On Tue, 28 Aug 2001, Matt Bernstein wrote:
> ..but it's too late by then! You say (in the clear)
> AUTH PLAIN MiMeHaSh..
> ..and the server replies
> 503 STARTTLS required before AUTH
the server doesn't have to advertise it's auth-capability unless the
channel is already secured :) (no, i don't know how (if at all) to do
that. but it wouldn't be nice...)
otoh - once one does ssl, then why bother with passwords ? use
certificates then :)
--
[-]