On 2013-12-06 14:44, Andrew Morgan wrote: > > I suppose I could try this in my test environment... > > Actually, it looks like my test environment has allowplaintext:0 > everywhere, and connections from the frontends use PLAIN+TLS. Now I > just need to put this in place in my production environment too! > When I set "allowplaintext:0" on the database server, I get errors from the front-end servers about not being able to connect to mupdate: Dec 11 10:27:30 imap-fe2 mupdate[2655]: successful mupdate connection to imap-fe1.serve r.rpi.edu Dec 11 10:39:53 imap-fe2 lmtp[4686]: mupdate-client: connect(imap-fe1.server.rpi.edu): Connection refused Dec 11 10:39:53 imap-fe2 lmtp[4686]: couldn't connect to imap-fe1.server.rpi.edu: no co nnection to server Dec 11 10:39:57 imap-fe2 lmtp[5428]: mupdate-client: connect(imap-fe1.server.rpi.edu): Connection refused Dec 11 10:39:57 imap-fe2 lmtp[5428]: couldn't connect to imap-fe1.server.rpi.edu: no co nnection to server etc. TLS is enabled. I do not have a shared authentication mechanism enabled. Saslauthd is running, but defers to PAM (MECH="pam"). Mike -- Michael D. Sofka sofkam@xxxxxxx C&MT Sr. Systems Programmer, Email, TeX, Epistemology Rensselaer Polytechnic Institute, Troy, NY. http://www.rpi.edu/~sofkam/ ---- Cyrus Home Page: http://www.cyrusimap.org/ List Archives/Info: http://lists.andrew.cmu.edu/pipermail/info-cyrus/ To Unsubscribe: https://lists.andrew.cmu.edu/mailman/listinfo/info-cyrus