OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Matthias Andree (ma_at_dt.e-technik.uni-dortmund.de)
Date: Mon Dec 02 2002 - 11:21:34 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    "Edward Wildgoose" <Edward.WildgooseFRMHedge.com> writes:

    > It will never happen, but my vote would be that all SMTP servers from
    > now on are shipped with SMTP AUTH enabled by default (using PAM/sasldb
    > on linux, local user account on Win32). The user must climb the admin
    > curve to turn that off rather than having to do some work to switch it
    > on!

    It will not happen, but the reason is another: because Wietse is
    uncomfortable with the huge Cyrus-SASL code linked in. Cyrus has had its
    security issues, so he has a valid point.

    -- 
    Matthias Andree