Am 13.09.2013 04:30, schrieb Quinn Comendant:
On Wed, 11 Sep 2013 15:07:31 +0200, Johannes Weberhofer wrote:
this line in the spec will remove CRAM-MD5 completely:
%{__perl} -pi -e "s|\#define CRAM_MD5||g" qmail-smtpd.c
I'd like to do this as well to remove the dependence on pw_clear_passwd. It's
really this easy? And the clients that were using CRAM MD5 before will then use
the alternative available option(s) during the smtp/submission transaction?
I look forward to seeing this as a full howto up on the wiki. ;)
Quinn
I'd recommend to disable plaintext-passworts in vpopmail, too (see configure)
and to disable CRAM-MD5 as authentication method in dovecot.
Where possible you should force using SSL or TLS connections.
Johannes
--
Johannes Weberhofer
Weberhofer GmbH, Austria, Vienna
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]