Gentoo Archives: gentoo-server

From: kashani <kashani-list@××××××××.net>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] Postfix Virt Mail Hosting
Date: Sat, 14 Jan 2006 23:11:36
Message-Id: 43C984A5.6050109@badapple.net
In Reply to: Re: [gentoo-server] Postfix Virt Mail Hosting by "Paul Kölle"
1 Paul Kölle wrote:
2 > kashani wrote:
3 >
4 >>BTW I would not recommend using that how-to for the following reasons.
5 >>
6 >>1. clear text passwords
7 >
8 > Do you mean "clear text" in the DB or on the wire? If you want to avoid
9 > the former you get the latter 'cause SASL shared secret mechs wouldn't
10 > work anymore. So trust SSL or die and better have *real* certificates ;)
11 > Ah, and have you configured postfix to actually deny PLAIN and LOGIN
12 > without SSL? (smtpd_sasl_security_options = noanonymous noplaintext and
13 > smtpd_sasl_tls_security_options =)
14
15 Any on the wire attack is going to include pop/imap/smtp as well. Either
16 you shove everything into TLS or you don't bother for any of these
17 services.
18
19 Regardless I prefer not to have everyone's clear text password laying in
20 a db somewhere.
21
22 Ramin
23 --
24 gentoo-server@g.o mailing list