Current time: 12-31-2024, 06:53 AM Hello There, Guest! (LoginRegister)


Post Reply 
Email security options
Author Message
bodysplit Offline
Junior Member
*

Posts: 45
Joined: Nov 2007
Reputation: 1
Post: #1
Email security options
I had already posted this on the german forums, but as suggested by BeNe I also make it public here.

After setting up 1.0RC2 and updating it to a more recent nighty, I have stumbled over some problems which might need changes in the future.

I already opened as a ticket are the typos in postfix configs. Hey it is also been fixed already!

Next, courier-auth is sending DIGEST-MD5 and CRAM-MD5 for authentication. I think besides IMAP and POP3, also SMTP is affected (I didn't check if sasl is using courier or MySQL). Anyhow, MD5-based auth doesn't work without a computed hash. ISPCP user creation should be modded according to this info. I personally prefer the generation of a userdb from MySQL as it realy speeds up mail server authentication, at least on my setup.

If MD5-based authentication works, we could kick out clear-text PASSWORD and LOGIN authentication on non-SSL connections, just to make sure a clear-text password is never being used.

Checking communication with several other public mail servers, I also had to find out that my self-signed certificate isn't accepted by some servers. Therefore mail is getting lost. I made it like Google and moved authentication completly to port 587. This said port 25 doesn't give AUTH or STARTTLS any more. 587 has to be used by every customer to send mail out, but it's working realy good. Perhaps it's an idea for 1.1.

Less on security, mailbox quotas aren't implemented per-user. Just like having an option to give every mailbox access to POP/IMAP and anti-virus/spam. I will check these and submit patches if I can.

Last, mail forwards are counted like mailboxes although they should be handled individually just like domain aliases.

Okay, that's it for some real long post.
11-02-2007 09:37 PM
Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
Email security options - bodysplit - 11-02-2007 09:37 PM
RE: Email security options - joximu - 11-02-2007, 09:46 PM
RE: Email security options - bodysplit - 11-02-2007, 10:46 PM
RE: Email security options - raphael - 11-03-2007, 11:15 AM
RE: Email security options - bodysplit - 11-04-2007, 07:51 PM
RE: Email security options - Cube - 11-03-2007, 11:53 AM
RE: Email security options - raphael - 11-05-2007, 04:16 AM
RE: Email security options - BeNe - 11-05-2007, 04:41 PM

Forum Jump:


User(s) browsing this thread: 2 Guest(s)