RFC 3620:The TUNNEL Profile
RFC-Ref

SASL


Click on the red underlined text to get to the source

... connections to outside servers based on the user identity negotiated via SASL. For example, a manager may connect to a proxy, authenticate ...
... a manager may connect to a proxy, authenticate herself with SASL, then instruct the proxy to tunnel ...


... Encryption already enabled (E.g., TLS already negotiated, or a SASL that provides encryption already negotiated.) ...


... is also reasonable to limit the use of the TUNNEL profile to authorized users, as identified by a SASL profile. ...
... connections. This latter attack can also be thwarted by requiring a SASL identification before allowing a TUNNEL channel to be ...



Google
Web
RFC-Ref