RFC 5802 · PROPOSED STANDARD · 2010

Salted Challenge Response Authentication Mechanism SASL and GSS-API Mechanisms

Overview

RFC 5802, “Salted Challenge Response Authentication Mechanism SASL and GSS-API Mechanisms”, is a Proposed Standard document published in July 2010 by C. Newman, A. Menon-Sen, A. Melnikov, N. Williams. It has since been updated by RFC 7677, RFC 9266. The canonical text is published by the RFC Editor.

Abstract

The secure authentication mechanism most widely deployed and used by Internet application protocols is the transmission of clear-text passwords over a channel protected by Transport Layer Security (TLS). There are some significant security concerns with that mechanism, which could be addressed by the use of a challenge response authentication mechanism protected by TLS. Unfortunately, the challenge response mechanisms presently on the standards track all fail to meet requirements necessary for widespread deployment, and have had success only in limited use.

This specification describes a family of Simple Authentication and Security Layer (SASL; RFC 4422) authentication mechanisms called the Salted Challenge Response Authentication Mechanism (SCRAM), which addresses the security concerns and meets the deployability requirements. When used in combination with TLS or an equivalent security layer, a mechanism from this family could improve the status quo for application protocol authentication and provide a suitable choice for a mandatory-to-implement mechanism for future application protocol standards. [STANDARDS-TRACK]

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 5802 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
Updated by
RFC 7677 RFC 9266
Other RFCs from 2010

Who Is Online

In total there are 46 users online: 0 registered, 38 guests and 8 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Bingbot Facebook Googlebot Other Bot SemrushBot Sogou

Users active in the past 15 minutes. Total registered members: 354