Re: [Imap-protocol] STARTTLS after PREAUTH

Jan Kundrát <[email protected]>
Newsgroups gmane.mail.imap.general
Message-ID <[email protected]>
On Tuesday, 18 March 2014 22:25:49 CEST, Michael M Slusarz wrote:
> Except as defined in base spec, STARTTLS is defined as "you are 
> allowed to protect privacy ONLY if you protect authentication".  
> In the absence of a need to protect authentication, you can't 
> protect privacy.

That's right. To my understanding, providing just these two options:

a) don't protect anything,
b) protect everything,

is much simpler than doing this in a more fine-grained manner, and the cost 
of forcing STARTTLS to happen earlier is negligible. But perhaps I'm 
missing something?

>> That's what you could get with AUTH EXTERNAL.
>
> Not a part of the base IMAP spec, which is what I was talking about.

The way I see it, IMAP delegates all means of authentication and 
authorization except the basic LOGIN (which is probably specified mainly 
for backward compatibility) to SASL, doesn't it? But you're of course right 
that it is not a mandatory part of the spec.

Besides, there's a reference to the EXTERNAL and an example of how to use 
it with STARTTLS right in the official IMAP RFC [1].

> Simple real-world example would be a machine on an internal 
> network that is guaranteed to belong to a certain user.

While I can imagine a scenario where an attacker can listen, but cannot 
spoof, I think that would be quite an artificial setup to be honest.

With kind regards,
Jan

[1] http://tools.ietf.org/html/rfc3501#section-6.2.1

-- 
Trojitá, a fast Qt IMAP e-mail client -- http://trojita.flaska.net/
_______________________________________________
Imap-protocol mailing list
[email protected]
http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.