indimail -h indimail.org --cap-add SYS_PTRACE --cap-add SYS_ADMIN --cap-add IPC_LOCK --cap-add SYS_RESOURCE --cap-add=NET_ADMIN --cap-add=CAP_NET_RAW --cap-add=SYS_NICE -p 2025:25 -p 2587:587 274da2d2b6d7
    2e11d469150726b874e808d9ad967b8c8c9a2629edee4186c1e827406828f048
    
    1. Open a shell on the running container
    $ podman exec -ti indimail bash
    indimail.org:(root) / >
    
    1. In the container, create domain using vadddomain and one user testuser01 that support SCRAM authentication using vadduser
    indimail.org:(root) / > vadddomain example.com password
    indimail.org:(root) / > vadduser -C -m SCRAM-SHA-256 -d testuser01@example.com somepassword
    
    1. On the host where you ran the podman command, test SCRAM-SHA-256 with the gsasl command. You will require to install the gsasl RPM or debian package on your host. Alternatively you can run gsasl command on the indimail container on port 587 instead of port 2587
    a) without channel binding
    $ gsasl -d --no-cb --hostname=argos.indimail.org --x509-ca-file="" -a testuser01@example.com --password 'somepassword' --mechanism SCRAM-SHA-256 --smtp --connect localhost:2587
    
    b) or you can use channel binding
    $ gsasl -d --hostname=argos.indimail.org --x509-ca-file="" -a testuser01@example.com --password 'somepassword' --mechanism SCRAM-SHA-256-PLUS --smtp --connect localhost:2587
    

    Any issue let me know. You can replace podman with docker command. The syntax is the same for both. I prefer podman because it runs without needing a daemon running as root.

    The response to the gsasl command will be like this and in the end you should get 235 ok, go ahead (#2.0.0)

    Trying ‘localhost’...
    220 indimail.org (NO UCE) ESMTP IndiMail 1.285 Thu, 30 Mar 2023 09:17:45 +0000
    EHLO [127.0.0.1]
    250-indimail.org
    250-AUTH LOGIN PLAIN CRAM-MD5 CRAM-SHA1 CRAM-SHA224 CRAM-SHA256 CRAM-SHA384 CRAM-SHA512 CRAM-RIPEMD DIGEST-MD5 SCRAM-SHA-1 SCRAM-SHA-256
    250-PIPELINING
    250-8BITMIME
    250-SIZE 20971520
    250-ETRN
    250-STARTTLS
    250 HELP
    STARTTLS
    220 ready for tls
    TLS X.509 Verification: The certificate is NOT trusted. The certificate chain is revoked. The certificate doesn't match the local copy (TOFU). The revocation or OCSP data are old and have been superseded. The revocation or OCSP data are issued with a future date. The certificate issuer is unknown. The certificate issuer is not a CA. The certificate chain uses insecure algorithm. The certificate chain violates the signer's constraints. The certificate chain does not match the intended purpose. The certificate chain uses not yet valid certificate. The certificate chain uses expired certificate. The signature in the certificate is invalid. The name in the certificate does not match the expected. The certificate requires the server to include an OCSP status in its response, but the OCSP status is missing. The received OCSP status response is invalid. The certificate contains an unknown critical extension.
    EHLO [127.0.0.1]
    250-indimail.org
    250-AUTH LOGIN PLAIN CRAM-MD5 CRAM-SHA1 CRAM-SHA224 CRAM-SHA256 CRAM-SHA384 CRAM-SHA512 CRAM-RIPEMD DIGEST-MD5 SCRAM-SHA-1 SCRAM-SHA-256 SCRAM-SHA-1-PLUS SCRAM-SHA-256-PLUS
    250-PIPELINING
    250-8BITMIME
    250-SIZE 20971520
    250-ETRN
    250 HELP
    AUTH SCRAM-SHA-256
    334
    biwsbj10ZXN0dXNlcjAxQGV4YW1wbGUuY29tLHI9TlNqa1pCSjdkSGc4NEpHcGVLRVJjYS9w
    334 cj1OU2prWkJKN2RIZzg0SkdwZUtFUmNhL3AwU1M2M3c1Z2RLUkZBQm1ZeTQ1b1pyZDEscz13YitqSjBvMTB5bWJoSHdZLGk9NDA5Ng==
    Yz1iaXdzLHI9TlNqa1pCSjdkSGc4NEpHcGVLRVJjYS9wMFNTNjN3NWdkS1JGQUJtWXk0NW9acmQxLHA9U1FTN1lCR0Z0cXlnM1NrZWVDQzVxbStqTGdYUzBrNVlCQ0hFY1NSREFvRT0=
    334 dj1zaDlVUEJtSDZvcTVtQ2NNZWpVRStQd2hmNFhrQW53Y0F0VHBzUHorejRnPQ==
    
    235 ok, go ahead (#2.0.0)
    Client authentication finished (server trusted)...
    Session finished...
    QUIT
    221 indimail.org closing connection
    
  14. schengawegga commented on Mar 31, 2023

    @schengawegga
    Contributor

    @mbhangui Thanks for your manual.
    But when i do step 3, i get the following errormessage

    Error: initializing source docker://registry.redhat.io/274da2d2b6d72e11d469150726b874e808d9ad967b8c8c9a2629edee4186c1e827406828f048:latest: reading manifest latest in registry.redhat.io/274da2d2b6d72e11d469150726b874e808d9ad967b8c8c9a2629edee4186c1e827406828f048: unknown: Not Found

    Maybe can you please provide a vbox image to me?
    That will be very helpful.
    I am not in a hurry, so it is okay if it takes some time.

  15. 13 remaining items

  16. schengawegga commented on Aug 12, 2023

    @schengawegga
    Contributor

    @mbhangui can you send me the vadduser statements for adding users with CRAM-MD5 and DIGEST-MD5 authentication methods? Then I can check several changes in pear/Net_SMTP and pear/Auth_SASL Thank you.

  17. Neustradamus commented on Aug 15, 2023

    @Neustradamus
    Author
  18. mbhangui commented on Aug 15, 2023

    @mbhangui

    @mbhangui can you send me the vadduser statements for adding users with CRAM-MD5 and DIGEST-MD5 authentication methods? Then I can check several changes in pear/Net_SMTP and pear/Auth_SASL Thank you.

    Totally slipped my mind that I have to reply. Here is the command. You just have to use -C option and it will support all CRAM methods. The -C option can be used with SCRAM methods too. However, the default setting of SMTP service in indimail doesn't support CRAM because of the danger of storing clear text passwords in the database. If someone steals the database, the person will walk away happily with un-encrypted passwords. To enable CRAM in SMTP a one time setting of ENABLE_CRAM variable is required, which is given below

    create a user that supports all CRAM Methods
    # vadduser -C testuser01@example.com somepassword
    
    Enable CRAM authentication in SMTP service
    
    # echo 1 > /service/qmail-smtpd.587/variables/ENABLE_CRAM
    
    Restart SMTPD
    
    # svc -r /service/qmail-smtpd.587
    
    Test using swaks. You can use port 2587 on your host where you are running docker command. If doing the test in the container then use port 587
    
    Test CRAM-MD5 using swaks
    
    swaks --to testuser01@example.com --from testuser01@example.com --server localhost --port 587 -a CRAM-MD5 -au testuser01@example.com -ap somepassword
    
    Test DIGEST-MD5 using swaks
    swaks --to testuser01@example.com --from testuser01@example.com --server localhost --port 587 -a DIGEST-MD5 -au testuser01@example.com -ap somepassword
    
    In fact You can use use CRAM-MD5 CRAM-SHA1 CRAM-SHA224 CRAM-SHA256 CRAM-SHA384 CRAM-SHA512 CRAM-RIPEMD DIGEST-MD5 methods if the client support those methods
    

    There is a detailed topic on setting up authenticated smtp mechanisms in indimail here. But feel free to post any doubts/clarification here itself

  19. mbhangui commented on Aug 15, 2023

    @mbhangui

    @mbhangui: Have you seen the last @schengawegga comment?

    Thanks for reminding me. It had totally slipped my mind as I was busy planning a vacation. I have updated the above post with few things that I had missed out

  20. added this to the 1.11.0 milestone on Aug 16, 2023
  21. modified the milestones: 1.11.0, 1.12.0 on Oct 23, 2023
  22. schengawegga commented on Jan 8, 2024

    @schengawegga
    Contributor

    @mbhangui Do indimail support XOAuth and OAuthbearer? And how do i configure this methods? Thanks you :-)

  23. mbhangui commented on Jan 9, 2024

    @mbhangui
  24. modified the milestones: 1.12.0, 1.13.0 on Feb 9, 2024
  25. Neustradamus commented on Oct 2, 2026

    @Neustradamus
    Author

    Dear all, @schengawegga, @mbhangui,

    It is in progress for Channel Binding in PHP, can you test it?

    Feedback is very important for the PHP PR author...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions