[
https://issues.jboss.org/browse/ELY-787?page=com.atlassian.jira.plugin.sy...
]
Josef Cacek commented on ELY-787:
---------------------------------
What about to register a family of mechanisms (e.g. the {{"JBOSS-*"}}) and all
of the new ones put under this family?
If we'll try to use non-registered names, we may and we will hit problems once anybody
asks for the name registration - as the process is on the first-come-first-served basis.
SASL mechanisms are not IANA registered and specifications are not
provided
---------------------------------------------------------------------------
Key: ELY-787
URL:
https://issues.jboss.org/browse/ELY-787
Project: WildFly Elytron
Issue Type: Bug
Reporter: Josef Cacek
Assignee: Darran Lofthouse
Priority: Critical
Labels: sasl
Elytron comes with set of SASL mechanisms (as requested by EAP7-530), but they don't
fit SASL requirements.
New mechanisms has to be registered by IANA as requested by [SASL RFC 4422 section
5|https://tools.ietf.org/html/rfc4422#section-5] and Java
[
SaslClientFactory|http://docs.oracle.com/javase/8/docs/api/javax/security...]
and
[
SaslServerFactory|http://docs.oracle.com/javase/8/docs/api/javax/security...]
contracts.
Current list of mechanisms provided by Elytron, which are not IANA registered:
* DIGEST-SHA
* DIGEST-SHA-256
* DIGEST-SHA-512
* JBOSS-LOCAL-USER
*Suggestion for improvement:*
Provide specifications for the new mechanisms and register the names by IANA (see
[section 7 in
RFC-4422|https://tools.ietf.org/html/rfc4422#section-7]).
--
This message was sent by Atlassian JIRA
(v7.2.3#72005)