On Wed, 10 Apr 2002, Igor Brezac wrote:

> Auxprop has to return a clear text password unless you make neccessary
> changes to lib/checkpw.c.

I don't agree, auxprop_verify_password() will take either a userPassword
(plaintext) or a cmusaslsecretPLAIN.

> It would be nicer if auxprop would simply take
> OK/NO type answer.

No, this defeats the the purpose of auxprop plugins, which is to return
user properties.  If you can only return a yes/no type answer, then you
have to use saslauthd and mechanisms that give you the plaintext password
(or an decryptable version of the plaintext password).

-Rob

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Rob Siemborski * Andrew Systems Group * Cyert Hall 235 * 412-268-7456
Research Systems Programmer * /usr/contributed Gatekeeper


Reply via email to