Re: Configuring SASL PLAIN auth only after STARTTLS

2014-01-31 Thread Johannes Bauer
On 31.01.2014 02:22, Viktor Dukhovni wrote: >> You're a genius! Thank you so much, this is exactly what I wanted. >> >> If we ever meet in person, be sure to claim your well-deserved beer :-) > > Instead of buying me a beer, you can pay me back in kind and take > 5-10 minutes to read Section 1.2

Re: Configuring SASL PLAIN auth only after STARTTLS

2014-01-30 Thread Viktor Dukhovni
On Fri, Jan 31, 2014 at 02:07:51AM +0100, Johannes Bauer wrote: > On 31.01.2014 01:41, Viktor Dukhovni wrote: > > On Fri, Jan 31, 2014 at 12:54:01AM +0100, Johannes Bauer wrote: > > > >> What I would like to do and cannot figure out: How can I *force* > >> authenticated clients to perform a START

Re: Configuring SASL PLAIN auth only after STARTTLS

2014-01-30 Thread Johannes Bauer
On 31.01.2014 01:41, Viktor Dukhovni wrote: > On Fri, Jan 31, 2014 at 12:54:01AM +0100, Johannes Bauer wrote: > >> What I would like to do and cannot figure out: How can I *force* >> authenticated clients to perform a STARTTLS before performing a "AUTH >> PLAIN"? > > If plaintext mechanisms are a

Re: Configuring SASL PLAIN auth only after STARTTLS

2014-01-30 Thread Viktor Dukhovni
On Fri, Jan 31, 2014 at 12:54:01AM +0100, Johannes Bauer wrote: > What I would like to do and cannot figure out: How can I *force* > authenticated clients to perform a STARTTLS before performing a "AUTH > PLAIN"? If plaintext mechanisms are all you have: smtpd_tls_auth_only = yes This disab

Configuring SASL PLAIN auth only after STARTTLS

2014-01-30 Thread Johannes Bauer
Hi list, I have a Postfix setup with Dovecot SASL. Other MTAs drop their mail at my host (without authentication obviously) and I have a couple of clients which drop their relay mail off after authentication. So, a pretty standard setup. For SASL authentication I have hashed passwords in the back