I can't reproduce..

I can somehow see another problem:
User: test.domain.de
pass: test.domain.de

# testsaslauthd -u test.domain.de -p test.domain.de
0: OK "Success."
# testsaslauthd -u test.domain.de -p test.domain.d
0: OK "Success."
# testsaslauthd -u test.domain.de -p test.domain.
0: OK "Success."
# testsaslauthd -u test.domain.de -p test
0: NO "authentication failed"
# testsaslauthd -u test.domain.de -p test.do
0: NO "authentication failed"
# testsaslauthd -u test.domain.de -p test.dom
0: OK "Success."

Seems like it is only validating the first 8 chars?

I can not authenticate with an arbitray Password and your suggested change did 
not change anything
(for me)

Jan

> Solved by changing :

> auth sufficient pam_mysql.so user=postfix passwd=postfix
> host=localhost db=mail table=accountuser usercolumn=username
> passwdcolumn=password crypt=1 logtable=log logmsgcolumn=msg
> logusercolumn=user loghostcolumn=host logpidcolumn=pid
> logtimecolumn=time

> to:

> auth required pam_mysql.so user=postfix passwd=postfix
> host=localhost db=mail table=accountuser usercolumn=username
> passwdcolumn=password crypt=1 logtable=log logmsgcolumn=msg
> logusercolumn=user loghostcolumn=host logpidcolumn=pid
> logtimecolumn=time

> I suggest that everyone should have a look at this since it appears to
> be a serious security issue.

> On 10/29/07, Marcel Hartmann <[EMAIL PROTECTED]> wrote:
>> Sorry i mean the saslauthd! Not postfix!
>>
>> Regards
>> Marcel
>>
>> _____________________________________________
>>
>> Marcel Hartmann
>>
>> Bokeler Landstraße 24a    26215 Wiefelstede - Bokel
>> Tel. 044 02 - 69 50 62      Fax 044 02 - 69 55 801
>> e-Mail:                             [EMAIL PROTECTED]
>>
>>
>> _______________________________________________
>> This mailing list is hosted and supported
>> by bit-heads GmbH | http://www.bit-heads.ch
>>
>> _______________________________________________
>> Web-cyradm mailing list
>> [email protected]
>> http://www.web-cyradm.org/mailman/listinfo/web-cyradm
>>


-- 
If you live by the sword, you'll die by the knife.

Mit freundlichen Grüßen
Jan Scholten
mailto:[EMAIL PROTECTED]




_______________________________________________
This mailing list is hosted and supported
by bit-heads GmbH | http://www.bit-heads.ch

_______________________________________________
Web-cyradm mailing list
[email protected]
http://www.web-cyradm.org/mailman/listinfo/web-cyradm

Reply via email to