Jackie submits CCS proposal to update monerod HTTP Digest RPC authentication to RFC7616
Jackie1 has submitted a new CCS proposal2 looking to migrate monerod’s built‑in HTTP Digest RPC authentication from the existing RFC 2617 to RFC 76163:
This change enables the use of HA1 hash credentials in place of plain‑text rpc‑login, eliminating plain‑text password storage. It mitigates security risks associated with the MD5 algorithm and reduces exposure to password leaks originating from compromised configuration files.
Total funding: 11.1 XMR.
ETA: TBD (168 hours).
It is worth noting that Jackie’s previous CCS proposals were closed4.
To read, share your feedback, ask questions and support this proposal, consult !6982.
This is an ongoing story and the report will be updated when new information is available.
-
https://github.com/PyXMR2025 ↩
-
https://repo.getmonero.org/monero-project/ccs-proposals/-/merge_requests/698 ↩ ↩2
-
https://www.rfc-editor.org/info/rfc7616, https://github.com/monero-project/monero/blob/master/contrib/epee/src/http_auth.cpp ↩
-
/openenet-submits-largest-ccs-proposal-build-monerospace-satellite-network/, /jackie-submits-ccs-proposal-monero-videos-chinese/ ↩