> The problem is the which database interface? from the firewall program to > the authentication database of users+passwords. Mail servers use all > kinds of users databases, mostly proprietary, as with Imail.
Indeed. I was thinking of some abstraction layer or perhaps using different "connectors" for a given firewall SMTP proxy to communicate with the different flavors of MTAs. > To avoid the proprietary aspect and to support various OS's used by > mailservers, a firewall program could specify an "secure" LDAP server. Why would the LDAP server need to be "secure"? In my view, it would sit behind the firewall and thus be secure with respect to the public Internet, n'est-ce pas? > ie, it's really very complicated, in general, for a firewall to support > user+passwords for SMTP AUTH. The best approach would be via some RFC > standard directory service like LDAP. But IMail's case LDAP server can't > be used securely for authentication to external LDAP clients like a firewall. I'll take your word for it, Len. Still, I'm baffled as to why Cisco, the IETF, et al. can't come up with a solution to what is to me a glaring shortcoming. How many mail servers out there today can only speak SMTP? I gather not many. Yet, we have these modern firewall SMTP proxies insisting on downgrading to SMTP and thus not supporting AUTH. I realize that implementing POP-before-SMTP solves the authentication problem but I see it as a workaround until the time comes when proxies will understand ESMTP, be it via "SLDAP" or some other mechanism. Thanks for your reply, Guy Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/
