mod_saslauth: Disable DIGEST-MD5 by default (closes #515)
authorKim Alvefur <zash@zash.se>
Fri, 18 Mar 2016 11:51:58 +0100
changeset 7301 7056bbaf81ee
parent 7297 5f4d0753c818
child 7302 b7dea8fd09c7
mod_saslauth: Disable DIGEST-MD5 by default (closes #515)
plugins/mod_saslauth.lua
--- a/plugins/mod_saslauth.lua	Fri Mar 18 00:08:33 2016 +0100
+++ b/plugins/mod_saslauth.lua	Fri Mar 18 11:51:58 2016 +0100
@@ -19,7 +19,7 @@
 local secure_auth_only = module:get_option_boolean("c2s_require_encryption", module:get_option_boolean("require_encryption", false));
 local allow_unencrypted_plain_auth = module:get_option_boolean("allow_unencrypted_plain_auth", false)
 local insecure_mechanisms = module:get_option_set("insecure_sasl_mechanisms", allow_unencrypted_plain_auth and {} or {"PLAIN", "LOGIN"});
-local disabled_mechanisms = module:get_option_set("disable_sasl_mechanisms", {});
+local disabled_mechanisms = module:get_option_set("disable_sasl_mechanisms", { "DIGEST-MD5" });
 
 local log = module._log;