qpid-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Robbie Gemmell (JIRA)" <j...@apache.org>
Subject [jira] [Updated] (QPIDJMS-335) SCRAM-SHA mechanism impls erroneously escape "=" and "," in the password during processing
Date Fri, 13 Oct 2017 16:53:00 GMT

     [ https://issues.apache.org/jira/browse/QPIDJMS-335?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

Robbie Gemmell updated QPIDJMS-335:
-----------------------------------
    Fix Version/s: 0.27.0

> SCRAM-SHA mechanism impls erroneously escape "=" and "," in the password during processing
> ------------------------------------------------------------------------------------------
>
>                 Key: QPIDJMS-335
>                 URL: https://issues.apache.org/jira/browse/QPIDJMS-335
>             Project: Qpid JMS
>          Issue Type: Bug
>          Components: qpid-jms-client
>    Affects Versions: 0.26.0
>            Reporter: Robbie Gemmell
>            Assignee: Robbie Gemmell
>             Fix For: 0.27.0
>
>
> Per discussion on http://mail-archives.apache.org/mod_mbox/qpid-users/201710.mbox/%3C1507290028737-0.post%40n2.nabble.com%3E
the client is erroneously escaping "=" and "," during password handling, whereas the SCRAM
mechanisms only require this for the username and some other cases, causing authentication
to fail when they are present as the wrong value is used to compute the details sent to the
server.



--
This message was sent by Atlassian JIRA
(v6.4.14#64029)

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@qpid.apache.org
For additional commands, e-mail: dev-help@qpid.apache.org


Mime
View raw message