[ 
https://issues.apache.org/jira/browse/QPIDJMS-294?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16015731#comment-16015731
 ] 

Rob Godfrey commented on QPIDJMS-294:
-------------------------------------

If the client gets a positive outcome from the server and there is no 
additional-data and there has been no challenge carrying the server final 
message then the client should fail to establish the connection (as it should 
if the server final message does not carry a correct proof)

> The SCRAM-SHA-* SASL mechanisms should verify the server final message if it 
> is sent in the additional-data field of sasl-outcome
> ---------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: QPIDJMS-294
>                 URL: https://issues.apache.org/jira/browse/QPIDJMS-294
>             Project: Qpid JMS
>          Issue Type: Bug
>            Reporter: Rob Godfrey
>
> Currently the client will only verify the server final message if it is sent 
> as an extra challenge in the sasl exchange.
> The client should also verify if the server final message is sent as 
> additional-data on the sasl outcome (which is really the way this should 
> always be sent).
> In order to do this PROTON-1486 will need fixing



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to