SASL authentication (RFC 4422), server and client side.
Mechanisms:
PLAIN(RFC 4616) -Sovite.SASL.PlainLOGIN(draft-murchison-sasl-login, for old clients) -Sovite.SASL.LoginSCRAM-SHA-256(RFC 5802, RFC 7677) -Sovite.SASL.ScramSHA256OAUTHBEARER(RFC 7628) -Sovite.SASL.OAuthBearer
Sovite.SASL.Server runs the server side against a
Sovite.SASL.Backend, which checks the credentials. Backends:
Sovite.SASL.Backend.Static- a passwd-style file.Sovite.SASL.Backend.SQL- a query on PostgreSQL or MySQL.Sovite.SASL.Backend.LDAP- bind as the user.Sovite.SASL.Backend.Introspection- OAuth 2.0 token introspection (RFC 7662), forOAUTHBEARER.
Sovite.SASL.Dovecot hands the whole exchange to a Dovecot auth
server instead. Sovite.SASL.Password hashes and checks stored
passwords.
Summary
Functions
Prepares a password or user name for comparison, a close approximation
of SASLprep (RFC 4013): non-ASCII spaces become spaces, characters
"commonly mapped to nothing" are removed, and the result is NFKC
normalized. Returns :error for invalid UTF-8 or prohibited
characters (controls).
Compares two binaries in constant time (for equal sizes).
Functions
Prepares a password or user name for comparison, a close approximation
of SASLprep (RFC 4013): non-ASCII spaces become spaces, characters
"commonly mapped to nothing" are removed, and the result is NFKC
normalized. Returns :error for invalid UTF-8 or prohibited
characters (controls).
iex> Sovite.SASL.saslprep("I\u00ADX")
{:ok, "IX"}
iex> Sovite.SASL.saslprep("\u2168")
{:ok, "IX"}
iex> Sovite.SASL.saslprep("a\u0007")
:error
Compares two binaries in constant time (for equal sizes).