Re: Cyrus SASL 2.1.28 testing

Dilyan Palauzov <[email protected]> Sat, 20 Nov 2021 20:23:36 +0000
Newsgroups gmane.comp.security.cyrus.sasl
Message-ID <[email protected]>
Hello,

for me GSSAPI, SPNEGO, and GS2-KRB5 work on the master branch:

# the Kerberos server is obtained by DNS lookup SRV _kerberos._udp.aegee.or=
g )
$ echo abc|kinit [email protected]
Password for [email protected]:

$ curl -v --negotiate -u: -XPROPFIND=20=20
https://mail.aegee.org/dav/calendars/user/aaa/Default
prints
> authorization: Negotiate=20=20
> YIICiAYGKwYBBQUCoIICfDCCAnigDTALBgkqhkiG9xIBAgKiggJlBIICYWCCAl0GCSqGSIb3E=
gECAgEAboICTDCCAkigAwIBBaEDAgEOogcDB
QAgAAAAo4IBZGGCAWAwggFcoAMCAQWhCxsJQUV...

Both when curl is compiled with Cyrus SASL (curl --version says=20=20
nothing about SASL and is linked with libsasl2) and with libgsasl=20=20
(curl --version  prints =E2=80=9Clibgsasl/1.10.0=E2=80=9D and is linked wit=
h libsasl2=20=20
and libgsasl).

# Next commands also work:
$ imtest -t "" -m GSSAPI   mail.aegee.org # (without Channel bindings=20=20
for GSSAPI on both sides)
$ imtest -t "" -m GS2-KRB5 mail.aegee.org # (without Channel bindings)
$ ldapsearch -ZZY GSSAPI    -b"dc=3Daegee,dc=3Dorg" -H=20=20
ldap://ldap.aegee.org   # (I do not know, if openldap utilizes channel=20=20
binding here, but it likely syncs with the ldapsearch client on this)
$ ldapsearch -ZZY GS2-KRB5  -b"dc=3Daegee,dc=3Dorg" -H ldap://ldap.aegee.org
$ sivtest -t "" -m GSSAPI  mail.aegee.org # (no GSSAPI Channel binding)

Greetings
   =D0=94=D0=B8=D0=BB=D1=8F=D0=BD

----- Message from Quanah Gibson-Mount <[email protected]> ---------
     Date: Tue, 16 Nov 2021 14:50:45 -0800
     From: Quanah Gibson-Mount <[email protected]>
Reply-To: SASL <[email protected]>
  Subject: Cyrus SASL 2.1.28 testing
       To: [email protected]


> Hi everyone,
>=20
> The cyrus-sasl-2.1 branch is ready for testing for the proposed
> 2.1.28 Cyrus SASL release.  For those who know how to build from
> source, it would be great if you can test and verify things work as
> expected.  If you have a kerberos based environment that makes use
> of SASL/GSSAPI for a variety of purposes, please note that in any
> feedback.
>=20
> A general list of fixed issues for this release can be found at:
>=20
> <https://github.com/cyrusimap/cyrus-sasl/milestone/2?closed=3D1>
>=20
> Thanks in advance!
>=20
> Regards,
> Quanah
>=20
> --
>=20
> Quanah Gibson-Mount
> Product Architect
> Symas Corporation
> Packaged, certified, and supported LDAP solutions powered by OpenLDAP:
> <http://www.symas.com>


----- End message from Quanah Gibson-Mount <[email protected]> -----




------------------------------------------
Cyrus: SASL
Permalink: https://cyrus.topicbox.com/groups/sasl/T382d628144c05df6-M85fb7b=
60618adeffb8e2fb95
Delivery options: https://cyrus.topicbox.com/groups/sasl/subscription