Bug#448499: cyrus-clients-2.3: imtest fails with Dovecot/GSSAPI: invalid response length

Ricardo Ramirez rram at mit.edu
Thu May 15 05:15:35 UTC 2008


Package: cyrus-clients-2.3
Version: 2.2
Followup-For: Bug #448499

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

I can confirm this bug also exists in cyrus-clients-2.2 (current stable).
Running imtest with -a also fails. Both client and server are running Debian etch.

client:
[rram at vinegar-pot ~]$ imtest -s -m GSSAPI the-tech.mit.eduverify
error:num=20:unable to get local issuer certificate
verify error:num=27:certificate not trusted
verify error:num=21:unable to verify the first certificate
TLS connection established: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)
S: * OK [CAPABILITY IMAP4rev1 SASL-IR SORT THREAD=REFERENCES MULTIAPPEND
UNSELECT LITERAL+ IDLE CHILDREN NAMESPACE LOGIN-REFERRALS AUTH=PLAIN
AUTH=GSSAPI] Dovecot ready.
C: C01 CAPABILITY
S: * CAPABILITY IMAP4rev1 SASL-IR SORT THREAD=REFERENCES MULTIAPPEND UNSELECT
LITERAL+ IDLE CHILDREN NAMESPACE LOGIN-REFERRALS AUTH=PLAIN AUTH=GSSAPI
S: C01 OK Capability completed.
C: A01 AUTHENTICATE GSSAPI [data redacted]
S: + [data redacted]
C: 
S: + [data redacted]
C: [data redacted]
S: A01 NO Authentication failed.
Authentication failed. generic failure
Security strength factor: 256
C: Q01 LOGOUT
Connection closed.
[rram at vinegar-pot ~]$ imtest -s -m GSSAPI -a rram the-tech.mit.edu
verify error:num=20:unable to get local issuer certificate
verify error:num=27:certificate not trusted
verify error:num=21:unable to verify the first certificate
TLS connection established: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)
S: * OK [CAPABILITY IMAP4rev1 SASL-IR SORT THREAD=REFERENCES MULTIAPPEND
UNSELECT LITERAL+ IDLE CHILDREN NAMESPACE LOGIN-REFERRALS AUTH=PLAIN
AUTH=GSSAPI] Dovecot ready.
C: C01 CAPABILITY
S: * CAPABILITY IMAP4rev1 SASL-IR SORT THREAD=REFERENCES MULTIAPPEND UNSELECT
LITERAL+ IDLE CHILDREN NAMESPACE LOGIN-REFERRALS AUTH=PLAIN AUTH=GSSAPI
S: C01 OK Capability completed.
C: A01 AUTHENTICATE GSSAPI [data redacted]
S: + [data redacted]
C: 
S: + [data redacted]
C: [data redacted]
S: A01 NO Authentication failed.
Authentication failed. generic failure
Security strength factor: 256
C: Q01 LOGOUT
Connection closed.
[rram at vinegar-pot ~]$ imtest -s -m GSSAPI -u rram the-tech.mit.edu
verify error:num=20:unable to get local issuer certificate
verify error:num=27:certificate not trusted
verify error:num=21:unable to verify the first certificate
TLS connection established: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)
S: * OK [CAPABILITY IMAP4rev1 SASL-IR SORT THREAD=REFERENCES MULTIAPPEND
UNSELECT LITERAL+ IDLE CHILDREN NAMESPACE LOGIN-REFERRALS AUTH=PLAIN
AUTH=GSSAPI] Dovecot ready.
C: C01 CAPABILITY
S: * CAPABILITY IMAP4rev1 SASL-IR SORT THREAD=REFERENCES MULTIAPPEND UNSELECT
LITERAL+ IDLE CHILDREN NAMESPACE LOGIN-REFERRALS AUTH=PLAIN AUTH=GSSAPI
S: C01 OK Capability completed.
C: A01 AUTHENTICATE GSSAPI [data redacted]
S: + [data redacted]
C: 
S: + [data redacted]
C: [data redacted]
S: A01 OK Logged in.
Authenticated.
Security strength factor: 256
C: Q01 LOGOUT
Connection closed.

server:
May 15 01:04:22 the-tech dovecot: auth(default): gssapi(?,18.181.0.51): Invalid
response length
May 15 01:04:27 the-tech dovecot: imap-login: Aborted login: method=GSSAPI,
rip=18.181.0.51, lip=18.187.1.155, TLS
May 15 01:04:34 the-tech dovecot: auth(default): gssapi(?,18.181.0.51): Invalid
response length
May 15 01:04:36 the-tech dovecot: imap-login: Aborted login: method=GSSAPI,
rip=18.181.0.51, lip=18.187.1.155, TLS
May 15 01:04:41 the-tech dovecot: imap-login: Login: user=<rram>, method=GSSAPI,
rip=18.181.0.51, lip=18.187.1.155, TLS
May 15 01:04:43 the-tech dovecot: IMAP(rram): Disconnected: Logged out

- -- System Information:
Debian Release: 4.0
  APT prefers stable
  APT policy: (990, 'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.18-6-686
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFIK8b3HvL19f6xTLsRAlKvAJ9m62D2M9YPp2zMUYhjdcGrdkNbyQCeMHYh
5Ncnj+AxJSMvarSesak5NeY=
=yXJa
-----END PGP SIGNATURE-----





More information about the Pkg-Cyrus-imapd-Debian-devel mailing list