<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.kde.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugs.kde.org/"
          
          maintainer="sysadmin@kde.org"
>

    <bug>
          <bug_id>249992</bug_id>
          
          <creation_ts>2010-09-03 12:28:46 +0000</creation_ts>
          <short_desc>Can&apos;t log in to IMAP server using non plain text auth mechanism</short_desc>
          <delta_ts>2012-02-15 16:23:12 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>3</classification_id>
          <classification>Frameworks and Libraries</classification>
          <product>Akonadi</product>
          <component>IMAP resource</component>
          <version>1.4.0</version>
          <rep_platform>Compiled Sources</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>NOR</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Bernhard Rosenkraenzer">bero</reporter>
          <assigned_to name="Kevin Ottens">ervin</assigned_to>
          <cc>alexxy</cc>
    
    <cc>bjo</cc>
    
    <cc>bugs</cc>
    
    <cc>devel</cc>
    
    <cc>dirk.heinrichs</cc>
    
    <cc>ismail</cc>
    
    <cc>kde+bugs</cc>
    
    <cc>kde</cc>
    
    <cc>Klaus.Weidenbach</cc>
    
    <cc>mr</cc>
    
    <cc>ol+kde</cc>
    
    <cc>pim-bugs-null</cc>
    
    <cc>vkrause</cc>
    
    <cc>winter</cc>
          
          <cf_commitlink></cf_commitlink>
          <cf_versionfixedin></cf_versionfixedin>
          <cf_sentryurl></cf_sentryurl>
          <votes>80</votes>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1013679</commentid>
    <comment_count>0</comment_count>
    <who name="Bernhard Rosenkraenzer">bero</who>
    <bug_when>2010-09-03 12:28:46 +0000</bug_when>
    <thetext>Version:           1.4.0 (using KDE 4.5.0) 
OS:                Linux

When trying to set up an account on a IMAP server running dovecot 2.0.1, akonadi (run from kmail) complains

The server refused the supplied username and password. Do you want to go to settings, have another attempt at logging in, or do nothing?
SASL(0): successful result:

The login actually succeeded (if I type the password again in the dialog, I get &quot;IMAP session in the wrong state for authentication&quot; because I&apos;m already logged in), but kmail/akonadi thinks it didn&apos;t.

The SASL version in use is cyrus-sasl 2.1.24-rc1.

Reproducible: Always

Steps to Reproduce:
Try to configure an IMAP account on a dovecot 2.0.1 server with kmail from the 4.5 branch in SVN

Actual Results:  
Fails with
SASL(0): successful result:

Expected Results:  
Succeeds</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1060337</commentid>
    <comment_count>1</comment_count>
    <who name="Bernhard Rosenkraenzer">bero</who>
    <bug_when>2010-12-17 11:00:23 +0000</bug_when>
    <thetext>I can&apos;t reproduce this anymore with 4.6.0-beta2, assuming it&apos;s fixed</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1089689</commentid>
    <comment_count>2</comment_count>
    <who name="Alexey Shvetsov">alexxy</who>
    <bug_when>2011-02-20 16:19:35 +0000</bug_when>
    <thetext>this bug seems still valid
at least with dovecot-2.0.9
and kdepim buld from git master or with latest kdepim-4.6.x beta</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1106713</commentid>
    <comment_count>3</comment_count>
    <who name="Christophe Marin">christophe</who>
    <bug_when>2011-04-11 15:15:55 +0000</bug_when>
    <thetext>*** Bug 270635 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1113070</commentid>
    <comment_count>4</comment_count>
    <who name="ancow">bugs</who>
    <bug_when>2011-04-30 12:52:34 +0000</bug_when>
    <thetext>I&apos;ve just experienced this bug and it doesn&apos;t seem to occur with the cleartext login method (it does with both CRAM-MD5 and PLAIN).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1136157</commentid>
    <comment_count>5</comment_count>
    <who name="Klaus Weidenbach">Klaus.Weidenbach</who>
    <bug_when>2011-06-27 20:04:56 +0000</bug_when>
    <thetext>The problem still exists with dovecot-2.0.13 and KDE 4.6.4. The autocheck function selects SSL/TLS and PLAIN, but it is not working. If I select cleartext I can access the IMAP account.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1141525</commentid>
    <comment_count>6</comment_count>
    <who name="Martin Samek">mr</who>
    <bug_when>2011-07-13 21:47:36 +0000</bug_when>
    <thetext>Yes, bug is still valid. I can confirm it witch kontakt 4.6.0  and dovecot 2.0.13. This issue is caused by this change in dovecot:

http://dovecot.org/list/dovecot/2010-April/048147.html

Other clients works like a charm, but kmail fails.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1156095</commentid>
    <comment_count>7</comment_count>
    <who name="Rob Wouters">kde</who>
    <bug_when>2011-08-22 18:41:14 +0000</bug_when>
    <thetext>Patch against kdepimlibs that fixes this bug for me:

--- kimap/loginjob.cpp.orig     2011-08-22 20:27:30.526267893 +0200
+++ kimap/loginjob.cpp  2011-08-22 20:38:11.555674184 +0200
@@ -324,7 +324,9 @@
     }
   } else if ( response.content.size() &gt;= 2 ) {
     if ( d-&gt;authState == LoginJobPrivate::Authenticate ) {
-      if (!d-&gt;answerChallenge(QByteArray::fromBase64(response.content[1].toString()))) {
+      //if we&apos;re receiving post-login capabilities, ignore them here
+      //capabilities are being set by capabilitiesjob after
+      if (response.content[1].toString()!=&quot;CAPABILITY&quot; &amp;&amp; !d-&gt;answerChallenge(QByteArray::fromBase64(response.content[1].toString()))) {
         emitResult(); //error, we&apos;re done
       }
     } else if ( response.content[1].toString()==&quot;CAPABILITY&quot; ) {

Please test and let me know if it works and doesn&apos;t cause regressions.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1157187</commentid>
    <comment_count>8</comment_count>
    <who name="Harm">kde+bugs</who>
    <bug_when>2011-08-26 00:08:19 +0000</bug_when>
    <thetext>Patch works for me using kmail-4.7.0 and dovecot-2.0.13 with sasl.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1158042</commentid>
    <comment_count>9</comment_count>
    <who name="Christophe Marin">christophe</who>
    <bug_when>2011-08-28 21:12:17 +0000</bug_when>
    <thetext>Rob, can you submit your patch to https://git.reviewboard.kde.org please (group &apos;kdepimlibs&apos;).

A small unit test would also help</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1182597</commentid>
    <comment_count>10</comment_count>
    <who name="Sam">academicsam</who>
    <bug_when>2011-11-07 23:12:05 +0000</bug_when>
    <thetext>Patch works for me as well. Using kmail 4.7.3 and dovecot-2.0.15. It would have been nice if this patch submitted in Aug. made it to at least 4.7.3.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1182599</commentid>
    <comment_count>11</comment_count>
      <attachid>65371</attachid>
    <who name="Bernhard Rosenkraenzer">bero</who>
    <bug_when>2011-11-07 23:22:24 +0000</bug_when>
    <thetext>Created attachment 65371
Another variant of the fix

The patch works for me too - but I wonder if just switching the if() statements wouldn&apos;t be a better fix (patch attached).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1182869</commentid>
    <comment_count>12</comment_count>
    <who name="Allen Winter">winter</who>
    <bug_when>2011-11-08 18:00:12 +0000</bug_when>
    <thetext>ervin, I would like to see this fix in the next bugfix release of KDE 4.7.x

could you give the thumbs-up or down on this patch?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1215185</commentid>
    <comment_count>13</comment_count>
    <who name="Peter Mühlenpfordt">devel</who>
    <bug_when>2012-01-16 18:34:49 +0000</bug_when>
    <thetext>Bug still exists in Kontact/Kmail 4.8 rc2 (Kubuntu testing, 12.04/precise).
Tested with latest auto built package of dovecot (2.0.17) running on debian.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1222314</commentid>
    <comment_count>14</comment_count>
    <who name="Oleg Girko">ol+kde</who>
    <bug_when>2012-02-02 22:03:54 +0000</bug_when>
    <thetext>The patch provided in comment #11 fixes the problem only partially.

Reordering if branches makes LOGIN authentication work, but other authentication methods get refused when SSL connection is used because the unsolicited untagged CAPABILITY response to AUTHENTICATE command does not contain &quot;AUTH=&quot; capabilities.

It&apos;s interesting to note that everything works fine if unencrypted connection is used, because KIMAP::LoginJob does not send CAPABILITY command when connection is not encrypted, so Dovecot IMAP server does not send unsolicited untagged CAPABILITY response to AUTHENTICATE command later. Not sending CAPABILITY command when unencrypted connection is used can be considered as a separate bug.

The logic in KIMAP::LoginJob::handleResponse() method is difficult to understand, do I&apos;ve refactored it and made it more correct.

Please take a look at the following review request:
https://git.reviewboard.kde.org/r/103854/
The patch in this review request fixes this bug.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1225950</commentid>
    <comment_count>15</comment_count>
    <who name="Kevin Ottens">ervin</who>
    <bug_when>2012-02-12 11:17:43 +0000</bug_when>
    <thetext>*** Bug 267884 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1225951</commentid>
    <comment_count>16</comment_count>
    <who name="Kevin Ottens">ervin</who>
    <bug_when>2012-02-12 11:19:58 +0000</bug_when>
    <thetext>Rewording the title a bit, it&apos;s more widespread than just dovecot, it&apos;s about
AUTHENTICATE command.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1227039</commentid>
    <comment_count>17</comment_count>
    <who name="Oleg Girko">ol+kde</who>
    <bug_when>2012-02-14 22:03:50 +0000</bug_when>
    <thetext>Git commit 07e337d8965fe5aa334bd60a5141031168b1ac62 by Oleg Girko.
Committed on 14/02/2012 at 22:51.
Pushed by girko into branch &apos;master&apos;.

Refactoring KIMAP::LoginJob::handleResponse() method for better correctness.

Besides better readability, this makes handleResponse() method
handle not only untagged response caused by CAPABILITY command,
but also unsolicited untagged CAPABILITY response caused by AUTHENTICATE
command which is returned by Dovecot IMAP server for compatibility with
MS Outlook.
This fixes bug #249992.
REVIEW: 103854

M  +136  -82   kimap/loginjob.cpp

http://commits.kde.org/kdepimlibs/07e337d8965fe5aa334bd60a5141031168b1ac62</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1227051</commentid>
    <comment_count>18</comment_count>
    <who name="Oleg Girko">ol+kde</who>
    <bug_when>2012-02-14 22:43:18 +0000</bug_when>
    <thetext>Git commit b4809337d8bd1de9274f5aa7f9284f22c579fdcd by Oleg Girko.
Committed on 14/02/2012 at 22:51.
Pushed by girko into branch &apos;KDE/4.8&apos;.

Refactoring KIMAP::LoginJob::handleResponse() method for better correctness.

Besides better readability, this makes handleResponse() method
handle not only untagged response caused by CAPABILITY command,
but also unsolicited untagged CAPABILITY response caused by AUTHENTICATE
command which is returned by Dovecot IMAP server for compatibility with
MS Outlook.
This fixes bug #249992.
REVIEW: 103854

M  +136  -82   kimap/loginjob.cpp

http://commits.kde.org/kdepimlibs/b4809337d8bd1de9274f5aa7f9284f22c579fdcd</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1227268</commentid>
    <comment_count>19</comment_count>
    <who name="Oleg Girko">ol+kde</who>
    <bug_when>2012-02-15 16:23:12 +0000</bug_when>
    <thetext>Git commit 454bc5fe8603f358c414720d128c79dcd33c9776 by Oleg Girko.
Committed on 14/02/2012 at 22:51.
Pushed by girko into branch &apos;KDE/4.7&apos;.

Refactoring KIMAP::LoginJob::handleResponse() method for better correctness.

Besides better readability, this makes handleResponse() method
handle not only untagged response caused by CAPABILITY command,
but also unsolicited untagged CAPABILITY response caused by AUTHENTICATE
command which is returned by Dovecot IMAP server for compatibility with
MS Outlook.
This fixes bug #249992.
REVIEW: 103854

M  +136  -82   kimap/loginjob.cpp

http://commits.kde.org/kdepimlibs/454bc5fe8603f358c414720d128c79dcd33c9776</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>65371</attachid>
            <date>2011-11-07 23:22:24 +0000</date>
            <delta_ts>2011-11-07 23:22:24 +0000</delta_ts>
            <desc>Another variant of the fix</desc>
            <filename>kdepimlibs-4.7.3-bug249992.patch</filename>
            <type>text/plain</type>
            <size>1286</size>
            <attacher name="Bernhard Rosenkraenzer">bero</attacher>
            
              <data encoding="base64">LS0tIGtkZXBpbWxpYnMtNC43LjMva2ltYXAvbG9naW5qb2IuY3BwLmFyawkyMDExLTExLTA4IDAw
OjE1OjIwLjMzOTMxNzg3MiArMDEwMAorKysga2RlcGltbGlicy00LjcuMy9raW1hcC9sb2dpbmpv
Yi5jcHAJMjAxMS0xMS0wOCAwMDoxOTo1MS42ODU5NzQ3MDYgKzAxMDAKQEAgLTMyMywxMSArMzIz
LDcgQEAgdm9pZCBMb2dpbkpvYjo6aGFuZGxlUmVzcG9uc2UoIGNvbnN0IE1lcwogICAgICAgfQog
ICAgIH0KICAgfSBlbHNlIGlmICggcmVzcG9uc2UuY29udGVudC5zaXplKCkgPj0gMiApIHsKLSAg
ICBpZiAoIGQtPmF1dGhTdGF0ZSA9PSBMb2dpbkpvYlByaXZhdGU6OkF1dGhlbnRpY2F0ZSApIHsK
LSAgICAgIGlmICghZC0+YW5zd2VyQ2hhbGxlbmdlKFFCeXRlQXJyYXk6OmZyb21CYXNlNjQocmVz
cG9uc2UuY29udGVudFsxXS50b1N0cmluZygpKSkpIHsKLSAgICAgICAgZW1pdFJlc3VsdCgpOyAv
L2Vycm9yLCB3ZSdyZSBkb25lCi0gICAgICB9Ci0gICAgfSBlbHNlIGlmICggcmVzcG9uc2UuY29u
dGVudFsxXS50b1N0cmluZygpPT0iQ0FQQUJJTElUWSIgKSB7CisgICAgaWYgKCByZXNwb25zZS5j
b250ZW50WzFdLnRvU3RyaW5nKCk9PSJDQVBBQklMSVRZIiApIHsKICAgICAgIGJvb2wgYXV0aE1v
ZGVTdXBwb3J0ZWQgPSBkLT5hdXRoTW9kZS5pc0VtcHR5KCk7CiAgICAgICBmb3IgKGludCBpID0g
MjsgaSA8IHJlc3BvbnNlLmNvbnRlbnQuc2l6ZSgpOyArK2kpIHsKICAgICAgICAgUVN0cmluZyBj
YXBhYmlsaXR5ID0gcmVzcG9uc2UuY29udGVudFtpXS50b1N0cmluZygpOwpAQCAtMzQ2LDYgKzM0
MiwxMCBAQCB2b2lkIExvZ2luSm9iOjpoYW5kbGVSZXNwb25zZSggY29uc3QgTWVzCiAgICAgICAg
IHNldEVycm9yVGV4dCggaTE4bigiTG9naW4gZmFpbGVkLCBhdXRoZW50aWNhdGlvbiBtb2RlICUx
IGlzIG5vdCBzdXBwb3J0ZWQgYnkgdGhlIHNlcnZlci4iLCBkLT5hdXRoTW9kZSkgKTsKICAgICAg
ICAgZC0+YXV0aFN0YXRlID0gTG9naW5Kb2JQcml2YXRlOjpMb2dpbjsgLy9qdXN0IHRvIHRyZWF0
IHRoZSB1cGNvbWluZyBPSyBjb3JyZWN0bHkKICAgICAgIH0KKyAgICB9IGVsc2UgaWYgKCBkLT5h
dXRoU3RhdGUgPT0gTG9naW5Kb2JQcml2YXRlOjpBdXRoZW50aWNhdGUgKSB7CisgICAgICBpZiAo
IWQtPmFuc3dlckNoYWxsZW5nZShRQnl0ZUFycmF5Ojpmcm9tQmFzZTY0KHJlc3BvbnNlLmNvbnRl
bnRbMV0udG9TdHJpbmcoKSkpKSB7CisgICAgICAgIGVtaXRSZXN1bHQoKTsgLy9lcnJvciwgd2Un
cmUgZG9uZQorICAgICAgfQogICAgIH0KICAgfQogfQo=
</data>

          </attachment>
      

    </bug>

</bugzilla>