Hello,

|> I have enabled POP logs. Is there any way to hide passwords=20
|in that log?
|
|What about setting the correct permissions to MAIL_ROOT ?

It's the immediate solution, but the basic security rule is not to give =
a
chance - and no not rely on one thing. It's why you should patch your =
server
even when you're behind firewall. And why you should not store sensitive
data secured only by access rights.=20

Especially when you recommend to run XMail in SYSTEM security context, =
and
thus allow access to anyone running the same context - for example any =
other
similar server software, which may have a security hole.

IMHO, the good solution would be not to include such information in =
logfile.
Or, at least not in case of successfull authentication - it may be =
helpful
to store passwords used when access was denied.

-- Altair

-
To unsubscribe from this list: send the line "unsubscribe xmail" in
the body of a message to [EMAIL PROTECTED]
For general help: send the line "help" in the body of a message to
[EMAIL PROTECTED]

Reply via email to