Am 13.09.2013 04:30, schrieb Quinn Comendant:
On Wed, 11 Sep 2013 15:07:31 +0200, Johannes Weberhofer wrote:
this line in the spec will remove CRAM-MD5 completely:

%{__perl} -pi -e "s|\#define CRAM_MD5||g" qmail-smtpd.c

I'd like to do this as well to remove the dependence on pw_clear_passwd. It's 
really this easy? And the clients that were using CRAM MD5 before will then use 
the alternative available option(s) during the smtp/submission transaction?

I look forward to seeing this as a full howto  up on the wiki. ;)

Quinn

I'd recommend to disable plaintext-passworts in vpopmail, too (see configure) 
and to disable CRAM-MD5 as authentication method in dovecot.

Where possible you should force using SSL or TLS connections.

Johannes

--
Johannes Weberhofer
Weberhofer GmbH, Austria, Vienna

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to