Re: [Imap-protocol] STARTTLS after PREAUTH

Jan Kundrát <[email protected]>
Newsgroups gmane.mail.imap.general
Message-ID <[email protected]>
On Tuesday, 18 March 2014 21:13:05 CEST, Michael M Slusarz wrote:
> Am I correct in my reading that this means that you lose any 
> ability to protect message data via TLS if PREAUTH is used?  In 
> other words: was STARTTLS solely designed to protect 
> authentication credentials (security) and not message data 
> (privacy)?

Not at all. Once issued, STARTTLS protects everything, i.e. both your 
credentials and transfers of all messages.

> I guess the workaround for a situation where you *could* 
> preauthenticate based on connection factors/details, but still 
> need message privacy, is to require some sort of dummy 
> authentication (after initializing TLS layer).  Feels pretty 
> hackish though.

That's what you could get with AUTH EXTERNAL. Also, nothing prevents a 
server from going directly to PREAUTH if the whole connection is using 
SSL/TLS ("port 993") with client certificates.

I'm a bit confused by your message. How do you want to authenticate your 
user? Specifically, what's the use case where you can safely verify the 
user's identity, but cannot guarantee confidentiality of the connection 
stream?

Cheers,
Jan

-- 
Trojitá, a fast Qt IMAP e-mail client -- http://trojita.flaska.net/
_______________________________________________
Imap-protocol mailing list
[email protected]
http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.