Re: LMTP AUTH security exposure?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Ken Murchison wrote:
>
> You can set service-specific options, such as "lmtp_allowplaintext: 
> yes".  The service-specific prefix must match a service name in 
> cyrus.conf.
>
That seems more than sufficient solution, thanks!

We set
allowplaintext: no
lmtp_allowplaintext: yes

It works like a charm.   I sniffed and it looks like LMTP delivery
over TCP does a STARTTLS so we are covered from compromised
hosts picking the password out of the traffic.

Thanks!


----
Cyrus Home Page: http://cyrusimap.web.cmu.edu/
Cyrus Wiki/FAQ: http://cyrusimap.web.cmu.edu/twiki
List Archives/Info: http://asg.web.cmu.edu/cyrus/mailing-list.html

[Index of Archives]     [Cyrus SASL]     [Squirrel Mail]     [Asterisk PBX]     [Video For Linux]     [Photo]     [Yosemite News]     [gtk]     [KDE]     [Gimp on Windows]     [Steve's Art]

  Powered by Linux