OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: SASL vs. M$ Outlook and Outlook Express

From: Tom Kovar (postfix_listkovarovi.org)
Date: Mon Jan 01 2007 - 12:06:03 CST


Yeah, Magnus, very much right. But not only that: LOGIN apparently has
to be the **FIRST** method proposed by the server - if not, M$ does
neither find nor recognise it.

Tack så mycket,
        --- Tom

-----Original Message-----
From: owner-postfix-userspostfix.org
[mailto:owner-postfix-userspostfix.org] On Behalf Of Magnus Bäck
Sent: Monday, January 01, 2007 7:00 PM
To: postfix-userspostfix.org
Subject: Re: SASL vs. M$ Outlook and Outlook Express

On Monday, January 01, 2007 at 14:32 CET,
     Rene van Hoek <reneactive8.nl> wrote:

> I did an telnet to your machine and that seems ok:
>
> Leto:/Volumes renevanhoek$ telnet mail.kovarovi.org 25
> Trying 194.212.102.169...
> Connected to bimbo.kovarovi.org.
> Escape character is '^]'.
> 220 mail.kovarovi.org ESMTP Postfix
> EHLO test.a8.nl
> 250-mail.kovarovi.org
> 250-PIPELINING
> 250-SIZE 10240000
> 250-VRFY
> 250-ETRN
> 250-AUTH PLAIN
> 250-AUTH=PLAIN
> 250-ENHANCEDSTATUSCODES
> 250-8BITMIME
> 250 DSN

No, that's not okay. The Microsoft-style LOGIN mechanism is missing.
More recent Microsoft clients may support the PLAIN mechansim as well,
but since people may be running older software I'd say it's a
requirement to provide both PLAIN and LOGIN.

While the OP is fixing LOGIN, I suggest he fixes support for CRAM-MD5
and DIGEST-MD5 as well so that clients won't be forced to send passwords
in the clear.

[...]

--
Magnus Bäck
magnusdsek.lth.se