On 12/08/2011 02:21 PM, Gary Smith wrote:
Wouldn't it be smarter to just tell SquirrelMail to use port 587 and pass through authentication? This way if the server is compromised or has another exploit there isn't a simple internal email server to send all that spam from. This is exactly what we do for both horde and roundcube.
That was my first suggestion, but the stable version of SquirrelMail (and the one supplied by Gentoo) doesn't support STARTTLS.