[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
RE: Cyrus SASL 2 is no good
> -----Original Message-----
> From: Kurt D. Zeilenga [mailto:Kurt@OpenLDAP.org]
> At 10:42 PM 2002-04-19, Howard Chu wrote:
> >I've noticed that the Cyrus 2 GSSAPI plugin tends to always send
> a non-NULL
> >authzid with its requests.
>
> Which is broken. They should not send an authzid unless the
> user is attempting proxy authorization.
Ah, thanks for pointing that out. I was using the Cyrus CVS and the last
patch I sent introduced this bug. The Cyrus library still requires authcid
and authzid to be non-empty, but usually it's handled by copying authcid to
authzid on the client and on the server. So a "default" authzid usually
doesn't get
transmitted over the wire.
-- Howard Chu
Chief Architect, Symas Corp. Director, Highland Sun
http://www.symas.com http://highlandsun.com/hyc
Symas: Premier OpenSource Development and Support