Re: [Dovecot] imapc vs auth-userdb security

2011-09-15 Thread Timo Sirainen
On Wed, 2011-09-14 at 13:57 +0200, Lutz Preßler wrote: > On Mi, 14 Sep 2011, Timo Sirainen wrote: > > > On 14.9.2011, at 14.40, Lutz Preßler wrote: > > > > > with imapc settings coming from userdb (individual configuration > > > necessary) > > > there exists a security problem if access to auth-

Re: [Dovecot] imapc vs auth-userdb security

2011-09-14 Thread Lutz Preßler
On Mi, 14 Sep 2011, Timo Sirainen wrote: > On 14.9.2011, at 14.40, Lutz Preßler wrote: > > > with imapc settings coming from userdb (individual configuration necessary) > > there exists a security problem if access to auth-userdb socket is given > > to normal (shell) users: > > So don't give it

Re: [Dovecot] imapc vs auth-userdb security

2011-09-14 Thread Timo Sirainen
On 14.9.2011, at 14.40, Lutz Preßler wrote: > with imapc settings coming from userdb (individual configuration necessary) > there exists a security problem if access to auth-userdb socket is given > to normal (shell) users: So don't give it to them? :) Actually this should be pretty much solved w

[Dovecot] imapc vs auth-userdb security

2011-09-14 Thread Lutz Preßler
Hello, with imapc settings coming from userdb (individual configuration necessary) there exists a security problem if access to auth-userdb socket is given to normal (shell) users: testuser@host:~$ doveadm user user1 userdb: lpmail uid : 1000 gid : home : /home/user1