Skip to content

DIGEST-MD5 response negotiation mishandles qop and quoted directives #754

Description

@OskarEichler

Problem

DIGEST-MD5 response construction can choose the wrong qop default/advertised option, escape quoted directive values incorrectly and lose empty directives. Servers with multiple qop values, quotes/backslashes or empty realms can reject otherwise valid authentication.

Prepared atomic commit a23cc925036aa6abf2a9ee5dbcfa1c995be91647 corrects qop selection/defaulting, directive escaping and empty-value preservation. Dual-Ruby RFC-style vectors and the full suite pass. No repository tests were modified.

Metadata

Metadata

Assignees

No one assigned

    Labels

    SASL 🔒Authentication and authentication mechanisms

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions