Re: MD5 in APOP

Albert 'Tigr' Dorofeev (
Thu, 10 Oct 2002 18:58:40 +0200 (CEST)

On Thu, 10 Oct 2002, Albert 'Tigr' Dorofeev wrote:

> Hi, all!
> Can someone patiently explain me why the @#$% md5_sum gives
> a value different from the MD5() function in OpenSSL lib?

This question stands. Really, now, what does md5_sum do?

> And what do the POP servers expect? They definitely don;t
> implement APOP authentication as explained in RFC...

Oh, well, they do, after all. It's the bloody server
that is not configured properly. Who would expect
the server to re-hash the hashes of the passwords
without telling something like "Sorry, no plaintext
password can be found, can't go on"?


