Need help in understanding auth digest-md5 and realm

Aki Tuomi aki.tuomi at dovecot.fi
Sat Oct 28 12:42:35 EEST 2017


> On October 28, 2017 at 11:37 AM Jerry <jerry at seibercom.net> wrote:
> 
> 
> On Fri, 27 Oct 2017 21:35:16 +0300 (EEST), Aki Tuomi stated:
> 
> >We actually discovered that Android has a bug with DIGEST-MD5, which Google
> >refuses to fix. Also DIGEST-MD5/CRAM-MD5 etc are not really good idea with
> >SSL anyways
> 
> Could you actually describe what that bug is? I actually know someone at
> Google and they might be able to get it investigated and perhaps corrected.
> The more info you could supply, the better.
> 
> Thanks :)
> 
> -- 
> Jerry

The issue is https://issuetracker.google.com/issues/36996387, and exactly what happens is bit unknown. From our point of view, Android sends all other values correctly except final hash when using digest-md5.

Aki


More information about the dovecot mailing list