The SCRAM-SHA-256 mechanism (RFC 5802, RFC 7677).
The password never crosses the wire, the server stores only derived
keys (see Sovite.SASL.Password), and both sides prove they know the
password. Channel binding (-PLUS) is not supported, so a client that
requires it is refused.
In SMTP the server's final message, which proves the server knows the
password, is sent as one more 334 challenge, answered by an empty
line (RFC 4954 §4).
For an unknown user the server answers with a salt derived from the name and fails at the end, so the exchange does not reveal which users exist.
Summary
Functions
Starts the client side. Returns the client-first message.
credentials has :username and :password.
Answers the server-first message, then checks the server-final one.
Returns {:error, reason} if the server is not who it claims.
Functions
Starts the client side. Returns the client-first message.
credentials has :username and :password.
Answers the server-first message, then checks the server-final one.
Returns {:error, reason} if the server is not who it claims.