Details
-
New Feature
-
Status: Stalled (View Workflow)
-
Critical
-
Resolution: Unresolved
Description
configurable default authentication plugin for the server.
"default" applies to the plugin name that the server uses for the first handshake packet, what plugin the server uses when no username is yet known.
- THD statically allocates 20 bytes for a scramble. Can be extended to 32 or malloc-ed every time
- MYSQL statically allocates 20 bytes for a scramble. Cannot be changed. The rest can go into the extension area.
- ed25519/parsec currently don't use the scramle from MYSQL (because it's too short) and request it from the server on every COM_CHANGE_USER. It might be the easiest to keep it that way, still storing the scramble in THD/MYSQL will save one round-trip for ed25519 (but not for parsec).
Attachments
Issue Links
- relates to
-
MDEV-12160 Modern alternative to the SHA1 authentication plugin
-
- Closed
-
-
MDEV-32618 PARSEC Authentication Plugin
-
- Closed
-
-
MXS-5130 Support for PARSEC auth plugin from MDEV-32618
-
- Closed
-
-
MDEV-11340 Allow multiple alternative authentication methods for the same user
-
- Closed
-