Read the 'maxssf' parameter if defined in Authen::SASL #2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
If /perl-authen-sasl/perl-authen-sasl/pull/11 is accepted, this adds support for reading the new 'maxssf' parameter.
Authen::SASL::XS is required for Active Directory domains using 'LDAP server channel binding token requirements' set to 'Always' (current security recommendation), because Authen::SASL::Perl does not appear to support CBT but Cyrus SASL does. But the XS module also requires MAXSSF set to 0, which is hard-coded to 255 with no mechanism to change it.
Leaving the default at 255 even through the Perl module defaults to 2**31 - 1