Re: Fwd: Issue with Postfix and GSSAPI Authentication

2021-10-05 Thread Sam R
Ok, Thank you for these useful clarifications Samuel Le lun. 4 oct. 2021 à 17:27, Viktor Dukhovni a écrit : > On Mon, Oct 04, 2021 at 04:34:39PM +0200, Sam R wrote: > > > Now it's working fine! > > > > I finally succeeded. I worked around by increasing only the value of the > >

Re: Fwd: Issue with Postfix and GSSAPI Authentication

2021-10-04 Thread Viktor Dukhovni
On Mon, Oct 04, 2021 at 04:34:39PM +0200, Sam R wrote: > Now it's working fine! > > I finally succeeded. I worked around by increasing only the value of the > line_length_limit option to 12288 ( same value as the default for > smtpd_sasl_response_limit ) That's the right thing to do when the

Re: Fwd: Issue with Postfix and GSSAPI Authentication

2021-10-04 Thread Sam R
Now it's working fine! I finally succeeded. I worked around by increasing only the value of the line_length_limit option to 12288 ( same value as the default for smtpd_sasl_response_limit ) And create a specific keytab file containing the SPN ( /etc/postfix/smtp.keytab ) But I haven't thought

Re: Fwd: Issue with Postfix and GSSAPI Authentication

2021-10-04 Thread Sam R
Good morning Viktor, Thank you for all this information, I will do the necessary for the keytabs right away. Concerning the clients, it is Thunderbird under Windows 10, the AD server being Samba4. I will try to see why the Kerberos ticket is so long. I don't think the problem is with Thunderbird

Re: Fwd: Issue with Postfix and GSSAPI Authentication

2021-10-01 Thread Viktor Dukhovni
On Fri, Oct 01, 2021 at 12:47:29PM -0400, Viktor Dukhovni wrote: > > -- basics -- > > Postfix: 3.5.6 > > Since you're using Postfix 3.5, which by default supports long SASL > messages after the initial response, your client is in violation of the > SMTP SASL specification, and needs to have a

Re: Fwd: Issue with Postfix and GSSAPI Authentication

2021-10-01 Thread Viktor Dukhovni
On Fri, Oct 01, 2021 at 04:17:03PM +0200, Sam R wrote: > I added two keytab in /etc/krb5.keytab There's your problem, the /etc/krb5.keytab file, given services like SSH with GSSAPI authentication, contains secrets sufficient to login to the host as any user, possibly including root. It must

Re: Fwd: Issue with Postfix and GSSAPI Authentication

2021-10-01 Thread Emmanuel Fusté
Hello, Le 01/10/2021 à 16:17, Sam R a écrit : Hello, I want to set up a Postfix SMTP server with cyrus-sasl in GSSAPI mode. I have two Samba4 servers in AD mode, and my clients are in windows 10. I removed the execution of Posfix in chroot to simplify. I added two keytab in /etc/krb5.keytab

Fwd: Issue with Postfix and GSSAPI Authentication

2021-10-01 Thread Sam R
Hello, I want to set up a Postfix SMTP server with cyrus-sasl in GSSAPI mode. I have two Samba4 servers in AD mode, and my clients are in windows 10. I removed the execution of Posfix in chroot to simplify. I added two keytab in /etc/krb5.keytab smtp/smtptest.domain.fr and host/