{
    "mode": "man",
    "parameter": "libsasl",
    "section": "5",
    "url": "https://www.chedong.com/phpMan.php/man/libsasl/5/json",
    "generated": "2026-10-08T07:30:53Z",
    "synopsis": "Cyrus SASL library handling communication between an application and the Cyrus SASL authenti‐\ncation framework.",
    "sections": {
        "NAME": {
            "content": "libsasl - authentication library\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "Cyrus SASL library handling communication between an application and the Cyrus SASL authenti‐\ncation framework.\n",
            "subsections": []
        },
        "Description": {
            "content": "This  document  describes generic configuration options for the Cyrus SASL authentication li‐\nbrary libsasl.\n\nThe library handles communication between an application and the  Cyrus  SASL  authentication\nframework.  Both  exchange  information before libsasl can start offering authentication ser‐\nvices for the application.\n\nThe application, among other data, sends the servicename. The service name is  the  services\nname  as specified by IANA. SMTP servers, for example, send smtp as servicename. This infor‐\nmation is handed over by libsasl e.g. when Kerberos or PAM authentication takes place.\n\nConfiguration options in general are read either from a file or passed by the application us‐\ning libsasl during library initialization.\n",
            "subsections": []
        },
        "File-Based configuration": {
            "content": "When an application (server) starts, it initializes  the  libsasl  library.  The  application\npasses  appname  (application  name) to the SASL library. Its value is used to construct the\nname of the application specific SASL configuration file. The Cyrus SASL  sample-server,  for\nexample, sends sample as appname. Using this value the SASL library will search the configu‐\nration directories for a file named sample.conf and read configuration options from it.\nNote\n\nConsult  the applications manual to determine what appname it sends to the Cyrus SASL\nlibrary.\n",
            "subsections": []
        },
        "Application-Based Configuration": {
            "content": "Configuration options for libsasl are written down together with application specific options\nin the applications configuration file. The application reads them and passes  them  over  to\nlibsasl when it loads the library.\nNote\n\nAn  example  for  application-based configuration is the Cyrus IMAP server imapd. SASL\nconfiguration is written to imapd.conf and passed to the SASL library when  the  imapd\nserver starts.\n",
            "subsections": []
        },
        "Configuration Syntax": {
            "content": "The general format of Cyrus SASL configuration file is as follows:\n\nConfiguration options\nConfiguration  options are written each on a single physical line. Parameter and value\nmust be separated by a colon and a single whitespace:\n\nparameter: value\nImportant\n\nThere must be no trailing whitespace after the value or Cyrus SASL will fail to  apply\nthe value appropriately!\n\nComments, Empty lines and whitespace-only lines\nEmpty lines and whitespace-only lines are ignored, as are lines whose first non-white‐\nspace character is a ‘#’.\n",
            "subsections": []
        },
        "Options": {
            "content": "There are generic options and options specific to the password verification service or auxil‐\niary  property  plugin  chosen  by the administrator. Such specific options are documented in\nmanuals listed in libsasl(5).\n\nThe following configuration parameters are generic configuration options:\n\nauthdaemondpath (default: /dev/null)\nPath to Courier MTA authdaemond's unix socket. Only applicable when pwcheckmethod  is\nset to authdaemond.\n\nautotransition: (default: no)\nAutomatically transition users to other mechanisms when they do a successful plaintext\nauthentication and if an auxprop plugin is used.\nImportant\n\nThis option does not apply to the ldapdb(5) plugin. It is a read-only plugin.\n\nno     Do not transition users to other mechanisms.\n\nnoplain\nTransition users to other mechanisms, but write non-plaintext secrets only.\n\nyes    Transition users to other mechanisms.\nNote\n\nThe  only  mechanisms (as currently implemented) which don't use plaintext secrets are\nOTP and SRP.\n\nauxpropplugin: (default: empty)\nA whitespace-separated list  of  one  or  more  auxiliary  plugins  used  if  the  pw‐\ncheckmethod parameter specifies auxprop as an option. Plugins will be queried in list\norder. If no plugin is specified, all available plugins will be queried.\n\nldapdb Specify ldapdb to use the Cyrus SASL ldapdb(5) plugin.\n\nsasldb Specify sasldb to use the Cyrus SASL sasldb(5) plugin.\n\nsql    Specify sql to use the Cyrus SASL sql(5) plugin.\n\nloglevel: (default: 1)\nSpecifies a numeric log level. Available log levels are:\n\n0      Don't log anything\n\n1      Log unusual errors\n\n2      Log all authentication failures\n\n3      Log non-fatal warnings\n\n4      More verbose than 3\n\n5      More verbose than 4\n\n6      Traces of internal protocols\n\n7      Traces of internal protocols, including passwords\nImportant\n\nCyrus SASL sends log messages to the application that runs it. The application decides\nif  it  forwards  such messages to the sysklogd(8) service, to which facility they are\nsent and which priority is given to the message.\n\nmechlist: (default: empty)\nThe optional mechlist parameter specifies a whitespace-separated list of one or  more\nmechanisms allowed for authentication.\n\npwcheckmethod: (default: auxprop)\nA whitespace-separated list of one or more mechanisms. Cyrus SASL provides the follow‐\ning mechanisms:\n\nauthdaemond\nConfigures  Cyrus SASL to contact the Courier MTA authdaemond(8) password veri‐\nfication service for password verification.\n\nalwaystrue\nLets the pwcheck succeed always.\n\nauxprop\nCyrus SASL will use its own plugin infrastructure to verify passwords. The aux‐\npropplugin parameter controls which plugins will be used.\n\npwcheck\nVerify passwords using the Cyrus SASL pwcheck(8) password verification service.\nThe pwcheck daemon is considered deprecated and should not be used anymore. Use\nthe saslauthd password verification service instead.\n\nsaslauthd\nVerify passwords using the Cyrus SASL saslauthd(8) password  verification  ser‐\nvice.\n\nsaslauthdpath: (default: empty)\nPath to saslauthd(8) run directory (including the /mux named pipe)\n\nSee also\nauthdaemond(5),   ldapdb(5),  libsasl(5),  saslauthd(8),  saslauthd.conf(5),  saslpasswd2(5),\nsasldblistusers2(5), sasldb(5), sql(5)\n",
            "subsections": []
        },
        "Author": {
            "content": "This manual was written for the Debian distribution because the  original  program  does  not\nhave  a  manual  page.  Parts  of the documentation have been taken from the Cyrus SASL's op‐\ntions.html.\n\nPatrick Ben Koetter\n<p@state-of-mind.de>\n\n15 April 2022                                 libsasl(5)",
            "subsections": []
        }
    },
    "summary": "libsasl - authentication library",
    "flags": [],
    "examples": [],
    "see_also": []
}