Sovite.SASL.ScramSHA256 (sovite v0.2.0)

Copy Markdown View Source

The SCRAM-SHA-256 mechanism (RFC 5802, RFC 7677).

The password never crosses the wire, the server stores only derived keys (see Sovite.SASL.Password), and both sides prove they know the password. Channel binding (-PLUS) is not supported, so a client that requires it is refused.

In SMTP the server's final message, which proves the server knows the password, is sent as one more 334 challenge, answered by an empty line (RFC 4954 §4).

For an unknown user the server answers with a salt derived from the name and fails at the end, so the exchange does not reveal which users exist.

Summary

Functions

Starts the client side. Returns the client-first message. credentials has :username and :password.

Answers the server-first message, then checks the server-final one. Returns {:error, reason} if the server is not who it claims.

Functions

client_start(map)

@spec client_start(%{username: String.t(), password: String.t()}) ::
  {:ok, binary(), term()}

Starts the client side. Returns the client-first message. credentials has :username and :password.

client_step(arg1, server_first)

@spec client_step(term(), binary()) :: {:ok, binary(), term()} | {:error, term()}

Answers the server-first message, then checks the server-final one. Returns {:error, reason} if the server is not who it claims.