Pop3 sasl AUTH PLAIN not supported over TLS?

Hi,
Thunberbird does not work with Mac OS X server 10.5.5 POP3 because SASL AUTH PLAIN method is not supported when TLS or SSL is used.
According to RFC5034:
"To ensure interoperability, client and server implementations of this extension MUST implement the PLAIN SASL mechanism [RFC4616] running over TLS [RFC2595]."
I have looked throught Cyrus documentation but I cannot find a find to enable AUTH PLAIN over TLS.
Any clue how to make the server RFC compliant?
Best regards,
Nicolas.

Really? Well I'd really like to dig through this. Could you post more info about your setup so that we can compare and check where the problem is on my side?
My setup: Mac OS X Server 10.5.5 running Cyrus POP3 v2.3.8-OS X Server 10.5. SSL and TLS are enabled but not required. Port 995 is only port open for outside clients.
Thunberbird version 2.0.0.18 and 3 beta 1 cannot connect to POP over SSL or TLS. The error I get is: 'authentication failure'.
Non encrypted connection works (Thunberbird will issue a USER/PASS and will not use the AUTH PLAIN method).
SASL and Kerberos are enabled on the server.
If I connect with openssl on command line to port 995, then issue a CAPA command here is the result:
CAPA
+OK List of capabilities follows
SASL GSSAPI
EXPIRE NEVER
LOGIN-DELAY 0
TOP
UIDL
PIPELINING
RESP-CODES
AUTH-RESP-CODE
USER
Could you please post the result of the same test?
('openssl> s_client -connect 10.1.1.1:995', then type 'CAPA').
Thanks to help on this,
Nicolas.

Similar Messages

  • Log onto incoming mail server (POP3): Your server does not support the connection encryption type you have specified. Try changing the encryption method. Contact your mail server administrator or Internet service provider (ISP) for additional assistance.

    Hi All,
    This is my first post to ms exchange forum am getting  Log onto incoming mail server (POP3): Your server does not support the connection encryption type you have specified. Try changing the encryption method. Contact your mail server administrator
    or Internet service provider (ISP) for additional assistance. in my outlook clients, till last Sunday (12.04.15) my exchange was well & good, Monday morning suddenly the problem started like none of our outlook pop3 clients are able to communicate
    with exchange (rest  IMAP, SMTP & Exchange accounts are working fine). i have tried with all port no but no luck. please help me to get raid of this one.
    Exchange 2013 CU6 with server 2012 Std 64Bit
    Thanks,
    Murali 

    Dear All,
    I have found the solution for above problem, the problem has occur due to PopProxy inactivity
    please find relevant exchange management shell commends below.
    1. Get-ServerComponentstate -Identity <yourmailserver.com> 
    Server Component State
    yourmailserver.com ServerWideOffline Active
    yourmailserver.com HubTransport Active
    yourmailserver.com FrontendTransport Active
    yourmailserver.com Monitoring Active
    yourmailserver.com RecoveryActionsEnabled Active
    yourmailserver.com AutoDiscoverProxy Active
    yourmailserver.com ActiveSyncProxy Active
    yourmailserver.com EcpProxy Active
    yourmailserver.com EwsProxy Active
    yourmailserver.com ImapProxy Active
    yourmailserver.com OabProxy Active
    yourmailserver.com OwaProxy Active
    yourmailserver.com PopProxy Inactive
    yourmailserver.com PushNotificationsProxy Active
    yourmailserver.com RpsProxy Active
    yourmailserver.com RwsProxy Active
    yourmailserver.com RpcProxy Active
    yourmailserver.com UMCallRouter Active
    yourmailserver.com XropProxy Active
    yourmailserver.com HttpProxyAvailabilityGroup Active
    yourmailserver.com ForwardSyncDaemon Active
    yourmailserver.com ProvisioningRps Active
    yourmailserver.com MapiProxy Active
    yourmailserver.com EdgeTransport Active
    yourmailserver.com HighAvailability Active
    yourmailserver.com SharedCache Active
    2. Set-ServerComponentState -Identity <yourmailserver.com> -Component PopProxy -Requester HealthAPI
    -State Active
    3. Get-ServerComponentstate -Identity <yourmailserver.com> 
    Server Component State
    yourmailserver.com ServerWideOffline Active
    yourmailserver.com HubTransport Active
    yourmailserver.com FrontendTransport Active
    yourmailserver.com Monitoring Active
    yourmailserver.com RecoveryActionsEnabled Active
    yourmailserver.com AutoDiscoverProxy Active
    yourmailserver.com ActiveSyncProxy Active
    yourmailserver.com EcpProxy Active
    yourmailserver.com EwsProxy Active
    yourmailserver.com ImapProxy Active
    yourmailserver.com OabProxy Active
    yourmailserver.com OwaProxy Active
    yourmailserver.com PopProxy Active
    yourmailserver.com PushNotificationsProxy Active
    yourmailserver.com RpsProxy Active
    yourmailserver.com RwsProxy Active
    yourmailserver.com RpcProxy Active
    yourmailserver.com UMCallRouter Active
    yourmailserver.com XropProxy Active
    yourmailserver.com HttpProxyAvailabilityGroup Active
    yourmailserver.com ForwardSyncDaemon Active
    yourmailserver.com ProvisioningRps Active
    yourmailserver.com MapiProxy Active
    yourmailserver.com EdgeTransport Active
    yourmailserver.com HighAvailability Active
    yourmailserver.com SharedCache Activ
    Replace yourmailserver.com with your server host name.
    Thanks

  • "Auth type not supported by External DB" error for web-auth SSIDs

    Hello
    We're having a problem with web-authentication on our 4404/WisM controllers since we moved to software rev 5.x (currently running 5.1.151.0).
    With software rev 4.x our web-auth SSIDs would send the authentication requests to a Cisco ACS4.0 which would then authenticate the users against MS Active directory.
    Now (with rev 5.x) the same SSIDs cannot authenticate users against AD, the error in the ACS is:
    Auth type not supported by External DB
    Found the following Cisco Doc regarding the problem: Cisco Secure ACS and Windows AD EAP/802.1x port authentication fails with the Auth type not supported by External DB error message - Case Number K24308566. Done a packet capture on ACS to see authentications coming in and the ones that fail with above error are using CHAP - from the Cisco documentation, MS AD doesn't support CHAP.
    Any ideas on how I can get the web-auth working again with software rev 5.x ?
    Thanks
    Andy

    my apologies - theres a setting under Controller - General for Web Radius Authentication. changed this from CHAP to PAP and its now working ok.

  • Dot1x mac-auth-byass not supported on 2950 switches

    Hi all
    I have 2950-24 and 2950SX-24 switches. I upgraded them to the Latest IOS version availlable on cisco site(12.1(22)EA11).
    We deployed the mac authentication bypass technology in our organization. The problem is the commands (dot1x mac-auth-bypass) and (dot1x critical) are not supported in this version.
    How can we solve this issue. I have many switches having this problem
    I appreciate your quick response and thanks on advance.
    Thanks

    Dear Sir
    Are you sure. why it is not supported on 2950 and it is supported on 2940 platforms?
    check the below link please. I want to know why cisco doesn't support these important features on this 2950 platform.
    http://www.cisco.com/en/US/docs/switches/lan/catalyst2950/software/release/12.1_22_ea11/release/notes/OL14991.html#wp1000099
    Thanks in advance,

  • RVS4000 remote management using SNMP not Supported over WAN

    I'm trying to mange the RVS4000 router from the WAN side. I just changed the default password and in the firewall setting:
    Block WAN Request is disabled.
    Remote Management is enabled with the default port.
    But I am not able to connect to the router remotely (using its WAN IP address). I can ping its WAN IP address fine from the remote PC. The router functions normally (i.e. PC on the LAN can connect to the Internet) but the remote management via SNMP also does not work. In most cases, the router just does not respond to the TCP SYNC or SNMP request from the WAN. Occassionally, it responds to the TCP SYNC fine but when the remote PC requests the HTTP page, it quickly responds with FIN/ACK.
    In addition, I can connect to its WAN IP address from the LAN side. But it just does not work from the WAN side.
    I tried disabling firewall, IPS, etc, nothing works.
    Message was edited by: Steve DiStefano

    Shoot, I just tried it myself.   Didnt work.   I contacted development team and they told me it wasnt speced to operate for SNMP management (port 161) over the WAN.
    Remote  Mgmt on RVS4000 is limited to WebUI access on RVS4000, and SNMP is only  accessible from LAN side.
    This  product did not have any requirement to be accessed from Internet using  SNMP.
    Very sorry I didnt know this.   Was there a datasheet or paper that indicated this was supported I can correct to prevent this frpom happening to others like us?
    You know, I was thnking that the times I used SNMP on SB Routeres was when I was VPNed into the router, then it works, since it is supported on LANB side.  is that an option for you?
    Tell us about what typs of things you view walking SNMP from the NOC and we'lls ee if there are alternative ways for you to get the same data.
    Steve
    SE Field Channel Sales
    Message was edited by: Steve DiStefano

  • How do I activate old version of Photoshop CS3 as it is not supported over the phone and website notes are not helping...? I need a human being to resolve this

    I am trying to activate an old version of Adobe Photoshop CS3 but internet activation is not working and the notes on the page online are not helping either. I need a person to assist me.

    You need to deal with Adobe for you problem this is an Adobe Photoshop User forum site not part of Adobe support users here do not have access to Adobe activation servers and database.  You need to get someone at Adobe to help.  Adobe support is not what it should be. Good luck.

  • Support for TLS 1.2 over Exchange 2013?

    How to enable TSL1.2 in Exchange 2013, any documentation leading me to configure it?
    Is there any confirmation about TSL 1.2 Supporting or not?
    Any help or insight would be greatly appreciated. Thanks!

    Hi
    Similar article, no info as yet:
    http://social.technet.microsoft.com/Forums/en-US/8815dada-94b5-4d89-ad80-43f03705c551/support-for-tls-12-over-exchange-2013-on-server-2012

  • I have a big crossbar mark over my FF4 icon after I've installed and replaced FF3. When I try to open the software, I get "You can't open the application "Firefox" because it is not supported on this architecture." What's up with that?

    I have a big crossbar mark over my FF4 icon after I've installed and replaced FF3. When I try to open the software, I get "You can't open the application "Firefox" because it is not supported on this architecture." What's up with that?

    Firefox 4 requires at least OS X 10.5 and an Intel Mac. There is a third party version of Firefox 4 that runs on OS X 10.4/10.5 and PPC Macs, for details see http://www.floodgap.com/software/tenfourfox
    If you prefer, you can get the latest version of Firefox 3.6 from http://www.mozilla.com/en-US/firefox/all-older.html

  • Technical Details: The website does not support encryption for the page you are viewing. Information sent over the internet withour encryption can be seen by other people while it is in transit

    Technical Details:
    The website does not support encryption for the page you are viewing.
    Information sent over the internet withour encryption can be seen by other people while it is in transit
    == This happened ==
    Not sure how often
    == started few days ago. previously never happened before.

    I was loading a website, it then stated as below, it wasnt any of the problems stated below.
    SERVER NOT FOUND
    # Check the address for typing errors such as
    ww.example.com instead of
    www.example.com
    # If you are unable to load any pages, check your computer's network
    connection.
    # If your computer or network is protected by a firewall or proxy, make sure
    that Firefox is permitted to access the Web.
    Thus i checked the Page Info, it states that:
    Security Info on page:
    '''This website does not supply ownership information.
    Connection not Encrypted.'''
    Technical Details:
    The website does not support encryption for the page you are viewing.
    Information sent over the internet withour encryption can be seen by other people while it is in transit

  • Server does not support PLAIN or LOGIN authentication

    I try to send mail via XI Mail adapter. My settings are below
    Transport protocol : SMTP
    Message protocol : XIPAYLOAD
    url : smtp://10.44...
    Authentication Method : Plain
    User : ...
    Password...
    From :
    To : ....
    But i give this error   "server does not support PLAIN or LOGIN authentication"..
    I think I use SSL or something else, but I dont know how to do by using Mail adapter..
    Or Why do i get this error ?
    Thanks

    Hello Tuncer,
    In your case, you need to first enable SSL on your PI server, which requires some effort. Here are the links for SSL configuration for AS ABAP and AS Java:
    http://help.sap.com/saphelp_nw70/helpdata/en/0d/a22640632cec01e10000000a155106/content.htm
    http://help.sap.com/saphelp_nw70/helpdata/en/56/a12640632cec01e10000000a155106/content.htm
    After that, you need to exchange client certificates between your PI and mail server so that the two systems will accept each other's logon tickets. Only after that you can use your mail adapter with SSL. All adapters that run on the adapter engine use Java AS's authentication mechanisms, so SSL should be enabled for your AS Java, you cannot enable it only for the mail adapter.
    I recommend trying this scenario with another mail server that doesn't require SSL first with plain authentication. Then you can go for SSL, but you will probably need an experienced basis guy to help you for the configuration.
    Hope this helps,
    Regards / selamlar
    Gökhan

  • Support for TLS 1.2 over Exchange 2013 on Server 2012?

    Greetings,
    We're trying to roll out TLS 1.2 in our test environment and can't seem to get Exchange to work with the protocol.
    We've been using this method to enable TLS 1.2 (and disable the other protocols - TLS1.0, SSL2.0, SSL3.0, PCT1.0): http://www.adminhorror.com/2011/10/enable-tls-11-and-tls-12-on-windows_1853.html
    We originally tried using Exchange 2010 on 2008 R2, but then I ran across this article saying that it is not supported: http://support.microsoft.com/kb/2709167/en-us
    We've since tried to set it up with Exchange 2013 on Server 2012. Still no luck. The only time Exchange wants to work is when TLS1.0 is enabled.
    I suspect that TLS1.1 and TLS 1.2 are also not supported on Exchange 2013, or that I'm changing the wrong registry keys, but I wanted to find confirmation. I've searched extensively and can't find any documentation leading me to believe one way or the other
    if it's supported.
    Any help or insight would be greatly appreciated. Thanks!
    --Aric

    hi All,
    Even i have tried enabling TLS 1.2 on Exchange 2013 from registry. i followed the below article.
    http://jackstromberg.com/2013/09/enabling-tls-1-2-on-iis-7-5-for-256-bit-cipher-strength/
    When i check OWA in chrome and check the connection information it says "The connection uses TLS 1.2.
    However when i run the below command to check for TLS 1.2 i get the following O/P.
    Command: java -jar TestSSLServer.jar ns-ex13.gtestexchange.com 443
    O/P:
    Supported versions: SSLv3 TLSv1.0 TLSv1.1
    Deflate compression: no
    Supported cipher suites (ORDER IS NOT SIGNIFICANT):
      SSLv3
         RSA_WITH_RC4_128_MD5
         RSA_WITH_RC4_128_SHA
         RSA_WITH_3DES_EDE_CBC_SHA
      TLSv1.0
         RSA_WITH_RC4_128_MD5
         RSA_WITH_RC4_128_SHA
         RSA_WITH_3DES_EDE_CBC_SHA
         RSA_WITH_AES_128_CBC_SHA
         RSA_WITH_AES_256_CBC_SHA
         TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
         TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
      (TLSv1.1: idem)
    Server certificate(s):
      1979e6bdbd9b8e197d00c45534959eaba82b6f40: CN=ex10.gtestexchange.com, OU=Domain
     Control Validated
    Minimal encryption strength:     strong encryption (96-bit or more)
    Achievable encryption strength:  strong encryption (96-bit or more)
    BEAST status: vulnerable
    CRIME status: protected
    ===================================================
    It doesnt says anything about TLS 1.2.
    Any suggestions from your side?

  • My ipad mini and iphone 4s are not connecting over bluetooth. iphone cannot locate ipad mini or says it is not supported. It used to work perfectly but now its not working. please help.

    my ipad mini and iphone 4s are not connecting over bluetooth. iphone cannot locate ipad mini or says it is not supported. It used to work perfectly but now its not working. please help.

    Hi
    Thanks for the support but I had already tried this . Again did it as you advised. Still not able to connect the ipad mini with Bluetooth.
    Could it be that some app is causing issue. I can connect my car and computer over Bluetooth but not ipad mini.
    On the other had ipad is connecting to other iPhone but only not mine.
    Still showing ipad not supported message. And also shows not paired.
    Please help.

  • Does Dreamweaver CS3  support implicit ftp over TLS?

    Does Dreamweaver CS3  support implicit ftp over TLS? I cannot find this option.

    Ask in the Dreamweaver forum. This forum is for suite specific issues only.

  • Pandora message "Pandora believes your browser does not support modern SSL/TLS" and everything seems disabled on the site-how fix?

    I have been using Firefox for a long time as my browser and typically play Pandora while at my office most days. For the first time today I received a pop up message "Pandora believes your browser does not support modern SSL/TLS. Consider upgrading your browswer" when I logged on to Pandora. I checked and I am on the latest version of Mozilla Firefox. I am unable to control volume or log out of Pandora now. I did some google searches and found Mozilla disabled ssl3.0 due to a "Poodle" attack. Does that mean that I can no longer use Firefox as my browser when I want to listen to music on Pandora or is there "a fix"? Thanks!

    Mozilla Firefox as of Firefox 34 has the vulnerable SSL 3.0 disabled and only allows for TLS 1.0 at minimum to 1.2 now.
    https://blog.mozilla.org/security/2014/10/14/the-poodle-attack-and-the-end-of-ssl-3-0/
    So Pandora is incorrect if they believe Firefox is not safe to use.
    Actually Pandora potentially needs to do a bit of upgrading themselves.
    https://www.ssllabs.com/ssltest/analyze.html?d=www.pandora.com&s=208.85.40.50

  • After updating I can not get over 1000 songs from my library to play.  I spent 2 hours with Apple support and he could not fix it.  Anybody got any ideas?

    After updating I can not get over 1000 songs from my library to play.  I spent 2 hours with Apple support and he could not fix it.  Anybody got any ideas?

    While not exactly the same, I wonder if this would help?  http://support.apple.com/kb/TS1967

Maybe you are looking for

  • How can I prevent sites displaying in bold font in versions of FF later than 3.6?

    Many sites (google, gmail, wikipedia to name a few) are appearing in bold font when they should not be. This started for me in FF4, and has persisted in FF5 and now FF6. I'm running Windows 7 x64. I've seen many replies to questions about bold font p

  • Converting 32bit binary to float

    hi again, is there a simple method for converting a string representation of a 32-bit binary value into its corresponding floating point value? e.g. string s = "01000001110011100001010001111011" thanks in advance

  • CR Drilldown Error by IE, but not by Firefox

    I designed a CR report with 3-levels drill down (by hyperlinking a new report rather than subreport) and published it to BOE.  I open the report by IE and drill down the new reports in a new window,  the report content in the original window disappea

  • Problem starting with jwsdp2.0 to build a web service

    i am using application server 9 and jwsdp2.0 to start building web services but i am finding difficuilties to start. i read the documentation but could not deploy the example web services. Is there any tutorial so that i can write a simple web servic

  • SOAP Parameters: Ugly name, can that be changed for something more friendly

    Hi, Everyone, I follow examples here: http://www.oracle-base.com/articles/11g/NativeOracleXmlDbWebServices_11gR1.php ( ours is 11GR2 but the differences are almost none) and created a test procedure and it automatically pubishes it as a SOAP service,