RE: SASL authentication

"Xu, Qiang (FXSGSC)" <[email protected]>
Newsgroups gmane.comp.mozilla.devel.directory
Message-ID <D8C9BC7FFCF8154FB7141EB8DB609C17223A2409EC@SGPAPHQ-EXSCC01.dc01.fujixerox.net>
> -----Original Message-----
> From: Rich Megginson [mailto:[email protected]] On
> Behalf Of Rich Megginson
> Sent: Tuesday, November 04, 2008 11:27 PM
> To: Xu, Qiang (FXSGSC)
> Cc: [email protected]; Michael Ströder
> Subject: Re: SASL authentication
>
> This is a very bad example for using SASL/GSSAPI.  Please
> refer to the actual source code.  There is an example file -
> http://mxr.mozilla.org/mozilla/source/directory/c-sdk/ldap/exa
> mples/saslsearch.c

Got it. Previously, I want to use ldap_sasl_bind_s() to avoid the hassle in dealing with asynchronous SASL binding with ldap_sasl_bind(), that is, to avoid the challenges sent back from the server with LDAP_SASL_BIND_IN_PROGRESS.

> For GSSAPI, it doesn't matter, because the real credentials
> will come from the TGT.

Good to hear this.

> Yes, but no, because you should not use ldap_sasl_bind_s, you
> should use ldap_sasl_interactive_bind_ext_s instead - see
> saslsearch.c above.

Why can't I find the reference to the function ldap_sasl_interactive_bind_ext_s() in MozLDAP C SDK document page (http://www.mozilla.org/directory/csdk-docs/function.htm)? Is this document outdated? And what benefit does it have, compared to ldap_sasl_bind_s()? In other words, what potential risk does ldap_sasl_bind() have?

Thanks a lot,
Xu Qiang
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.