[From nobody Wed Sep  9 15:13:06 2026
Received: (at submit) by bugs.debian.org; 23 Jan 2021 22:23:43 +0000
X-Spam-Checker-Version: SpamAssassin 3.4.2-bugs.debian.org_2005_01_02
 (2018-09-13) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-20.3 required=4.0 tests=BAYES_00,DIGITS_LETTERS,
 DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,
 FVGT_m_MULTI_ODD,HAS_PACKAGE,MURPHY_DRUGS_REL8,PGPSIGNATURE,
 SPF_HELO_PASS,SPF_PASS,TXREP autolearn=ham autolearn_force=no
 version=3.4.2-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 130; hammy, 150; neutral, 146; spammy,
 0. spammytokens: hammytokens:0.000-+--H*ct:pgp-sha256,
 0.000-+--H*u:Gnus, 0.000-+--H*u:linux, 0.000-+--H*UA:linux,
 0.000-+--H*u:gnu
Return-path: &lt;simon@josefsson.org&gt;
Received: from uggla.sjd.se ([2001:9b1:8633::107]:50396)
 by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.92) (envelope-from &lt;simon@josefsson.org&gt;) id 1l3RJn-00017N-0u
 for submit@bugs.debian.org; Sat, 23 Jan 2021 22:23:43 +0000
DKIM-Signature: v=1; a=ed25519-sha256; q=dns/txt; c=relaxed/relaxed;
 d=josefsson.org; s=ed2101; h=Content-Type:MIME-Version:Message-ID:Date:
 Subject:To:From:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:
 Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
 :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:
 List-Subscribe:List-Post:List-Owner:List-Archive;
 bh=M6x7mmYI0JErC98mwjmeNTkqm3pmUKtkRHBxNDtkQbg=; t=1611440622; x=1612650222;
 b=W6FMqsHJGlrL0EWt/mI44mXyyKiFTl1LY9qK3qyv0zZztIBPSSKM4ZJPk9l0Iu4ScET4Z80mqS
 Olhjrt+nEFDw==;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=josefsson.org; s=rsa2101; h=Content-Type:MIME-Version:Message-ID:Date:
 Subject:To:From:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:
 Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
 :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:
 List-Subscribe:List-Post:List-Owner:List-Archive;
 bh=M6x7mmYI0JErC98mwjmeNTkqm3pmUKtkRHBxNDtkQbg=; t=1611440622; x=1612650222;
 b=SN4uXAKM5mkaC1RHNtd9QVndlylF2AzvPRpgkEmkbExZgwCXeOF1jLVdv1j2Gkn6g/gu2ZSa1e
 KckVoIOnbTOnneNgnncGv6H3JEU89vBMss8gotGd07sIDfX02vD6JBCVlHg+RLk32H3RSaC3w46ph
 WUFSabeJFNraUOeeSugRmNTJwsl9IHzmPBzhXR6ZNT73zcF5fOpfbx9nMEvfEzrnNh3aBEqNN7DQZ
 F3w+el2TSzzc06/1i467tlBT63VmtyWmufxtW8I6oWKeSnYSTUPVWoT+BVktNMVPbBdQI2/B80Iiv
 9yHldmbZ1Hk3kdaYJJg4YcjIjY2qYSVmj486o9prAicF1kWctQZ/DtlHRM9qqUm95R7ctNN8uqDTT
 4IZsyijak3VlnhdfOZHOJwwBnZBdG2aNL5zUlN7wcTdbJW8OHpST/hb84d1efGZAvIKlFq1TwT
 ;
Received: from 31-208-42-58.cust.bredband2.com ([31.208.42.58]:49938
 helo=latte)
 by uggla.sjd.se with esmtpsa (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.92) (envelope-from &lt;simon@josefsson.org&gt;) id 1l3RJj-0003gx-UA
 for submit@bugs.debian.org; Sat, 23 Jan 2021 22:23:39 +0000
X-Hashcash: 1:22:210123:submit@bugs.debian.org::ykBww9roFZTdrJzI:5cY7
From: Simon Josefsson &lt;simon@josefsson.org&gt;
To: submit@bugs.debian.org
Subject: [PATCH] Support SCRAM-SHA-1 etc via libgsasl
OpenPGP: id=B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE;
 url=https://josefsson.org/key-20190320.txt
Date: Sat, 23 Jan 2021 23:23:39 +0100
Message-ID: &lt;87czxvs36c.fsf@latte.josefsson.org&gt;
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary=&quot;==-=-=&quot;;
 micalg=pgp-sha256; protocol=&quot;application/pgp-signature&quot;
Delivered-To: submit@bugs.debian.org

--==-=-=
Content-Type: multipart/mixed; boundary=&quot;=-=-=&quot;

--=-=-=
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

Package: exim4
Tags: patch

Hi!

The patch below links exim4-daemon-heavy to libgsasl to enable the
'gsasl' authenticator support in exim, see:

https://exim.org/exim-html-current/doc/html/spec_html/ch-the_gsasl_authenti=
cator.html

This makes it possible to enable SCRAM-SHA-1 and SCRAM-SHA-256 in Exim
via libgsasl.

Any chance this could make it into bullseye?  Thanks :)

I have done some testing using a minimal gsasl driver, and it seems to
work.  Configuration on the server side:

root@sid:/etc/exim4# cat conf.d/auth/50-sid
gsasl:
  driver =3D gsasl
  public_name =3D SCRAM-SHA-1
  server_password =3D foo
  server_set_id =3D ${quote:$auth1}
  server_condition =3D yes
root@sid:/etc/exim4#=20

Client side works:

jas@latte:~$ LANG=3DC gsasl x.y.z.q 587 --no-starttls --mechanism SCRAM-SHA=
-1 -a jas --password foo -d
Trying 'x.y.z.q'...
220 sid ESMTP Exim 4.94 Sat, 23 Jan 2021 22:20:48 +0000
EHLO [127.0.0.1]
250-sid Hello ...
250-SIZE 52428800
250-8BITMIME
250-PIPELINING
250-PIPE_CONNECT
250-AUTH SCRAM-SHA-1
250-CHUNKING
250-STARTTLS
250-PRDR
250 HELP
AUTH SCRAM-SHA-1
334=20
biwsbj1qYXMscj1oOEh0TmFxci9UclA4eDlrbHlOeFhQTWc=3D
334 cj1oOEh0TmFxci9UclA4eDlrbHlOeFhQTWdPYkNqUnQ2OFU1Y0pJblR5ZWtyam12aVEscz1=
5QnU1N3JNN3RwenFlNUpiLGk9NDA5Ng=3D=3D
Yz1iaXdzLHI9aDhIdE5hcXIvVHJQOHg5a2x5TnhYUE1nT2JDalJ0NjhVNWNKSW5UeWVrcmptdml=
RLHA9V1hVWGliY05tYTVZMk9UVExqQnlmWUNJT1NVPQ=3D=3D
334 dj1pNkgzeW9IWWhVTXJxdERYd3VPaURYM0t6T2s9

235 Authentication succeeded
Client authentication finished (server trusted)...
Session finished...
QUIT
221 sid closing connection
jas@latte:~$=20

/Simon

--=-=-=
Content-Type: text/x-diff
Content-Disposition: inline;
 filename=0001-Support-gsasl-authenticators.patch
Content-Transfer-Encoding: quoted-printable

diff --git a/debian/EDITME.exim4-heavy.diff b/debian/EDITME.exim4-heavy.diff
index b95c091d..d9943647 100644
=2D-- a/debian/EDITME.exim4-heavy.diff
+++ b/debian/EDITME.exim4-heavy.diff
@@ -76,7 +76,7 @@
=20=20
  # If you have content scanning you may wish to only include some of the s=
canner
  # interfaces.  Uncomment any of these lines to remove that code.
=2D@@ -757,8 +760,8 @@
+@@ -757,9 +760,9 @@
  # configuration to make use of the mechanism(s) selected.
=20=20
  AUTH_CRAM_MD5=3Dyes
@@ -85,8 +85,10 @@
 +AUTH_CYRUS_SASL=3Dyes
 +AUTH_DOVECOT=3Dyes
  # AUTH_EXTERNAL=3Dyes
=2D # AUTH_GSASL=3Dyes
+-# AUTH_GSASL=3Dyes
++AUTH_GSASL=3Dyes
  # AUTH_GSASL_PC=3Dlibgsasl
+ # AUTH_HEIMDAL_GSSAPI=3Dyes
 @@ -766,8 +769,8 @@
  # AUTH_HEIMDAL_GSSAPI_PC=3Dheimdal-gssapi
  # AUTH_HEIMDAL_GSSAPI_PC=3Dheimdal-gssapi heimdal-krb5
@@ -103,7 +105,7 @@
  # Ditto for AUTH_HEIMDAL_GSSAPI(_PC).
=20=20
 -# AUTH_LIBS=3D-lsasl2
=2D+AUTH_LIBS=3D-lsasl2
++AUTH_LIBS=3D-lsasl2 -lgsasl
  # AUTH_LIBS=3D-lgsasl
  # AUTH_LIBS=3D-lgssapi -lheimntlm -lkrb5 -lhx509 -lcom_err -lhcrypto -las=
n1 -lwind -lroken -lcrypt
=20=20
diff --git a/debian/changelog b/debian/changelog
index fa073995..681abcbd 100644
diff --git a/debian/control b/debian/control
index 31390e45..5ef32e4a 100644
=2D-- a/debian/control
+++ b/debian/control
@@ -17,6 +17,7 @@ Build-Depends:
  docbook-xsl,
  libdb5.3-dev,
  libgnutls28-dev (&gt;=3D 3.5.7),
+ libgsasl7-dev,
  libident-dev,
  libidn11-dev,
  libidn2-dev,

--=-=-=--

--==-=-=
Content-Type: application/pgp-signature; name=&quot;signature.asc&quot;

-----BEGIN PGP SIGNATURE-----

iHUEARYIAB0WIQSjzJyHC50xCrrUzy9RcisI/kdFogUCYAyh6wAKCRBRcisI/kdF
onqoAP0arwI5bXQRQJDOfB8OovwsNT+y1VidEhCwaGA6l5Cy6gD/c7ICCcyNaM55
h7jOHkf0fJJNvy7L95oV6orP/autIg4=
=G7SX
-----END PGP SIGNATURE-----
--==-=-=--
]