On 2013-12-06 14:44, Andrew Morgan wrote:
>
> I suppose I could try this in my test environment...
>
> Actually, it looks like my test environment has allowplaintext:0
> everywhere, and connections from the frontends use PLAIN+TLS.  Now I
> just need to put this in place in my production environment too!
>

When I set "allowplaintext:0" on the database server, I get errors from 
the front-end servers about not being able to connect to mupdate:


Dec 11 10:27:30 imap-fe2 mupdate[2655]: successful mupdate connection 
to imap-fe1.serve
r.rpi.edu
Dec 11 10:39:53 imap-fe2 lmtp[4686]: mupdate-client: 
connect(imap-fe1.server.rpi.edu):
Connection refused
Dec 11 10:39:53 imap-fe2 lmtp[4686]: couldn't connect to 
imap-fe1.server.rpi.edu: no co
nnection to server
Dec 11 10:39:57 imap-fe2 lmtp[5428]: mupdate-client: 
connect(imap-fe1.server.rpi.edu):
Connection refused
Dec 11 10:39:57 imap-fe2 lmtp[5428]: couldn't connect to 
imap-fe1.server.rpi.edu: no co
nnection to server


etc.

TLS is enabled.  I do not have a shared authentication mechanism 
enabled.  Saslauthd is running, but defers to PAM (MECH="pam").

Mike

-- 
Michael D. Sofka               sof...@rpi.edu
C&MT Sr. Systems Programmer,   Email, TeX, Epistemology
Rensselaer Polytechnic Institute, Troy, NY.  
http://www.rpi.edu/~sofkam/
----
Cyrus Home Page: http://www.cyrusimap.org/
List Archives/Info: http://lists.andrew.cmu.edu/pipermail/info-cyrus/
To Unsubscribe:
https://lists.andrew.cmu.edu/mailman/listinfo/info-cyrus

Reply via email to