RE: Disallow cleartext on the wire

2011-01-10 Thread Adam Tauno Williams
On Sun, 2011-01-09 at 14:40 -0800, Dudi Goldenberg wrote: I am using Thunderbird to test with. I want completely disallow logins without TLS for IMAP. Have a look at /etc/cyrus.conf: SERVICES { # --- Normal cyrus spool, or Murder backends --- # add or remove based on

Re: Disallow cleartext on the wire

2011-01-10 Thread Bron Gondwana
On Mon, Jan 10, 2011 at 07:00:13AM -0500, Adam Tauno Williams wrote: On Sun, 2011-01-09 at 14:40 -0800, Dudi Goldenberg wrote: I am using Thunderbird to test with. I want completely disallow logins without TLS for IMAP. Have a look at /etc/cyrus.conf: Just hash out imap and restart

Re: Disallow cleartext on the wire

2011-01-10 Thread Dan White
On 10/01/11 23:32 +1100, Bron Gondwana wrote: On Mon, Jan 10, 2011 at 07:00:13AM -0500, Adam Tauno Williams wrote: On Sun, 2011-01-09 at 14:40 -0800, Dudi Goldenberg wrote: I am using Thunderbird to test with. I want completely disallow logins without TLS for IMAP. Have a look at

Re: Disallow cleartext on the wire

2011-01-10 Thread Bron Gondwana
On Mon, Jan 10, 2011 at 11:22:51AM -0600, Dan White wrote: On 10/01/11 23:32 +1100, Bron Gondwana wrote: On Mon, Jan 10, 2011 at 07:00:13AM -0500, Adam Tauno Williams wrote: On Sun, 2011-01-09 at 14:40 -0800, Dudi Goldenberg wrote: I am using Thunderbird to test with. I want completely

Re: Disallow cleartext on the wire

2011-01-10 Thread jonr
Quoting Bron Gondwana br...@fastmail.fm: On Mon, Jan 10, 2011 at 11:22:51AM -0600, Dan White wrote: On 10/01/11 23:32 +1100, Bron Gondwana wrote: On Mon, Jan 10, 2011 at 07:00:13AM -0500, Adam Tauno Williams wrote: On Sun, 2011-01-09 at 14:40 -0800, Dudi Goldenberg wrote: I am using

Re: Disallow cleartext on the wire

2011-01-10 Thread Lucas Zinato Carraro
RFC2595 - not recommended IMAPs, but I disagree in some points. imaps and pop3s ports Separate imaps and pop3s ports were registered for use with SSL. Use of these ports is discouraged in favor of the STARTTLS or STLScommands. .. - Separate ports

Re: Disallow cleartext on the wire

2011-01-10 Thread jonr
Quoting Lucas Zinato Carraro luca...@gmail.com: RFC2595 - not recommended IMAPs, but I disagree in some points. imaps and pop3s ports Separate imaps and pop3s ports were registered for use with SSL. Use of these ports is discouraged in favor of the STARTTLS or STLScommands.

Re: Disallow cleartext on the wire

2011-01-10 Thread Bron Gondwana
On Tue, Jan 11, 2011 at 08:56:01AM +1100, Bron Gondwana wrote: Running IMAP over 143 should be safe from over the wire snooping, if the server is properly configured. Yeah, that's what's known as wishful thinking I suspect. Has anyone actually done any testing on this? And it's certainly

Disallow cleartext on the wire

2011-01-09 Thread jonr
Hello List! I am going mad, mad as in crazy. CentOS 5.5 Sendmail 8.13.8/8.13.8 cyrus-imapd.x86_64-2.3.7-7.el5_4.3 cyrus-imapd-devel.x86_64 -2.3.7-7.el5_4.3 cyrus-imapd-perl.x86_64 -2.3.7-7.el5_4.3 cyrus-imapd-utils.x86_64 -2.3.7-7.el5_4.3 cyrus-sasl.x86_64

RE: Disallow cleartext on the wire

2011-01-09 Thread Dudi Goldenberg
Hi I am using Thunderbird to test with. I want completely disallow logins without TLS for IMAP. Have a look at /etc/cyrus.conf: SERVICES { # --- Normal cyrus spool, or Murder backends --- # add or remove based on preferences imapcmd=imapd -U 30 listen=imap

Re: Disallow cleartext on the wire

2011-01-09 Thread Andrew Morgan
On Sun, 9 Jan 2011, j...@destar.net wrote: Hello List! I am going mad, mad as in crazy. CentOS 5.5 Sendmail 8.13.8/8.13.8 cyrus-imapd.x86_64-2.3.7-7.el5_4.3 cyrus-imapd-devel.x86_64 -2.3.7-7.el5_4.3 cyrus-imapd-perl.x86_64 -2.3.7-7.el5_4.3 cyrus-imapd-utils.x86_64

Re: Disallow cleartext on the wire

2011-01-09 Thread Raphael Jaffey
j...@destar.net wrote: Hello List! I am going mad, mad as in crazy. CentOS 5.5 Sendmail 8.13.8/8.13.8 cyrus-imapd.x86_64-2.3.7-7.el5_4.3 cyrus-imapd-devel.x86_64 -2.3.7-7.el5_4.3 cyrus-imapd-perl.x86_64 -2.3.7-7.el5_4.3 cyrus-imapd-utils.x86_64 -2.3.7-7.el5_4.3

Re: Disallow cleartext on the wire

2011-01-09 Thread jonr
Quoting Andrew Morgan mor...@orst.edu: On Sun, 9 Jan 2011, j...@destar.net wrote: Hello List! I think maybe I am confused here. I thought 'allowplainwithouttls: O' would not allow cleartext passwords but now I am thinking it means only the PLAIN mech. Is that correct? If that is the