Re: dovecot security

2010-10-21 Thread Camaleón
On Wed, 20 Oct 2010 17:49:16 -0400, Rob Owens wrote: > On Wed, Oct 20, 2010 at 01:05:08PM +, Camaleón wrote: >> Check Dovecot's log files. What error are you getting? :-? >> > dovecot: imap-login: Aborted login (0 authentication attempts): > > And then it shows the IP address of my server a

Re: dovecot security

2010-10-20 Thread Rob Owens
On Thu, Oct 21, 2010 at 12:15:36AM +0200, Sjoerd Hardeman wrote: > Op 20-10-10 23:49, Rob Owens schreef: > > One detail I've left out, and the "cannot log in" error makes me wonder > > about it: My user is an LDAP account user, and I did not configure > > /etc/dovecot/dovecot-ldap.conf. My reason

Re: dovecot security

2010-10-20 Thread Sjoerd Hardeman
Op 20-10-10 23:49, Rob Owens schreef: > One detail I've left out, and the "cannot log in" error makes me wonder > about it: My user is an LDAP account user, and I did not configure > /etc/dovecot/dovecot-ldap.conf. My reason for not configuring it was > that dovecot seemed to work without it (but

Re: dovecot security

2010-10-20 Thread Rob Owens
On Wed, Oct 20, 2010 at 01:05:08PM +, Camaleón wrote: > On Tue, 19 Oct 2010 16:24:29 -0400, Rob Owens wrote: > > > On Sun, Oct 17, 2010 at 05:56:40PM +, Camaleón wrote: > > >> Plaintext Authentication > >> http://wiki2.dovecot.org/BasicConfiguration > >> > > Thanks for those links. I ha

Re: dovecot security

2010-10-20 Thread Camaleón
On Tue, 19 Oct 2010 16:24:29 -0400, Rob Owens wrote: > On Sun, Oct 17, 2010 at 05:56:40PM +, Camaleón wrote: >> Plaintext Authentication >> http://wiki2.dovecot.org/BasicConfiguration >> > Thanks for those links. I had a quick look at my config files again, > and they seem to allow plaintex

Re: dovecot security

2010-10-19 Thread Eduardo M KALINOWSKI
On 10/19/2010 06:24 PM, Rob Owens wrote: Thanks. I just wanted to make sure that my auto-generated SSL cert was in fact auto-generated, and not just a default cert that *everybody* gets when they install dovecot. Such thing wouldn't work, as certificates are specific to one host. If the host

Re: dovecot security

2010-10-19 Thread Rob Owens
On Sun, Oct 17, 2010 at 05:56:40PM +, Camaleón wrote: > On Sun, 17 Oct 2010 11:21:28 -0400, Rob Owens wrote: > > > 1) It seems like cleartext communication is disabled by default, and > > only TLS or SSL is allowed. I can't find this in the docs or conf file, > > though. Can anybody confirm

Re: dovecot security

2010-10-17 Thread Camaleón
On Sun, 17 Oct 2010 11:21:28 -0400, Rob Owens wrote: > 1) It seems like cleartext communication is disabled by default, and > only TLS or SSL is allowed. I can't find this in the docs or conf file, > though. Can anybody confirm this is the case? Look, at their testing sample page there is a co

dovecot security

2010-10-17 Thread Rob Owens
I'm testing out dovecot-imapd and there are a couple things I can't figure out. 1) It seems like cleartext communication is disabled by default, and only TLS or SSL is allowed. I can't find this in the docs or conf file, though. Can anybody confirm this is the case? 2) There is a certificat