[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Proprietary or non-standard SMTP AUTH mechanisms
- To: "ietf-smtp@xxxxxxx" <ietf-smtp@xxxxxxx>
- Subject: Re: Proprietary or non-standard SMTP AUTH mechanisms
- From: Hector Santos <hsantos@xxxxxxxxxxxxxx>
- Date: Thu, 12 Jan 2012 22:30:50 -0500
- Dkim-signature: v=1; d=santronics.com; s=tms1; a=rsa-sha1; c=simple/relaxed; t=1326425448; h=Received:Received:Message-ID: Date:From:Organization:To:Subject:List-ID; bh=AgXt/dyr4gmh8iLLQ0 exQwPgpjQ=; b=xwF8Rj8y2Z6M3f30iiGol3ZzRIN3TVDmyaLvuiC6D2YtRU6ocn Vma/D+5hghWm+K1JoVafG5RfSejnV/+IVl/Rzgc0oZCGdyl2ntEvbDXN/PX8nyh6 QnGx40KCXbH0j7uEd+nK6caOULiPY1pIwM5ur5YciM0NKJhgncuOHD9fs=
- In-reply-to: <>
- List-archive: <http://www.imc.org/ietf-smtp/mail-archive/>
- List-id: <ietf-smtp.imc.org>
- List-unsubscribe: <mailto:ietf-smtp-request@imc.org?body=unsubscribe>
- Organization: Santronics Software, Inc.
- References: <> <> <>
- Sender: owner-ietf-smtp@xxxxxxxxxxxx
- User-agent: Thunderbird 2.0.0.24 (Windows/20100228)
Murray S. Kucherawy wrote:
Do they deviate from the SMTP AUTH framework in any way, other than
maybe the method name?
No deviation other than a private method name, proprietary, but
standard implementation of SMTP AUTH. Just a private/unique method
100% designed for proprietary client entry only.
That's really what I'm after. If you do your own thing with its own
name but still stick to the general base64 and "334" and such, then
it's still compliant as far as the context about which I'm asking.
I see your point.
We consider it a trade secret and part of our corporate and legal
security policy not divulge details, but frankly nothing special other
than leveraging a standard protocol method including the client/server
base64 SASL challenge/response handshaking and the expected SMTP AUTH
reply codes that by design offers the flexibility to offer new
methods, including non-standard ones.
While off hand at the moment I can't recall any specific method by
name, I would swear there are quite a few of others private methods by
just seeing some obscure/unknown AUTH names exposed in logs. But I
don't known if they were ever proposed I-D or not.
--
Sincerely
Hector Santos
http://www.santronics.com
jabber: hector@xxxxxxxxxxxxxxx