[ https://issues.apache.org/jira/browse/JAMES-3636?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Benoit Tellier closed JAMES-3636. --------------------------------- Resolution: Fixed Contributed by https://github.com/apache/james-project/pull/613 > IMAP plainAuthDisallowed should be true by default > -------------------------------------------------- > > Key: JAMES-3636 > URL: https://issues.apache.org/jira/browse/JAMES-3636 > Project: James Server > Issue Type: Improvement > Components: IMAPServer > Affects Versions: 3.6.0 > Reporter: Benoit Tellier > Priority: Major > Fix For: 3.7.0 > > > Encouraging non encrypted login is definitely a bad practice and could lead > to session fixation (where the attacker logs in first then the victim do not > realize it's login fails). > We should make the safe 'plainAuthDisallowed' option the default everywhere. -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: server-dev-unsubscr...@james.apache.org For additional commands, e-mail: server-dev-h...@james.apache.org