gssapi considered as PLAIN?

2014-11-05 Thread Harry Schmalzbauer
Hello, as soon as I set disable_plaintext_auth = yes, AUTH=GSSAPI vanishes from capabilities. ([CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE IDLE STARTTLS AUTH=GSSAPI AUTH=PLAIN AUTH=LOGIN] vs [CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE IDLE STARTTLS

ntlm_auth seems ok, initial auth failure with dovecot2 (and winbind 4.1.13)

2014-11-05 Thread Harry Schmalzbauer
Hello, I've read quite often that there are problems with ntlm_auth helper (last one here http://www.dovecot.org/list/dovecot/2014-June/096561.html). But haven't found any confirmation, neither it's working for anybody else nor that it's known taht this issue needs debuging. Like for ohers, my

Re: gssapi considered as PLAIN?

2014-11-05 Thread Harry Schmalzbauer
Bezüglich Hans Morten Kind's Nachricht vom 05.11.2014 16:48 (localtime): On Wed, Nov 05, 2014 at 04:22:12PM +0100, Harry Schmalzbauer wrote: as soon as I set disable_plaintext_auth = yes, AUTH=GSSAPI vanishes from capabilities. Try setting login_trusted_networks to something you trust

Re: gssapi considered as PLAIN?

2014-11-05 Thread Harry Schmalzbauer
Bezüglich Jan Behrend's Nachricht vom 05.11.2014 17:01 (localtime): On Wed, 2014-11-05 at 16:52 +0100, Harry Schmalzbauer wrote: Bezüglich Hans Morten Kind's Nachricht vom 05.11.2014 16:48 (localtime): On Wed, Nov 05, 2014 at 04:22:12PM +0100, Harry Schmalzbauer wrote: as soon as I set

Re: gssapi considered as PLAIN?

2014-11-05 Thread Harry Schmalzbauer
Bezüglich Jan Behrend's Nachricht vom 05.11.2014 17:15 (localtime): On Wed, 2014-11-05 at 17:04 +0100, Harry Schmalzbauer wrote: Bezüglich Jan Behrend's Nachricht vom 05.11.2014 17:01 (localtime): On Wed, 2014-11-05 at 16:52 +0100, Harry Schmalzbauer wrote: Bezüglich Hans Morten Kind's

[solved] Re:gssapi considered as PLAIN?

2014-11-05 Thread Harry Schmalzbauer
Bezüglich Harry Schmalzbauer's Nachricht vom 05.11.2014 18:04 (localtime): … Sorry, I might have been unclear. Of course, AUTH=GSSAPI is offered if connection passes STARTTLS, along WITH PLAIN (and LOGIN), but the intention of disable_plaintext_auth is to prevent PLAIN if _no_ encryption