1 |
Paul Kölle wrote: |
2 |
> kashani wrote: |
3 |
> |
4 |
>>BTW I would not recommend using that how-to for the following reasons. |
5 |
>> |
6 |
>>1. clear text passwords |
7 |
> |
8 |
> Do you mean "clear text" in the DB or on the wire? If you want to avoid |
9 |
> the former you get the latter 'cause SASL shared secret mechs wouldn't |
10 |
> work anymore. So trust SSL or die and better have *real* certificates ;) |
11 |
> Ah, and have you configured postfix to actually deny PLAIN and LOGIN |
12 |
> without SSL? (smtpd_sasl_security_options = noanonymous noplaintext and |
13 |
> smtpd_sasl_tls_security_options =) |
14 |
|
15 |
Any on the wire attack is going to include pop/imap/smtp as well. Either |
16 |
you shove everything into TLS or you don't bother for any of these |
17 |
services. |
18 |
|
19 |
Regardless I prefer not to have everyone's clear text password laying in |
20 |
a db somewhere. |
21 |
|
22 |
Ramin |
23 |
-- |
24 |
gentoo-server@g.o mailing list |