z-logo
open-access-imgOpen Access
Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API Mechanisms
Author(s) -
C. Newman,
A. Me-Sen,
A. Melnikov,
Nicolás Williams
Publication year - 2010
Publication title -
rfc
Language(s) - English
Resource type - Reports
DOI - 10.17487/rfc5802
Subject(s) - scram , authentication (law) , computer security , computer science , mechanism (biology) , authentication protocol , password , engineering , nuclear engineering , philosophy , epistemology
The secure authentication mechanism most widely deployed and used byInternet application protocols is the transmission of clear-textpasswords over a channel protected by Transport Layer Security (TLS).There are some significant security concerns with that mechanism,which could be addressed by the use of a challenge responseauthentication mechanism protected by TLS. Unfortunately, thechallenge response mechanisms presently on the standards track allfail to meet requirements necessary for widespread deployment, andhave had success only in limited use. This specification describes afamily of Simple Authentication and Security Layer (SASL; RFC 4422)authentication mechanisms called the Salted Challenge ResponseAuthentication Mechanism (SCRAM), which addresses the securityconcerns and meets the deployability requirements. When used incombination with TLS or an equivalent security layer, a mechanism fromthis family could improve the status quo for application protocolauthentication and provide a suitable choice for a mandatory-to-implement mechanism for future application protocol standards.[STANDARDS-TRACK]

The content you want is available to Zendy users.

Already have an account? Click here to sign in.
Having issues? You can contact us here
Accelerating Research

Address

John Eccles House
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom