OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
postfix & cyrus & sasl_smtp_auth

From: Philippe Vogel (filiaapfreenet.de)
Date: Fri Oct 01 2004 - 18:27:18 CDT


Hello!

Anybody got any idea why the cyrus-team made smtp-client-auth with that
insecure way by storing user-pw in a file?

1) This is not easy to administrate because everything has to be but in
a file again.
2) Is there a different way using sasldb2 or direct sasl-auth?

I know this lists are flodded with this stuff, but there are many
questions and no answers to find on the net.
Everybody has nice explanations but nobody shows a working solution
except this insecure one.

I run postfix chroot + amavisd-new + spamassassin + cyrus-imap + smtp-auth.
The spamassassin + amavis is no problem at all, but cyrus is trash.

Philippe