Re: OpenLDAP/SASL/GSSAPI/Kerberos issue with Active Directory searches (ITS#2179)


This would be better if such limits were defined within lower level 
packages, in this case SASL so that you don't have such inter-dependencies.

I have also submitted this issue to Microsoft and will see what happens.


>My mistake. You reported this bug against GSSAPI, and the Cyrus GSSAPI 
>was patched in 2.1.9 to allow 16M. (The DIGEST-MD5 plugin still has the 64K
>limit. I believe this must be an oversight in the 2.1.9 release. Also in 
>the SRP
>Unfortunately this makes it difficult for us to change the definition of
>SASL_MAX_BUFF_SIZE in ldap-int.h without requiring that everyone upgrade to
>Cyrus 2.1.10 (whenever that gets released). Tracking bug fixes in other 
>is always troublesome.

