[Date Prev][Date Next] [Chronological] [Thread] [Top]

RE: Cyrus SASL 2 is no good



> -----Original Message-----
> From: Kurt D. Zeilenga [mailto:Kurt@OpenLDAP.org]

> At 10:42 PM 2002-04-19, Howard Chu wrote:
> >I've noticed that the Cyrus 2 GSSAPI plugin tends to always send
> a non-NULL
> >authzid with its requests.
>
> Which is broken.  They should not send an authzid unless the
> user is attempting proxy authorization.

Ah, thanks for pointing that out. I was using the Cyrus CVS and the last
patch I sent introduced this bug. The Cyrus library still requires authcid
and authzid to be non-empty, but usually it's handled by copying authcid to
authzid on the client and on the server. So a "default" authzid usually
doesn't get
transmitted over the wire.

  -- Howard Chu
  Chief Architect, Symas Corp.       Director, Highland Sun
  http://www.symas.com               http://highlandsun.com/hyc
  Symas: Premier OpenSource Development and Support