Hi, I have been working through adding SASL GSSAPI (Kerberos) support to the qpid-jms-client[1] and have hit a limit in proton-j
The initial response in the SASL_Init frame can be > 512 which breaks the max frame size limitation as frame size negotiation has not completed yet. Proton-j will allow the frame to be written but the parse at the other end identifies the size exceeding the limit and errors out. I see in the AMQP Claims Based Security draft there is some work to describe how to SASL within that limitation in the context of a new mechanism. Is it reasonable to relax the check via config to allow the existing gssapi mechanism to work. Of the top of your head, what does proton-c do, maybe it never sends an initial response in the sasl_init? thanks in advance for any read of this :-) gary. [1] https://issues.apache.org/jira/browse/QPIDJMS-303
