cyrusimap / cyrus-sasl

Other
133 stars 150 forks source link

OTP plugin doesn't protect against race attack #83

Closed brong closed 7 years ago

brong commented 23 years ago

From: Ken Murchison Bugzilla-Id: 1019 Version: 2.0 Owner: Ken Murchison

brong commented 23 years ago

From: Ken Murchison

The OPIE library supports locking of the user key, which protects against the race attack, but it requires root privilges to do so. This won't work with all SASL applications (ie, Cyrus IMAPD) and is a bug that needs to be resolved in OPIE.

brong commented 12 years ago

From: Alexey Melnikov

OpenSSL version was implemented that doesn't have this restriction.

Besides OTP is a very rarely used plugins.

brong commented 7 years ago

Closing: was RESOLVED in import