Internet Engineering Task Force (IETF) A. Melnikov Request for Comments: 5803 Isode Limited Category: Informational July 2010 ISSN: 2070-1721Lightweight Directory Access Protocol (LDAP) Schema for Storing Salted Challenge Response Authentication Mechanism (SCRAM) Secrets
Melnikov Informational [Page 1]
RFC 5803 LDAP Schema for Storing SCRAM Secrets July 2010
Table of Contents
1. Overview
This document describes how the authPassword LDAP attribute [AUTHPASS] can be used for storing secrets used by [SCRAM] Simple Authentication and Security Layer [RFC4422] Mechanisms.
Melnikov Informational [Page 2]
RFC 5803 LDAP Schema for Storing SCRAM Secrets July 2010
; See definition in [SCRAM].
2. Conventions Used in This Document
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].
3. Security Considerations
This document defines how the authPassword attribute can be used to store SCRAM secrets. Therefore, security considerations relevant to [SCRAM] and hash functions used with it are also relevant to this document.
Melnikov Informational [Page 3]
RFC 5803 LDAP Schema for Storing SCRAM Secrets July 2010 4. AcknowledgementsThe author gratefully acknowledges the feedback provided by Chris Newman, Kurt Zeilenga, Chris Lonvick, Peter Saint-Andre, Barry Leiba, and Chris Ridd.
5. Normative References
[AUTHPASS] Zeilenga, K., "LDAP Authentication Password Schema",