Networking Forums

Networking Forums > Computer Networking > Linux Networking > RFC 3501 (Use of CAPABILITY in IMAP4S session)

Reply
Thread Tools Display Modes

RFC 3501 (Use of CAPABILITY in IMAP4S session)

 
 
Scott Lowe
Guest
Posts: n/a

 
      05-14-2005, 11:59 PM
I'm experimenting with the use of Perdition as an IMAP4S proxy in front
of a proprietary messaging system. Perdition will accept the IMAP4S
connection, then send unencrypted IMAP4 to the back-end messaging
system.

I'm a bit concerned, though, that the IMAP4S connection isn't
necessarily as secure as I would like. In particular, I am concerned
about the IMAP4 client sending authentication credentials before the
TLS connection has been established. I've been reviewing RFC 3501 in
an effort to verify that the IMAP4 client first sends a CAPABILITY
command before attempting to authenticate. If so, then Perdition will
return both the STARTTLS and LOGINDISABLED responses, indicating that
the TLS connection must first be established, then authentication will
be permitted.

Anyone have a clue on this one? Packet captures thus far have been
inconclusive...although this may be due to my inexperience with tcpdump.

TIA.

--
Scott Lowe

 
Reply With Quote
 
 
 
 
Dr Balwinder S Dheeman
Guest
Posts: n/a

 
      05-15-2005, 02:14 AM
On 05/15/2005 05:29 AM, Scott Lowe wrote:
> I'm experimenting with the use of Perdition as an IMAP4S proxy in front
> of a proprietary messaging system. Perdition will accept the IMAP4S
> connection, then send unencrypted IMAP4 to the back-end messaging system.
>
> I'm a bit concerned, though, that the IMAP4S connection isn't
> necessarily as secure as I would like. In particular, I am concerned
> about the IMAP4 client sending authentication credentials before the TLS
> connection has been established. I've been reviewing RFC 3501 in an
> effort to verify that the IMAP4 client first sends a CAPABILITY command
> before attempting to authenticate. If so, then Perdition will return
> both the STARTTLS and LOGINDISABLED responses, indicating that the TLS
> connection must first be established, then authentication will be
> permitted.
>
> Anyone have a clue on this one? Packet captures thus far have been
> inconclusive...although this may be due to my inexperience with tcpdump.


I think, Ethereal may help a lot; is more intutive as compared to tcpdump.

Inspired from a Net::SMTP Client Library in standard Ruby Libs, I've
developed Net::NNTP Client Library; plz have a look at detailed docs as
well as source at ...

Home: http://nntp.rubyforge.org/
Download: http://rubyforge.org/projects/nntp/

But implementation of some of the Authentication methods is incomplete
in both of the above packages. I have searched a number of RFC's and, or
drafts, but me too am clueless till yet.

I would love to hear from you on any further progress.

Regards,
--
Dr Balwinder Singh Dheeman Registered Linux User: #229709
CLLO (Chief Linux Learning Officer) Machines: #168573, 170593, 259192
Anu's Linux@HOME Distros: Ubuntu, Fedora, Knoppix
More: http://anu.homelinux.net/~bsd/ Visit: http://counter.li.org/
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
My PC has wireless capability Barry Karas Wireless Networks 1 02-25-2006 10:54 AM
WPA Capability Mystified Wireless Networks 4 05-14-2005 03:58 AM
no network capability mysterious_114 Windows Networking 5 02-02-2004 09:23 PM
Anyone know of any products with this capability Tagaki Wireless Internet 0 12-02-2003 11:06 PM
Wireless LAN capability Colin Steadman Broadband 4 10-30-2003 07:37 AM



1 2 3 4 5 6 7 8 9 10 11