Micron Document
____ _ _ _ _
| _ \ ___ | |_ (_) _ __ ___ __| | (_) __ _
| |_) | / _ \ | __| | | | '_ \ / _ \ / _| | | | / _ |
| _ < | __/ | |_ | | | |_) | | __/ | (_| | | | | (_| |
|_| \_\ \___| \__| |_| | .__/ \___| \__,_| |_| \__,_|
|_|


The NomadNet German & English Wikipedia | Archives | Info
- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b

πŸ” Search

Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―

Simple Authentication and Security Layer
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
top
Simple Authentication and Security Layer (SASL) ist ein Framework, das von verschiedenen Protokollen zur Authentifizierung im Internet verwendet wird. Es wurde im Oktober 1997 als RFC 2222cite-ref-1[1] definiert, der im Juni 2006 durch RFC 4422cite-ref-2[2] ersetzt wurde.

SASL bietet dem Applikationsprotokoll damit eine standardisierte MΓΆglichkeit der Aushandlung von Kommunikationsparametern. Im Regelfall wird nur eine Authentifizierungsmethode ausgehandelt, es kann aber auch vereinbart werden, dass zuerst auf ein verschlΓΌsseltes Transportprotokoll, z. B. auf TLS, gewechselt wird. Die SASL-Implementierungen auf Client- und Server-Seite einigen sich auf ein Verfahren, dieses kann dann von der Applikation transparent benutzt werden.

Durch diesen Standard wird die Entwicklung sicherer Applikationsprotokolle wesentlich vereinfacht: der Entwickler muss lediglich eine bestehende SASL-Implementierung nutzen, anstatt ein komplettes Verfahren zur Authentifizierung und DatenverschlΓΌsselung selbst zu implementieren.

SASL wird u. a. bei SMTP, IMAP, POP3, LDAP und XMPP benutzt.

Contents

β€’ Literatur
β€’ Weblinks

──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────

Authentifizierungsmechanismen

Unter anderem folgende standardisierte Mechanismen sind bei der IANA aufgelistet (siehe Weblinks):

β€’ PLAIN, alle Daten werden im Klartext ausgetauscht (hier bietet meistens TLS die nΓΆtigen Sicherheitsmechanismen)
β€’ GSSAPI, ist selbst ein Framework, das beispielsweise Kerberos v5 anbietet
β€’ CRAM-MD5, vermeidet die Übertragung des Passworts im Klartext
β€’ DIGEST-MD5, Γ€hnlich wie CRAM-MD5, jedoch mit der MΓΆglichkeit, zusΓ€tzliche Parameter wie IntegritΓ€tssicherung auszuhandeln
β€’ SCRAM (RFC 5802cite-ref-3[3]), auf einer Challenge-Response-Authentifizierung basierender Mechanismus
β€’ Einmalkennwort (OTP), bietet Passwortverifizierung, ohne dass der Server das Passwort kennt
β€’ ANONYMOUS, der Nutzer kann den Dienst ohne Authentifizierung nutzen
β€’ EXTERNAL, die Authentifizierung erfolgt außerhalb von SASL.

Literatur

β€’ Roland Bless et al.: Sichere Netzwerkkommunikation. Springer Verlag, 2005, ISBN 3-540-21845-9.

Weblinks

β€’ RFCs

β€’ RFC: 2222 – Simple Authentication and Security Layer (SASL). Oktober 1997 (aktualisiert durch RFC 4422, englisch).
β€’ RFC: 4422 – Simple Authentication and Security Layer (SASL). Oktober 2006 (lΓΆst RFC 2222 ab, englisch).

β€’ SASL-Mechanismen. iana.org
β€’ Freie Bibliotheken

β€’ Cyrus SASL
β€’ GNU SASL
β€’ Dovecot SASL

Einzelnachweise

cite-note-11. ↑ RFC: 2222 – Simple Authentication and Security Layer (SASL). Oktober 1997 (aktualisiert durch RFC 4422, englisch).
cite-note-22. ↑ RFC: 4422 – Simple Authentication and Security Layer (SASL). Oktober 2006 (lΓΆst RFC 2222 ab, englisch).
cite-note-33. ↑ RFC: 5802 – Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API Mechanisms. Juli 2010 (englisch).