Re: [Dovecot-news] CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used

2022-07-07 Thread Noel Butler
On 07/07/2022 07:24, Aki Tuomi wrote: On 06/07/2022 16:54 EEST Aki Tuomi via Dovecot-news wrote: Affected product: Dovecot IMAP Server Internal reference: DOV-5320 Vulnerability type: Improper Access Control (CWE-284) Vulnerable version: 2.2 Vulnerable component: submission Report confidence:

Perl5 error in logs

2022-07-07 Thread @lbutlr
I am getting a lot of these in the logs: dovecot[52816] imap: Error: Use of uninitialized value $ENV{"PATH"} in split at /usr/local/lib/perl5/5.36/mach/File/Spec/Unix.pm line 256. FreeBSD 13.1-RELEASE releng/13.1-n250148-fc952ac2212 GENERIC ===>>> dovecot-2.3.19.1 ===>>> dovecot-pigeonhole-0.5.

Redhat 9 Repository for Dovecot

2022-07-07 Thread Istiak Ferdous
Hello, Redhat 9 is publicly released for some time. Is there any plan to provide repository for it? http://repo.dovecot.org/ce-2.3-latest/rhel/ https://developers.redhat.com/articles/2022/05/18/whats-new-red-hat-enterprise-linux-9 Thanks, Istiak Ferdous

Re: User authentication / activity log

2022-07-07 Thread Karl Denninger
On 7/7/2022 10:44, dove...@ptld.com wrote: On 07-07-2022 10:15 am, Karl Denninger wrote: I have a set of maintenance "things" that I want to have happen if someone does not authenticate against Dovecot (to check mail) after some period of time. I also don't see anything appropriate in the syslo

Re: User authentication / activity log

2022-07-07 Thread dovecot
> On 07-07-2022 10:15 am, Karl Denninger wrote: > > I have a set of maintenance "things" that I want to have happen if someone > does not authenticate against Dovecot (to check mail) after some period of > time. > I also don't see anything appropriate in the syslog that dovecot dumps into > the

User authentication / activity log

2022-07-07 Thread Karl Denninger
I'm on 2.3.19.1 (9b53102964) running on FreeBSD, if it matters. I have a set of maintenance "things" that I want to have happen if someone does not authenticate against Dovecot (to check mail) after some period of time.  I was running the Z-Push exchange server, which (as its in PHP) made stic

Re: Is multi factor authentication practical/feasible?

2022-07-07 Thread Aki Tuomi
> On 07/07/2022 01:12 EEST Michael Peddemors wrote: > > > On 2022-07-06 10:17, gene heskett wrote: > >> As far as I can see from what I tested today (mainly switching my > >> Thunderbird from "Normal Password" to "OAuth"), Clients effectively > >> *have* to be "also a browser" (rendering th