> The problem is the which database interface? from the firewall program to
> the authentication database of users+passwords.   Mail servers use all
> kinds of users databases, mostly proprietary, as with Imail.

Indeed. I was thinking of some abstraction layer or perhaps using different
"connectors" for a given firewall SMTP proxy to communicate with the
different flavors of MTAs.

> To avoid the proprietary aspect and to support various OS's used by
> mailservers, a firewall program could specify an "secure" LDAP server.

Why would the LDAP server need to be "secure"? In my view, it would sit
behind the firewall and thus be secure with respect to the public Internet,
n'est-ce pas?

> ie, it's really very complicated, in general, for a firewall to support
> user+passwords for SMTP AUTH.   The best approach would be via some RFC
> standard directory service like LDAP.  But IMail's case LDAP server can't
> be used securely for authentication to external LDAP clients like a
firewall.

I'll take your word for it, Len. Still, I'm baffled as to why Cisco, the
IETF, et al. can't come up with a solution to what is to me a glaring
shortcoming. How many mail servers out there today can only speak SMTP? I
gather not many. Yet, we have these modern firewall SMTP proxies insisting
on downgrading to SMTP and thus not supporting AUTH. I realize that
implementing POP-before-SMTP solves the authentication problem but I see it
as a workaround until the time comes when proxies will understand ESMTP, be
it via "SLDAP" or some other mechanism.

Thanks for your reply,

Guy




Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/

Reply via email to