ECTED]
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| /usr/contributed Gatekeeper
-BEGIN GEEK CODE BLOCK
Version: 3.12
GCS/IT/CM/CC/PA d- s+: a-- C$ UBLS$ P+++$ L++(+++) E
dback either to [EMAIL PROTECTED] (public
list) or to [EMAIL PROTECTED]
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | W3VC President * Scotch & Soda Technical Coordinator
Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK | ABTech Exec
-BEGIN
On Sat, 14 Jul 2001, Jeremy Howard wrote:
> "Rob Siemborski" <[EMAIL PROTECTED]> wrote:
> > I'd like to announce the release of Cyrus SASL 2.0.2-ALPHA, available on
> > ftp.andrew.cmu.edu.
> >
> Is there a quick overview someplace of what the major ch
using, as well as the output of ldd on
libgssapiv2.so
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
.c. It
loops through all the possible mechanisms and looks for a match.
Currently it will only match against a single mech, but you could impose
some sort of format on the pwcheck method variable which could be used to
check more than one mech...
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
-sasl-2.0.3-BETA.tar.gz
Thanks,
Rob Siemborski
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
or each) are listed
at:
http://www.iana.org/assignments/sasl-mechanisms
I hope this helps,
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
.cmu.edu.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
hives live are at the same location as the old one,
http://asg.web.cmu.edu/bb/archive.info-cyrus
http://asg.web.cmu.edu/bb/archive.cyrus-sasl
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU
EMAIL PROTECTED] or
[EMAIL PROTECTED]
Download at:
ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-sasl-2.0.4-BETA.tar.gz
Thanks,
Rob Siemborski
- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU
the CVS for SASL 1.5, however,
nothing of such major concern to warrant a new release.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
on-plaintext mechs. You'll have to check with
> Rob Siemborski about this.
No, it is not possible to sue CRAM-MD5 (or DIGEST-MD5) with
pwcheck/saslauthd, because the mechanism needs to be able to compute the
secret which is used from the plaintext. saslauthd and pwcheck both will
only veri
that resetting passwords would be, at best, "interesting"), but
there's no reason that I can currently think of that the database file
cannot be shared in a read-only enviornment.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Syste
mproved memory allocation and management, as well as more
build options (for example, you can build a static libsasl2) that can
improve performance in the long run.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 4
ary. There is no requirement that
any mechanism plugin use sasldb for authentication (e.g. KERBEROS_V4).
For the record, saslpasswd makes all appropriate setpass() calls, though
the supplied mechanisms do not make use of it (except possibly OTP at
this point, but I'm not sure).
-Rob
-=-=-=-
. Offhand, I'm not sure if it's
in the most recent release or not.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
t's not entirely in sync with
non-sasl-related changes.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
se on production systems.
Please send any feedback either to [EMAIL PROTECTED]
(public list) or to [EMAIL PROTECTED]
Download at:
ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-sasl-2.0.5-BETA.tar.gz
Thanks,
Rob Siemborski
- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
thenticate from it.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
saslauthd, you give it a password checking mechanism (e.g. pam or
rimap or kerberos4 or shadow, such as:
saslauthd -a shadow
-Rob
On Fri, 7 Dec 2001, Vincent Stoessel wrote:
> How then does pam interface with the new saslauthd?
>
>
>
> Rob Siemborski wrote:
>
> > On
this message.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
SASLAUTHD(8)System Manager's Manual SASLAUTHD(8)
NNAAMMEE
ssaassllaauutthhdd - sa
lly won't have anything
finalized for another week or two.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | W3VC President * Scotch & Soda Technical Coordinator
Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK | ABTech Exec
- -BEGIN GEEK CODE BLOCK
Version: 3.12
GCS/IT/CM/CC/PA d- s+: a-- C$ UBLS$ P+++$ L++(+++) E W- N- o?
K- w O- M-- V-- PS+ PE
admins and proxyservers are
allowed to authorize to a different user.
I *suspect* the command you want is:
sieveshell -u mailadmin -a mailadmin localhost
But without further information I cannot be sure.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andr
some issues with lmtp authentication
(especially with regards to unix sockets). They have since been fixed in
CVS.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
htforward if you were going to go
ahead and implement this.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
switches
back into broadcast mode, so I would be wary of doing administrative
PLAIN logins without the protection of SSL.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SA
sg=11576
Also, what mechanism is pop3 using to authenticate with? Does pop3test
work?
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
x27;t connect to lmtpd: Success
> 421 4.3.0 deliver: couldn't connect to lmtpd
>
> Does anyone have an idea?
There is a problem in the unix socket SASL implementation in Cyrus 2.1.0.
If you grab a new lmtpengine.c out of CVS that should fix the problem.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=
On Fri, 4 Jan 2002, Alec H. Peterson wrote:
> --On Friday, January 4, 2002 19:57 -0500 Rob Siemborski
> <[EMAIL PROTECTED]> wrote:
>
> I should have also mentioned that I've been running under 2.0.16 without
> any problems for months.
>
> I converted /etc/sasl
es.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
esirable for the linker,
> but the sasl2 autoconf stuff doesn't make use of this.
I just committed what I believe to be a fix for these two problems into
CVS. Could you verify that the new version is now working for you?
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
l), then it is
fine and nroff is not needed.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
hanks for your very helpful reports ;)
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
| Cyrus SASL Developer, /usr/contributed Gatekeeper
ease out by
early next week.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
Research Systems Programmer * /usr/contributed Gatekeeper
out by early next
week).
Thanks,
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
Research Systems Programmer * /usr/contributed Gatekeeper
his answers your question, but I hope it helps.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
Research Systems Programmer * /usr/contributed Gatekeeper
tch ;)
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
Research Systems Programmer * /usr/contributed Gatekeeper
On Fri, 18 Jan 2002, Igor Brezac wrote:
> Will cyrus sasl 2.1.0 work with DB4?
Cyrus SASL does not use the transaction API of DB4, so there shouldn't be
any problems with it.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Syste
gned certificate only, you will need
to submit a CSR to a CA to get a signed one (see OpenSSL documentation).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
Research Systems Programmer * /usr/contributed Gatekeeper
op plugin or saslauthd module that
worked with SASLv2.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
Research Systems Programmer * /usr/contributed Gatekeeper
ce output from this, it would be helpful.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
Research Systems Programmer * /usr/contributed Gatekeeper
the
plugins can make use of it as they see fit, either to point to a config
file or straight off the command line.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
Research Systems Programmer * /usr/contributed Gatekeeper
are logged at the LOG_DEBUG level so if you decrease the
level that syslog logs at they will go away.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
Research Systems Programmer * /usr/contributed Gatekeeper
ibution.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-CMU-TREK
Research Systems Programmer * /usr/contributed Gatekeeper
t) or [EMAIL PROTECTED]
Download at:
ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-sasl-2.1.1.tar.gz
or:
http://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-sasl-2.1.1.tar.gz
Thanks,
- -Rob
- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group - Res
it interprets & as a shell would.
So, you need to escape it as well to prevent it from thinking you want to
background the process. eg:
cm user.user\&-co
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 23
keley DB 3.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
rseing of the pwcheck_method option shouldn't be very hard (If you
do it, send us a patch!).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
ure that SASL is installed properly (symlink made for
/usr/lib/sasl2, etc).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
ssword checker can only be
defined on the server side.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
fault will still be to be a temporary failure.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
On Thu, 21 Feb 2002, Rob Siemborski wrote:
> This part is actually pertty interesting, since you're not seeing
> AUTH=PLAIN banners (and you have sasl_mech_list set to plain), it implies
> that cyrus can't see your plugin directory, are permissions set on it in a
> r
ion function (though we do
make the mechanism-specific setpass callbacks).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
s, we're currently planning on deploying skiplist to production
for atleast the mailboxes database this weekend.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
ut before 2.1.0...
I believe the tag you are looking for is "cyrus-2-1-sasl-v1-tail"
so, something similar to
cvs co -r cyrus-2-1-sasl-v1-tail cyrus
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-
On Tue, 26 Feb 2002, John C. Amodeo wrote:
> I think (I could be wrong) there may be a problem with CVS.
I believe I have fixed the problem, please try again.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall
e (GNU automake) 1.4
ltmain.sh (GNU libtool) 1.3.4 (1.385.2.196 1999/12/07 21:47:57)
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
the non-loopback interface, since some
of this stuff may be being put in because of the hostname.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
linux imapd[11030]: badlogin: thor.awc[192.168.144.12]
> plaintext nico SASL(-4): no mechanism available: checkpass failed
[snip]
> sasl_pwcheck_method: sasldb
Please see the archives of the list, you want:
sasl_pwcheck_method: auxprop
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
re changing your servername in
imapd.conf
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
uld export
this (which is basically all of the included ones, except for libsasldb).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
ST-MD5 with LDAP won't work with out an LDAP auxprop plugin, since it
needs the plaintext password (or DIGEST secret). (i.e. it won't work with
saslauthd).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
e dicumentation in the doc/ directory could probably stand some
improvment. Suggestions are welcome, patches are encouraged ;)
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
EMAIL PROTECTED]
Download at either:
http://ftp.andrew.cmu.edu/pub/cyrus/cyrus-sasl-2.1.2.tar.gz
or
ftp://ftp.andrew.cmu.edu/pub/cyrus/cyrus-sasl-2.1.2.tar.gz
- -Rob
- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268
has been done with KERBEROS_V4, GSSAPI shouldn't be any different). If
there were bugs, I'd expect to see them with the shared secret mechs (i.e.
PLAIN, CRAM-MD5, DIGEST-MD5, etc.)
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Syste
ds to sasldb2?
Only if you want to use CRAM, DIGEST, SRP, OTP, etc...
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
he configure flag is --enable-auth-sasldb).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
om CVS in the doc
directory).
We'd probably want to stay with the Xfig format for any other diagrams
(such as the Cyrus Murder diagram in the imapd distribution) due to the
fact that it is text based and easy to convert to other formats.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
CVS?
Done. (That is, I added a #include above the sys/socket.h
include).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
ctually needs to write to the database.
Also, LOGIN also uses checkpass.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
uct
of the variety of situations where it has been used in the past, not a
requirement of SASL.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
that can return either a hash of the correct format
for the mechanism via the "cmusaslsecret(MECHNAME)" properties, or a
plaintext password via the userPassword property should be doing "the
right thing"
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Ro
rect
> thing).
Well, yes, but the secret that is being stored has to be (in, for example,
the case of DIGEST-MD5) a DIGEST-MD5 secret, it can't just be a regular
md5 hash.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group *
laintext password).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
is slightly different. The differences
allow the SASLv2 saslauthd to differentiate between service types.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
ELEASE:
[snip]
Sorry for the delay. I've made your changes a bit more generic (so that
configure figures out fdatasync on platforms other than FreeBSD correctly
also), and committed them.
Thanks,
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * And
I see
> the following errors in the log file:
you need to do a
require "reject";
at the top of the file.
Note, that if you use other features this line may look more like:
require ["reject","fileinto","envelope"];
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
h a header and allow people to use sieve to do
what they will with the resulting messages.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
nd come back when you encounter the SASL re-entrancy bug.
saslauthd naturally negates any reentrancy issues.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
any of the other shared-secret mechs, such as
DIGEST, or SRP) with saslauthd. Since the information just isn't there to
do the authentication with. You'd need to use sasldb for it to work.
Sorry,
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski
pile imapd correctly.
saslauthd is a separate binary. you need to configure sasl
--with-saslauthd to compile it (and enable the password verifier internal
within the library).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
was not built with
--with-saslauthd (or there is a misspelling somewhere, like the conf
file).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
;m too lazy to do a real patch, but you get the idea... ;-)
>
> buf is actually uninitialized at this point, so this bug causes
> intermittent failures that are hard to track down.
>
>
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Syst
imultaneously, and nobody appears to know how to fix it ...
We have it working here at CMU. We use MIMEDefang (a milter) to call
SpamAssassin on each message, and add a header as appropriate. There was
not a terrible trial configuring it either.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
ved the sasl_mech_list option if you can't
support mechs other than PLAIN anyway?
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
orrections to the GSSAPI
plugin), and of course Ken Murchison (for the general plugin cleanup).
- -Rob
- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski | Andrew Systems Group - Research Systems Programmer
Scotch & Soda Technical Coordinator | Cyert Hall
that SA can put enough information in the header to let sieve
have pretty fine-grained control over the message.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
ocate that file (in a manner similar to timsieved).
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
ld be fine, but in the case of Cyrus
lmtpproxyd currently this isn't exactly a plug-and-play operation...
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
webpages (whoops ;) (along with sasl-cvs)
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
ke 1.4, which are
not the most recent versions
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
DFLAGS=$LIB_SASL
to
LDFLAGS=$LIB_SASL $LDFLAGS
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
/* POSIX */
# else
#define O_DSYNC O_FSYNC /* BSD */
# endif
#endif
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
t's how you do it.
Were any error messages logged?
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
On Thu, 16 May 2002, Mathew Hennessy wrote:
> >What version of cyrus is this?
> >
> CVS:
Run recovery on your databases (ctl_cyrusdb -r)
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-26
On Thu, 16 May 2002, Mathew Hennessy wrote:
> I've got a folder that I want to wipe, but it's got a \Noselect flag
> and my attempts at removal are thwarted :/
What version of cyrus is this?
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Sie
rather know why recovery isn't clearing it.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
ct that it's a trivial matter for an
eavesdropper to get the password if PLAIN is used without TLS protection.
-Rob
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper
1 - 100 of 1236 matches
Mail list logo