Bluehost.com Web Hosting $6.95

Re: An alternative to Cyrus SASL

This is a discussion on Re: An alternative to Cyrus SASL within the mailing.postfix.users forums, part of the Mail Servers and Related category; > > That would require the SASL daemon to understand SMTP. The daemon > >Do not take me too ...


Go Back   Usenet Forums > Mail Servers and Related > mailing.postfix.users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-08-2004
Petri Riihikallio
 
Posts: n/a
Default Re: An alternative to Cyrus SASL

> > That would require the SASL daemon to understand SMTP. The daemon
>
>Do not take me too literally.


Sometimes you expect people to read your words _very_ literally :o)

I read the Plan 9 auth paper. In an example given a POP server wants
to start a conversation with the client. Factotum tells the server to
start with "+OK POP3 cxhxaxlxlxexnxgxe". The POP server would pass
that verbatim to the client and pass the client response back to
Factotum. I just combined your idea of transparent proxy with this
example.

Now I know better.

>The SASL API is way too complicated for the trivial needs of Postfix.


Whenever you have time to sit down and go through the whole process,
you will find that you are going to need the five steps I outlined
earlier:

>1) initialize
>2) get a list of mechanisms
>3) start the mechanism that client selected
>4) pass protocol data to/from client until success or error
>5) clean up
>With the different mechanisms there are variable number of rounds at #4.


That is the Cyrus|GNU SASL API. I don't think you can do it any simpler.

What you can do is simplify the argument lists a bit. The callbacks
are a real hassle, but there won't be any since the SASLD would be
responsible to look up the secrets in some datastore.

I am eager to see what you have in mind. I have given this matter a
lot of thought lately. Maybe I can give some constructive feedback. I
hope I am not too set in the current API frameset, though.
--
Cheers
Petri

GSM: +358 400 505 939
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 08:43 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0