[Imap-protocol] STARTTLS after PREAUTH

Michael M Slusarz <[email protected]>
Newsgroups gmane.mail.imap.general
Message-ID <20140318141305.Horde.iyy0UP8Ostx9TojRZiFyjw1@bigworm.curecanti.org>
STARTTLS is a non-authenticated command (3501 [6.2.1]).

Am I correct in my reading that this means that you lose any ability  
to protect message data via TLS if PREAUTH is used?  In other words:  
was STARTTLS solely designed to protect authentication credentials  
(security) and not message data (privacy)?

I guess the workaround for a situation where you *could*  
preauthenticate based on connection factors/details, but still need  
message privacy, is to require some sort of dummy authentication  
(after initializing TLS layer).  Feels pretty hackish though.

michael

_______________________________________________
Imap-protocol mailing list
[email protected]
http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.