Larry Osterman wrote: > When I worked on the IMAP server (Ex 5.5), assuming that the NT guys did > the right thing with there Kerberos SSPI provider, it was a DS config > change to add support. I don't know what happened with E2K, since the > authentication logic was moved from the store to IIS. > > Your best bet w.r.t Kerberos is actually spnego, which is a superset of > Kerberos (and there IS an RFC for SPNEGO out there (although nobody > bothered to write the SASL profile for POP and IMAP for it :()
There are generic SASL profiles for IMAP (RFC 2060) and POP (RFC 1734). How to implement GSSAPI SPENEGO is documented in draft-ietf-cat-sasl-gssapi-05.txt. All interested parties should read this document, as it will be Last Called soon. Alexey Melnikov __________________________________________ R & D, ACI Worldwide/MessagingDirect Richmond, Surrey, UK Phone: +44 20 8332 4508 I speak for myself only, not for my employer. __________________________________________
