Re: LDAP authentication without saslautd
"Patrick Pfeifer via SASL" <[email protected]> Mon, 29 May 2023 18:39:53 +0200
| Newsgroups | gmane.comp.security.cyrus.sasl |
|---|---|
| Message-ID | <[email protected]> |
--------------TYihNvmM7FXmxDaaZXV0VXw2
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable
Ah. Yea, sorry: I forgot to mention that for - no good reason other than=20
the love of simplicity - another constraint that I am imposing on the=20
solution is that I do not want to use saslauthd. I guess that actually=20
sort of answers the "what am I missing" part of the question. But I am=20
missing that on purpose. I just do not want that daemon running.
So actually this is actually more kind of a feature request: I'd like to=20
have the functionality of that 2001 patch implemented. :-) And, as I=20
assume everybody is busy scratching their own itches: Is there any good=20
reason for me not to pursue this?
On 29.05.23 18:22, PFiver via SASL wrote:
> I am making another effort to upgrade my mail and calendar system from=20
> dovecot and apple calendarserver-
>
> cyrus-imapd seems still be the best option, as it has caldav and=20
> carddav support, which I need and I don't like any of the PHP=20
> implementations that are also available for free.
>
> However, my setup includes an openLDAP instance where I store {SSHA}=20
> password <https://www.openldap.org/faq/data/cache/347.html>. Thus I=20
> can not use the "auxprop" plugins.
>
> Is there a specific reason why none of the available mechanisms /=20
> plugins is supporting this setup?
>
> Although there has been a patch=20
> <https://www.openldap.org/lists/openldap-software/200108/msg00075.html>=20
> contributed to the mailing list (in 2001 !) and there is an open=20
> pull-request <https://github.com/cyrusimap/cyrus-sasl/pull/468> that=20
> would enable it, the functionality to _verify a user-supplied=20
> plain-text password against a stored hash_ still seems to be lacking=20
> from the trunk.
>
> Or am I missing something here?
>
> *Cyrus <https://cyrus.topicbox.com/latest>* / SASL / see discussions=20
> <https://cyrus.topicbox.com/groups/sasl> + participants=20
> <https://cyrus.topicbox.com/groups/sasl/members> + delivery=C2=A0options=
=20
> <https://cyrus.topicbox.com/groups/sasl/subscription> Permalink=20
> <https://cyrus.topicbox.com/groups/sasl/T944af1261400714f-M05b928c71f697a=
5dba0186cc>=20
>
------------------------------------------
Cyrus: SASL
Permalink: https://cyrus.topicbox.com/groups/sasl/T944af1261400714f-M877f32=
4b6f8223e1a3200790
Delivery options: https://cyrus.topicbox.com/groups/sasl/subscription
--------------TYihNvmM7FXmxDaaZXV0VXw2
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
<html><html><html><head><meta content=3D"text/html; charset=3DUTF-8" http-e=
quiv=3D"Content-Type" /></head><body><div class=3D"moz-cite-prefix">Ah. Yea=
, sorry: I forgot to mention
that for - no good reason other than the love of simplicity -
another constraint that I am imposing on the solution is that I do
not want to use saslauthd. I guess that actually sort of answers
the "what am I missing" part of the question. But I am miss=
ing
that on purpose. I just do not want that daemon running.</div><div cl=
ass=3D"moz-cite-prefix"><br /></div><div class=3D"moz-cite-prefix">So actua=
lly this is actually more kind
of a feature request: I'd like to have the functionality of that
2001 patch implemented. :-) And, as I assume everybody is busy
scratching their own itches: Is there any good reason for me not
to pursue this?<br /></div><div class=3D"moz-cite-prefix"><br /></div=
><div class=3D"moz-cite-prefix">On 29.05.23 18:22, PFiver via SASL
wrote:<br /></div><blockquote cite=3D"mid:16853773750.d097.15293@comp=
oser.cyrus.topicbox.com" type=3D"cite"><meta content=3D"text/html; charset=
=3DUTF-8" http-equiv=3D"content-type" /><div>I am making another effort to =
upgrade my mail and calendar
system from dovecot and apple calendarserver-<br /></div><div><br /=
></div><div>cyrus-imapd seems still be the best option, as it has caldav
and carddav support, which I need and I don't like any of the
PHP implementations that are also available for free.<br /></div><d=
iv><br /></div><div>However, my setup includes an openLDAP instance where I=
store
<a href=3D"https://www.openldap.org/faq/data/cache/347.html" moz-do=
-not-send=3D"true">{SSHA} password</a>. Thus I can not use
the "auxprop" plugins.<br /></div><div><br />
Is there a specific reason why none of the available mechanisms
/ plugins is supporting this setup?</div><div><br /></div><div>Alth=
ough there has been a <a href=3D"https://www.openldap.org/lists/openldap-so=
ftware/200108/msg00075.html" moz-do-not-send=3D"true">patch</a> contributed=
to the mailing
list (in 2001 !) and there is an open <a href=3D"https://github.com=
/cyrusimap/cyrus-sasl/pull/468" moz-do-not-send=3D"true">pull-request</a> t=
hat would enable it,
the functionality to <u>verify a user-supplied plain-text
password against a stored hash</u> still seems to be lacking
from the trunk.<br /></div><div><br /></div><div>Or am I missing so=
mething here?<br /></div><div><br /></div></blockquote><p><br /><div id=3D"=
topicbox-footer" style=3D"margin:10px 0 0;border-top:1px solid #ddd;border-=
color:rgba(0,0,0,.15);padding:7px 0;">
<strong><a href=3D"https://cyrus.topicbox.com/latest" style=3D"color:inheri=
t;text-decoration:none">Cyrus</a></strong>
/ SASL / see
<a href=3D"https://cyrus.topicbox.com/groups/sasl">discussions</a>
+
<a href=3D"https://cyrus.topicbox.com/groups/sasl/members">participants</a>
+
<a href=3D"https://cyrus.topicbox.com/groups/sasl/subscription">delivery&nb=
sp;options</a>
<a href=3D"https://cyrus.topicbox.com/groups/sasl/T944af1261400714f-M877f32=
4b6f8223e1a3200790" style=3D"float:right">Permalink</a>
</div>
</body></html></html></html>=
--------------TYihNvmM7FXmxDaaZXV0VXw2--