LDAP authentication without saslautd

"PFiver via SASL" <[email protected]> Mon, 29 May 2023 12:22:55 -0400
Newsgroups gmane.comp.security.cyrus.sasl
Message-ID <[email protected]>
--16853773751.dD22a.15293
Date: Mon, 29 May 2023 12:22:55 -0400
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

I am making another effort to upgrade my mail and calendar system from dove=
cot and apple calendarserver-

cyrus-imapd seems still be the best option, as it has caldav and carddav su=
pport, which I need and I don't like any of the PHP implementations that ar=
e also available for free.

However, my setup includes an openLDAP instance where I store {SSHA} passwo=
rd <https://www.openldap.org/faq/data/cache/347.html>. Thus I can not use t=
he "auxprop" plugins.

Is there a specific reason why none of the available mechanisms / plugins i=
s supporting this setup?

Although there has been a patch <https://www.openldap.org/lists/openldap-so=
ftware/200108/msg00075.html> contributed to the mailing list (in 2001 !) an=
d there is an open pull-request <https://github.com/cyrusimap/cyrus-sasl/pu=
ll/468> that would enable it, the functionality to _verify a user-supplied =
plain-text password against a stored hash_ still seems to be lacking from t=
he trunk.

Or am I missing something here?

------------------------------------------
Cyrus: SASL
Permalink: https://cyrus.topicbox.com/groups/sasl/T944af1261400714f-M05b928=
c71f697a5dba0186cc
Delivery options: https://cyrus.topicbox.com/groups/sasl/subscription

--16853773751.dD22a.15293
Date: Mon, 29 May 2023 12:22:55 -0400
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE html>
<html><html><html><body><div>I am making another effort to upgrade my mail =
and calendar system from dovecot and apple calendarserver-<br /></div><div>=
<br /></div><div>cyrus-imapd seems still be the best option, as it has cald=
av and carddav support, which I need and I don&#39;t like any of the PHP im=
plementations that are also available for free.<br /></div><div><br /></div=
><div>However, my setup includes an openLDAP instance where I store <a href=
=3D"https://www.openldap.org/faq/data/cache/347.html">{SSHA} password</a>. =
Thus I can not use the &quot;auxprop&quot; plugins.<br /></div><div><br />I=
s there a specific reason why none of the available mechanisms / plugins is=
 supporting this setup?</div><div><br /></div><div>Although there has been =
a <a href=3D"https://www.openldap.org/lists/openldap-software/200108/msg000=
75.html">patch</a> contributed to the mailing list (in 2001 !) and there is=
 an open <a href=3D"https://github.com/cyrusimap/cyrus-sasl/pull/468">pull-=
request</a> that would enable it, the functionality to <u>verify a user-sup=
plied plain-text password against a stored hash</u> still seems to be lacki=
ng from the trunk.<br /></div><div><br /></div><div>Or am I missing somethi=
ng here?<br /></div><div><br /></div><div id=3D"topicbox-footer" style=3D"m=
argin:10px 0 0;border-top:1px solid #ddd;border-color:rgba(0,0,0,.15);paddi=
ng:7px 0;">

<strong><a href=3D"https://cyrus.topicbox.com/latest" style=3D"color:inheri=
t;text-decoration:none">Cyrus</a></strong>
  / SASL / see
<a href=3D"https://cyrus.topicbox.com/groups/sasl">discussions</a>
  +
<a href=3D"https://cyrus.topicbox.com/groups/sasl/members">participants</a>
  +
<a href=3D"https://cyrus.topicbox.com/groups/sasl/subscription">delivery&nb=
sp;options</a>
<a href=3D"https://cyrus.topicbox.com/groups/sasl/T944af1261400714f-M05b928=
c71f697a5dba0186cc" style=3D"float:right">Permalink</a>
</div>
</body></html></html></html>=

--16853773751.dD22a.15293--