HELP! Auth bug in tin 2.4 ?
Alec Muffett <[email protected]> Wed, 21 Sep 2016 14:33:22 +0100
| Newsgroups | gmane.network.tin.user |
|---|---|
| Message-ID | <CAFWeb9Lv-Rtd2uv5gfYnb3y21yvM=Fqf-QaUxZyTxgSex=N+Jg@mail.gmail.com> |
--===============5545830378529607680==
Content-Type: multipart/alternative; boundary=bcaec54fbb4838fceb053d0499a3
--bcaec54fbb4838fceb053d0499a3
Content-Type: text/plain; charset=UTF-8
Hi! I am experimenting with USENET again - after a 20 year gap - and have
both built tin 2.4.0 and also used the version from brew.sh / Homebrew on
OSX.
I have a INN server with the capabilities below*, and something about them
seems to trigger Tin into believing that the server needs/wants the user to
authenticate; entering a blank username and password causes Tin to
disconnect and quit.
I can guarantee that authentication is not needed - I run the server - and
that slrn, gnus, nn, seamonkey all work fine.
Presumably something about the capabilities is triggering the
authentication code.
I ran dtruss on the execution of tin to establish how far in the connection
process it gets, which I have recreated below.
Is there a way to convince Tin that auth is not required?
I skimmed auth.c and found the following comment:
* At this point, either authentication with username/password pair
from
* .newsauth has failed or there's no .newsauth file respectively no
* matching username/password for the current server. If we are not
at
* startup we ask the user to enter such a pair by hand. Don't ask
him
* at startup except if requested by -A option because if he
doesn't need
* to authenticate (we don't know), the "Server expects
authentication"
* messages are annoying (and even wrong).
* UNSURE: Maybe we want to make this decision configurable in the
* options menu, too, so that the user doesn't need -A.
* TODO: Put questions into do_authinfo_user() because it is
possible
* that the server doesn't want a password; so only ask for it if
needed.
...but I can't establish the current / expected behaviour from the code.
Thanks!
- alec
--
*for reference
200 usenet InterNetNews server INN 2.6.0 ready (transit mode)
CAPABILITIES
101 Capability list:
VERSION 2
IMPLEMENTATION INN 2.6.0
AUTHINFO USER
MODE-READER
.
MODE READER
200 usenet InterNetNews NNRP server INN 2.6.0 ready (posting ok)
CAPABILITIES
101 Capability list:
VERSION 2
IMPLEMENTATION INN 2.6.0
AUTHINFO SASL
HDR
LIST ACTIVE ACTIVE.TIMES COUNTS DISTRIB.PATS DISTRIBUTIONS HEADERS
MODERATORS MOTD NEWSGROUPS OVERVIEW.FMT SUBSCRIPTIONS
OVER
POST
READER
SASL DIGEST-MD5 NTLM CRAM-MD5
STARTTLS
.
--
http://dropsafe.crypticide.com/aboutalecm
--bcaec54fbb4838fceb053d0499a3
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr">Hi! I am experimenting with USENET again - after a 20 year=
gap - and have both built tin 2.4.0 and also used the version from brew.sh=
/ Homebrew on OSX.<div><br></div><div>I have a INN server with the capabil=
ities below*, and something about them seems to trigger Tin into believing =
that the server needs/wants the user to authenticate; entering a blank user=
name and password causes Tin to disconnect and quit.</div><div><br></div><d=
iv>I can guarantee that authentication is not needed - I run the server - a=
nd that slrn, gnus, nn, seamonkey all work fine.</div><div><br></div><div>P=
resumably something about the capabilities is triggering the authentication=
code.</div><div><br></div><div>I ran dtruss on the execution of tin to est=
ablish how far in the connection process it gets, which I have recreated be=
low.</div><div><br clear=3D"all"><div>Is there a way to convince Tin that a=
uth is not required?</div><div><br></div><div>I skimmed auth.c and found th=
e following comment:</div><div><br></div><div><div>=C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0* At this point, either authentication with username/password pai=
r from</div><div>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0* .newsauth has failed o=
r there's no .newsauth file respectively no</div><div>=C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0* matching username/password for the current server. If we=
are not at</div><div>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0* startup we ask th=
e user to enter such a pair by hand. Don't ask him</div><div>=C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0* at startup except if requested by -A option becau=
se if he doesn't need</div><div>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0* to =
authenticate (we don't know), the "Server expects authentication&q=
uot;</div><div>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0* messages are annoying (a=
nd even wrong).</div><div>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0* UNSURE: Maybe=
we want to make this decision configurable in the</div><div>=C2=A0 =C2=A0 =
=C2=A0 =C2=A0 =C2=A0* options menu, too, so that the user doesn't need =
-A.</div><div>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0* TODO: Put questions into =
do_authinfo_user() because it is possible</div><div>=C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0* that the server doesn't want a password; so only ask for=
it if needed.</div></div><div><br></div><div>...but I can't establish =
the current / expected behaviour from the code.</div><div><br></div><div>Th=
anks!</div><div><br></div><div>=C2=A0 =C2=A0 - alec</div><div><br></div><di=
v><br></div><div><br></div><div>--</div><div>*for reference</div><div><br><=
/div><div><div>200 usenet InterNetNews server INN 2.6.0 ready (transit mode=
)</div><div>CAPABILITIES</div><div>101 Capability list:</div><div>VERSION 2=
</div><div>IMPLEMENTATION INN 2.6.0</div><div>AUTHINFO USER</div><div>MODE-=
READER</div><div>.</div><div>MODE READER</div><div>200=C2=A0usenet=C2=A0Int=
erNetNews NNRP server INN 2.6.0 ready (posting ok)</div><div>CAPABILITIES</=
div><div>101 Capability list:</div><div>VERSION 2</div><div>IMPLEMENTATION =
INN 2.6.0</div><div>AUTHINFO SASL</div><div>HDR</div><div>LIST ACTIVE ACTIV=
E.TIMES COUNTS DISTRIB.PATS DISTRIBUTIONS HEADERS MODERATORS MOTD NEWSGROUP=
S OVERVIEW.FMT SUBSCRIPTIONS</div><div>OVER</div><div>POST</div><div>READER=
</div><div>SASL DIGEST-MD5 NTLM CRAM-MD5</div><div>STARTTLS</div><div>.</di=
v></div><div><br></div><div><br></div><div><br></div>-- <br><div class=3D"g=
mail_signature"><a href=3D"http://dropsafe.crypticide.com/aboutalecm" targe=
t=3D"_blank">http://dropsafe.crypticide.com/aboutalecm</a><br></div>
</div></div>
--bcaec54fbb4838fceb053d0499a3--
--===============5545830378529607680==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KdGluLXVzZXJz
IG1haWxpbmcgbGlzdAp0aW4tdXNlcnNAdGluLm9yZwpodHRwOi8vbGlzdHMudGluLm9yZy9jZ2kt
YmluL21haWxtYW4vbGlzdGluZm8vdGluLXVzZXJzCg==
--===============5545830378529607680==--