You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Dovecot with ldap auth_bind only supports plain and login authentication mechanisms.
Since they both use plain text passwords they are only enable on imaps protocol.
This make imap protocol useless since no remaining authentication mechanisms are allowed.
We can use PassordLookups instead, which supports crypt mechanisms.
Cons:
requires a bind dn with permission to read user password hashes
may require a different hash format for LDAP password
The old LILiK mail server permits plain text authentication mechanism over imap, which I think is the worst solution.
The text was updated successfully, but these errors were encountered:
Moreover we can configure Dovecot with our CA and to use starttls by upgrading every connection to and encrypted channel. This should kill every kind of not-encrypted plaintext authentication.
Some admins want to require SSL/TLS, but don't realize that this is also possible with STARTTLS (Dovecot has disable_plaintext_auth=yes and ssl=required settings).
Dovecot with ldap auth_bind only supports plain and login authentication mechanisms.
Since they both use plain text passwords they are only enable on imaps protocol.
This make imap protocol useless since no remaining authentication mechanisms are allowed.
We can use PassordLookups instead, which supports crypt mechanisms.
Cons:
The old LILiK mail server permits plain text authentication mechanism over imap, which I think is the worst solution.
The text was updated successfully, but these errors were encountered: