Scientific Operations Bellum Gratia Artis

testing - 1997 - January - this message

[ previous , next ]

Subject: Re: (none)

From: Brandon Black <photon@[REDACTED]>
Date: Wed, 29 Jan 1997 18:24:19 -0600 (CST)


A pop3 mail server should be trivial to implement in C on plan 9, with the
exception of one point: Authentication. Most pop3 implementations use
"USER" and "PASS" to authenticate themselves by transmitting cleartext
passwords across the network. Obviously, cleartext passwords will not do
for plan 9 (well, you could do it, buy why???).

According to RFC's 1734 and 1731 (POP AUTHentication command and IMAP
Authentication methods, respectively), there is an "AUTH" command in POP3
which can be used to implement more secure authentication methods. The
methods listed in 1731 include kerberos, GSSAPI, and S/Key.

It would be possible to make an "AUTH SecureNet" POP3 AUTH method, but the
clients would have to be modified to know to send this authentication
type... Also, I'm not sure if any widely used pop clients implement the
AUTH SKEY protocol, but if they do, you could use that... simply have the
plan 9 pop3 server transmit the SecureNet challenge in place of the SKey
sequence number, and the user reponds with his securenet answer instead of
the skey answer. If there was a client out there that support skey
authentication, and prompted the user with the sequence number... that
could conceivably work.....

brandon

On Wed, 29 Jan 1997, Kai Radicke wrote:

> Tom if you ever find one (a POP server) can you please notify me?
>
> Thanks,
>
> Kai M. Radicke -- mowogmg@dynanet.com
> http://www.dynanet.com/~mowogmg
>
> Webmaster -- webking@bigfoot.com
> Phat Enterprises -- http://www.dynanet.com/~mowogmg/phat/default.htm
>
>
>
> ----------
> > From: tab@cisco.COM
> > Newsgroups: comp.os.plan9
> > Subject: (none)
> > Date: Thursday, January 23, 1997 9:16 AM
> >
> > I'm looking for a POP server for plan9. Any clues?
> >
> > Tom Bohannon
> > Cisco Systems
> > tab@cisco.com
> >
>


................................. ..............
: Brandon Lee Black : [Office] :.............: [Personal] :....
:....................: brandon.black@wcom.com : photon@nol.net :.......
: "Sanity is the : +1.281.362.6466 .......: photon@gnu.ai.mit.edu :
: trademark of a :.................:..../\: vis_blb@unx1.shsu.edu :
: weak mind. . ." : LDDS WorldCom, Inc. :\/: +1.281.397.3490 ......:
:....................:.....................:..:.................: