Re: auxprop pwcheck with sasl ldapdb and openldap backend not working

"PFiver via SASL" <[email protected]> Sat, 6 Nov 2021 18:41:22 -0400
Newsgroups gmane.comp.security.cyrus.sasl
Message-ID <[email protected]>
Got it.... thank you!

I was finally able to get cyrus-imapd to talk to the ldap as well, by removing the "-hashed" suffix.
 
I am wondering, what to do now. For one thing, hashed LDAP passwords seem to be supported in saslauthd: https://github.com/cyrusimap/cyrus-sasl/blob/master/saslauthd/lak.c#L128

I am not willing to story pain passwords in the ldap (and use "auxprop" with "ldapdb" as is), but I am tempted to attempt to port that part over to the sasl-ldapdb module.

The first option would certainly be easier. But the second more fun, maybe. :-)

But what are - hypothetically -  the chances of getting that code - assuming it would be a few dozen lines in, say plugins/ldapdb.ch and maybe re-using parts from lak.c - accepted in cyrus-sasl?

Would some of the original developers and/or current maintainers  of the code in question be willing to assist in helping to collect all the information required and drafting a design for a solution?

- plugins/ldapdb.ch -> e.g. Howard Chu, Ken Murchison ?
- saslauthd/lak.c -> e.g. Igor Brezac, Rob Siemborski ?

I would be willing to put in a few days to help with the design and then write code and test. (Which is not a commitment yet, but if there is some general support for the idea, that would help, of course, to increase the chances of me "finding" those hours...
------------------------------------------
Cyrus: SASL
Permalink: https://cyrus.topicbox.com/groups/sasl/T2c60ca246b64197b-M8b5f912bd5ced09d563c467d
Delivery options: https://cyrus.topicbox.com/groups/sasl/subscription