Why is SASL authentication have to be so difficult? Round 2

Igor Brezac igor at ipass.net
Tue Dec 7 11:26:16 EST 2004


On Tue, 7 Dec 2004, Derrick J Brashear wrote:

> But it looks like I also miss the scope; sasl_check_pass canonifies (which 
> means auxprop_verify_password canonifies twice from sasl_check_pass, and from 
> sasl_user_exists is the only verify_password backend which canonifies... 
> sigh)
>
> anyway, i think there is something more subtle doing on here maybe?
>

I have not looked at the code in awhile, but it looks like double 
canonification occurs twice in cmd_login() as well - imapd_canon_user() 
and sasl_checkpass().

-- 
Igor
---
Cyrus Home Page: http://asg.web.cmu.edu/cyrus
Cyrus Wiki/FAQ: http://cyruswiki.andrew.cmu.edu
List Archives/Info: http://asg.web.cmu.edu/cyrus/mailing-list.html




More information about the Info-cyrus mailing list