Re: [Imap-protocol] STARTTLS after PREAUTH
Michael M Slusarz <[email protected]>
| Newsgroups | gmane.mail.imap.general |
|---|---|
| Message-ID | <20140319132159.Horde.CpARW7j5F6OgSt8te3iCaA1@bigworm.curecanti.org> |
Quoting Arnt Gulbrandsen <[email protected]>: > On Wednesday, March 19, 2014 12:56:08 PM CEST, Jan Kundrát wrote: >> Oops. Thanks for an excellent suggestion, Arnt. It turns out that >> Trojita silenty fails to establish encryption when the remote >> server greets us with an initial PREAUTH. > > PREAUTH is a trouble magnet, IMNSHO. The protocol would have been > better off without it. Agreed. And (unlikely scenario, but...) what can you do if you want to auth as another user? You will never get the chance. Also the fact you don't even know what user you are preauth'd as. Wondering if it makes sense for our library to reject PREAUTH by default due to some of these issues. michael _______________________________________________ Imap-protocol mailing list [email protected] http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol