28 Oct
2017
28 Oct
'17
12:42 p.m.
On October 28, 2017 at 11:37 AM Jerry jerry@seibercom.net wrote:
On Fri, 27 Oct 2017 21:35:16 +0300 (EEST), Aki Tuomi stated:
We actually discovered that Android has a bug with DIGEST-MD5, which Google refuses to fix. Also DIGEST-MD5/CRAM-MD5 etc are not really good idea with SSL anyways
Could you actually describe what that bug is? I actually know someone at Google and they might be able to get it investigated and perhaps corrected. The more info you could supply, the better.
Thanks :)
-- Jerry
The issue is https://issuetracker.google.com/issues/36996387, and exactly what happens is bit unknown. From our point of view, Android sends all other values correctly except final hash when using digest-md5.
Aki