- Implement SCRAM-SHA-512 (RFC 5802 with SHA-512) as a Luma-side
SaslMechanism and register it ahead of Martin's SHA-256/SHA-1/PLAIN,
so modern servers preferring SHA-512 authenticate with it.
- Verify the math against Python-computed reference vectors (salted
password, client proof, server signature) in SCRAMSHA512Tests and
guard the mechanism registration in Scripts/verify.sh.
- Confirm the TLS stack negotiates TLS 1.3 (negotiatedSSL + ALPN via
SecureTransport, handshake verified against a TLS 1.3-only server)
and document the TLS/SCRAM posture in SECURITY.md.