Nelson Tang wrote: > It's legit. The specification of the PLAIN SASL mechanism says: This is legit for ANY SASL mechanism that has an authorization identity field. From Section 3 of RFC 2222: With any mechanism, transmitting an authorization identity of the empty string directs the server to derive an authorization identity from the client's authentication credentials.