Stephan Bosch
2008-May-04 15:11 UTC
[Dovecot] New ManageSieve releases: v0.10.2 for Dovecot 1.1.rc4 and v9.3 for Dovecot 1.0.13
Hello Dovecot users, Recently, I was pointed towards a problem in the managesieve SASL implementation. As it turns out there was a bug in handling mechanisms that expect more than a single client response. That is why the PLAIN mechanism works and the (obsolete) LOGIN mechanism fails (along with probably many others). This problem was present in both v9.2 and v0.10.1 for Dovecot 1.0 and 1.1 respectively. This issue is fixed in the new releases: Change Log v9.3/v0.10.2 ------------------------ * Fixed bug that caused SASL mechanisms that require more than a single client response to fail. Reported by Steffen Kaiser and occured when he tried using the (obsolete) LOGIN mechanism. * Updated installation and configuration documentation to match the information provided in the wiki Installation ------------ The full installation procedure and other relevant information regarding ManageSieve is finally available on the Dovecot wiki at: http://wiki.dovecot.org/ManageSieve New releases: 1.0: (patch) http://www.rename-it.nl/dovecot/1.0/dovecot-1.0.13-MANAGESIEVE-v9.3.diff.gz http://www.rename-it.nl/dovecot/1.0/dovecot-1.0.13-MANAGESIEVE-v9.3.diff.gz.sig 1.1: (package + patch) http://www.rename-it.nl/dovecot/1.1/dovecot-1.1-managesieve-0.10.2.tar.gz http://www.rename-it.nl/dovecot/1.1/dovecot-1.1-managesieve-0.10.2.tar.gz.sig http://www.rename-it.nl/dovecot/1.1/dovecot-1.1.rc4-managesieve-0.10.2.diff.gz http://www.rename-it.nl/dovecot/1.1/dovecot-1.1.rc4-managesieve-0.10.2.diff.gz.sig (my public key (id: 3DFBB4F4) can be found at wwwkeys.pgp.net) Have fun testing the Dovecot ManageSieve service. Don't hesitate to notify me when there are problems. Regards, -- Stephan Bosch stephan at rename-it.nl IRC: Freenode, #dovecot, S[r]us
Steffen Kaiser
2008-May-20 14:02 UTC
[Dovecot] New ManageSieve releases: v0.10.2 for Dovecot 1.1.rc4 and v9.3 for Dovecot 1.0.13
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sun, 4 May 2008, Stephan Bosch wrote:> * Fixed bug that caused SASL mechanisms that require more than a > single client response to fail. Reported by Steffen Kaiser and > occured when he tried using the (obsolete) LOGIN mechanism.Ancient :) LOGIN is working. BTW: Is it possible to add a version string to the capability list? Bye, - -- Steffen Kaiser -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFIMtoVVJMDrex4hCIRAj8ZAJ0b1pB5U3V7keVgfwN8S3N1l1D+kQCgv7tG kgs3rHwLkusFQdPKX1lPDjQ=huv+ -----END PGP SIGNATURE-----
Seemingly Similar Threads
- font errors running Fpc v9.3 is a fingerprint database basically
- ManageSieve v0.10.1 released for Dovecot 1.1.rc1
- Upgrading libvirt and qemu to latest version
- ManageSieve SECURITY hole: virtual users can edit scripts of other virtual users (all versions)
- ManageSieve SECURITY hole: virtual users can edit scripts of other virtual users (all versions)