Fork me on GitHub
Subscribe 3

Ticket #191 (duplicate enhancement)

Add CRAM-MD5 auth to SMTP e-mail.

  • Created: 2010-11-18 22:04:53
  • Reported by: MattF
  • Assigned to: Reines
  • Milestone: 1.4.6
  • Component: email
  • Priority: normal

Add CRAM-MD5 auth to SMTP e-mail. Rather than just defaulting to LOGIN, check to see whether CRAM-MD5 is available and trying that first. Fallback to LOGIN if CRAM is not available. The patch linked to should also fallback to standard, non-ESMTP mode, if the server doesn't support it. Currently that mode only happens if no username/password is supplied.

Note: This code is untested so may need some reworking:


MattF 2010-11-18 22:05:44

  • Description changed. (Diff)

MattF 2010-11-18 22:06:02

  • Description changed. (Diff)

Reines 2010-11-25 16:35:02

  • Milestone set to 1.4.4.

Franz 2010-11-26 16:36:00

  • Type changed from task to enhancement.

Franz 2010-12-26 13:50:48

  • Uploaded patch email.php.diff.txt. (view)

Uploaded above patch just to test out the feature. smile

adaur 2010-12-26 14:25:19

Franz: We are sorry, but the file "/development/core/tickets/191/patch/olv3exz191z16186.patch" could not be found.

Franz 2010-12-26 14:31:05

Ah, thanks. Should be fixed.

Reines 2011-01-23 12:58:04

  • Uploaded patch crammd5.patch. (view)

Here is a slightly tidied, but still 100% untested, patch. I mainly just tidied up the comments etc to match that used in FluxBB, but I also added a check that we have hash_hmac support, since it requires PHP 5.1.2 or the PECL hash extension to be installed.

Reines 2011-01-26 11:31:01

  • Owner set to Reines.

Reines 2011-01-27 16:47:58

I've given this a test and it doesn't currently work - the EHLO command returns a list of extensions. Since we stop reading when we get an AUTH line, the next time we try reading we start at the next extension line, not where we expect.

Reines 2011-01-27 18:20:44

  • Milestone changed from 1.4.4 to 1.4.5.

Reines 2011-02-21 09:45:11

  • Owner Reines removed.

I'm going to take my name off this just in-case anyone else wants to work on it. If not then I'll get back to it later...

Reines 2011-03-11 09:25:24

  • Milestone changed from 1.4.5 to 1.4.6.

Reines 2011-04-18 22:03:10

  • Owner set to Reines.
  • Status changed from open to duplicate.

The current SMTP support is rather messy. I have totally recoded this for FluxBB 2.0, however it isn't suitable for FluxBB 1.4.x so I'm going to just close this ticket.

The ticket regarding this for FluxBB 2.0 is here.

PS. MattF, do you have access to an SMTP server which uses CRAM-MD5? None of the servers I have access to seem to support it (I assume because it requires storing passwords in plain text...).