Re: RE: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Aki Tuomi via dovecot
SCRAM-SHA-256/512 could be one. Aki > On 10/02/2025 16:13 EET Jochen Bern via dovecot wrote: > > > On 10.02.25 14:18, Aki Tuomi wrote: > > I am not sure how we should actually implement this. Do you mean > > that we should require that you always provide a password scheme > > for credentials,

Re: RE: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Jochen Bern via dovecot
On 10.02.25 14:18, Aki Tuomi wrote: I am not sure how we should actually implement this. Do you mean that we should require that you always provide a password scheme for credentials, or require explicit {PLAIN} prefix or what? Everything costs something and has unexpected side-effects, like break