Is it possible to use the cram-md5 authenticator and in the same time to
keep user's password not in PLAINTEXT but MD5-digest?
The line "The server then computes the CRAM-MD5 digest that the client should
have sent, and checks that it received the correct string" confuses me.
I don't want to compute, but compare MD5-digest.