To the one who posted Cyrus SASL diagram...

Ken Murchison ken at oceana.com
Thu Oct 30 13:06:25 EST 2003


Cyrus Daboo wrote:

> Hi Etienne,
> 
> --On Thursday, October 30, 2003 9:07 -0500 Etienne Goyer 
> <etienne.goyer at linuxquebec.com> wrote:
> 
> | It might be interesting to add that only certain mechanism provide
> | so-called "proxy" authentication (authcid/authzid separation; how would
> | this feature be called ?).  PLAIN and DIGEST-MD5 are the one I know for
> | sure provide it, while CRAM-MD5 don't.  I am not sure about GSSAPI,
> | EXTERNAL and other.
> 
> Both Kerberos_v4 and GSSAPI have authorization ids, as does EXTERNAL. 
> The only standard ones that currently do not are CRAM-MD5 and 
> (obviously) ANONYMOUS.

And just for completeness, the non-standard ones (LOGIN, NTLM) do *not* 
support authzids.

-- 
Kenneth Murchison     Oceana Matrix Ltd.
Software Engineer     21 Princeton Place
716-662-8973 x26      Orchard Park, NY 14127
--PGP Public Key--    http://www.oceana.com/~ken/ksm.pgp





More information about the Info-cyrus mailing list