[vchkpw] security issue

2010-12-22 Thread ckubu
Hi, Mailsetup: qmail + vpopmail 5.5.27 + dovecot Over the years, we didn't store cleatext versions of passwords. Some time ago, we wanted to change that setup and since that time, we used vpopmail compiled without option --disable-clear-passwd, but know with option --enable-learn-passwords .

Re: [vchkpw] security issue

2010-12-22 Thread Matt Brookings
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/22/2010 05:06 AM, ckubu wrote: Hi, Mailsetup: qmail + vpopmail 5.5.27 + dovecot I assume you mean vpopmail 5.4.27. Over the years, we didn't store cleatext versions of passwords. Some time ago, we wanted to change that setup and since

Re: [vchkpw] security issue

2010-12-22 Thread Joshua Megerman
Hi, Mailsetup: qmail + vpopmail 5.5.27 + dovecot Over the years, we didn't store cleatext versions of passwords. Some time ago, we wanted to change that setup and since that time, we used vpopmail compiled without option --disable-clear-passwd, but know with option

Re: [vchkpw] security issue

2010-12-22 Thread RemoMattei
I would like to add my 2 cents here. As far as I remember if the client will login with imap there will be no password learning and it will stay empty. I remember I had similar case so I have advice my client to connect with pop (I use qmail pop since it's secure and it never gave me problems) and