You can use fail2ban to parse your web server log. If 3 fails from the
same IP, then ban for x hours.
Filter on POST method and 403 status code and connect uri
<IP> - - [<DATE>] "POST /SOGo/connect HTTP/1.1" 403 354
On 2018-04-27 22:17, Chris wrote:
On Fri, 27 Apr 2018 09:41:05 +0200
Christian Mack wrote:
The other possibility would be to use one of CAS or SAML2
authentication. Those two generate a session ticket, which is passed
to SOGo for authentication.
SOGo then accesses IMAP- and SIEVE-servers with that ticket.
Because of that your IMAP-, SIEVE- and SMTP-servers have to be enabled
to use those tickets first.
Thank you for your detailed reply. I didn't know that it's possible to
use tickets. Maybe I'll test this when there's a bit more time...
--
Papst Franziskus ruft zum Kampf gegen Fake News auf. Wir finden, der
Mann, der sich als Stellvertreter Christi ausgibt, von dem er
behauptet, dessen Mutter sei zeitlebens Jungfrau gewesen, er hätte über
Wasser gehen und selbiges in Wein verwandeln können, hat vollkommen
recht.
--
[email protected]
https://inverse.ca/sogo/lists