> i just checked the relevant SASL RFCs, they are pretty clear that authzid > handling is not required for server implementations and those servers will > reject any SASL exchanges with authzid set. Indeed. simplesasl does the right thing, but qca-sasl does not, which is why textshell posted this. cheers, Remko