Hi,
I have been working through adding SASL GSSAPI (Kerberos) support to the
qpid-jms-client[1] and have hit a limit in proton-j

The initial response in the SASL_Init frame can be > 512 which breaks the
max frame size limitation as frame size negotiation has not completed yet.
Proton-j will allow the frame to be written but the parse at the other end
identifies the size exceeding the limit and errors out.

I see in the AMQP Claims Based Security draft there is some work to
describe how to SASL within that limitation in the context of a new
mechanism.

Is it reasonable to relax the check via config to allow the existing gssapi
mechanism to work.

Of the top of your head, what does proton-c do, maybe it never sends an
initial response in the sasl_init?

thanks in advance for any read of this :-)

gary.

[1] https://issues.apache.org/jira/browse/QPIDJMS-303

Reply via email to