Network Working Group R. Gellens
Request for Comments: 3206 QUALCOMM
Category: Standards Track February 2002
The SYS and AUTH POP Response Codes
Gellens Standards Track [Page 1]
RFC 3206 The SYS and AUTH POP Response Codes February 2002 1. IntroductionRFC 2449 [POP3-EXT] defined extended [POP3] response codes, to give clients more information about errors so clients can respond more appropriately. In addition to the mechanism, two initial response codes were defined (IN-USE and LOGIN-DELAY), in an attempt to differentiate between authentication failures related to user credentials, and other errors.
2. Conventions Used in this Document
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in RFC 2119 [KEYWORDS].
3. Background
RFC 2449 [POP3-EXT] introduced the IN-USE and LOGIN-DELAY response codes. The intent is to allow clients to clearly determine the underlying cause of a failure in order to respond. For example, clients need to know if the user should be asked for new credentials, or if the POP3 session should simply be tried again later. (Some deployed POP3 clients attempt to parse the text of authentication failure errors, looking for strings known to be issued by various servers which indicate the mailbox is locked.)
Gellens Standards Track [Page 2]
RFC 3206 The SYS and AUTH POP Response Codes February 2002 4. The SYS Response CodeThe SYS response code announces that a failure is due to a system error, as opposed to the user's credentials or an external condition. It is hierarchical, with two possible second-level codes: TEMP and PERM. (Case is not significant at any level of the hierarchy.)
5. The AUTH Response Code
The AUTH response code informs the client that there is a problem with the user's credentials. This might be an incorrect password, an unknown user name, an expired account, an attempt to authenticate in violation of policy (such as from an invalid location or during an unauthorized time), or some other problem.
Gellens Standards Track [Page 3]
RFC 3206 The SYS and AUTH POP Response Codes February 2002 6. The AUTH-RESP-CODE CapabilityCAPA tag:
7. IANA Considerations
IANA has added the AUTH-RESP-CODE capability to the list of POP3 capabilities (established by RFC 2449 [POP3-EXT]).
8. Security Considerations
Section 5, The AUTH Response Code, discusses the security issues related to use of the AUTH response code with the USER command.
Gellens Standards Track [Page 4]
RFC 3206 The SYS and AUTH POP Response Codes February 2002 9. References[KEYWORDS] Bradner, S., "Key words for use in RFCs to Indicate
10. Author's Address
Randall Gellens QUALCOMM Incorporated 5775 Morehouse Drive San Diego, CA 92121-2779 U.S.A.
Gellens Standards Track [Page 5]
RFC 3206 The SYS and AUTH POP Response Codes February 2002 11. Full Copyright StatementCopyright (C) The Internet Society (2002). All Rights Reserved.