• binkit and SHA-1

    From Dmitry Protasoff@2:5001/100 to Rob Swindell on Sat Sep 26 13:31:53 2026
    Hello All!

    Sorry for probably posting this in the wrong echo, but here's what I found implementing SHA-1 support in my software:

    When my FidoMail answered a call from Synchronet, it offered CRAM authentication in the FTS-1027 format:

    M_NUL "OPT CRAM-SHA1/MD5-<challenge>"

    binkit's load/binkp.js only recognises an option that starts with the literal "CRAM-MD5-":

    if (args[i].substr(0,9) === 'CRAM-MD5-') {
    this.cram = {algo:'MD5', challenge:...};
    }

    FTS-1027 defines the offer as "CRAM-<hash list>-<challenge>", with the hash names separated by '/', so "CRAM-SHA1/MD5-..." is a valid offer that includes MD5:

    FTS-1027:

    ---
    Answering side transmits challenge data in the very first M_NUL message, in the following way:

    M_NUL "OPT [othropt] CRAM-lsthf-cde [othropt]"

    lsthf is a list of aliases of supported hash functions, delimited by slash characters. The list begins with alias of the most preferred and ends with alias of the least preferred hash function.

    Currently defined aliases are: MD5 for [MD5] and SHA1 for [SHA-1].
    ---

    Would it be possible to fix it?

    See you,
    dp.
    --- FidoMail v0.1.4-150-gcf791f6e
    * Origin: livin' on the edge (2:5001/100)