OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: 2.3 and Dovecot SASL

From: Victor Duchovni (Victor.DuchovniMorganStanley.com)
Date: Fri Apr 28 2006 - 14:11:07 CDT


On Fri, Apr 28, 2006 at 02:01:22PM -0500, Anthony Messina wrote:

> i do understand that DIGEST and CRAM won't work this way, but since
> neither of those are recommended over an unencrypted connection, you

Do you have a reference for this? Are you conncerned about attacks that
intercept, damage, and then replay the response in flight? SMTP over
TLS in typical configurations is also vulnerable to man-in-the-middle
attacks...

--
        Viktor.

P.S. Morgan Stanley is looking for a New York City based, Senior Unix
     system/email administrator to architect and sustain the Unix email
     environment. If you are interested, please drop me a note.

Disclaimer: off-list followups get on-list replies or get ignored.
Please do not ignore the "Reply-To" header.

To unsubscribe from the postfix-users list, visit
http://www.postfix.org/lists.html or click the link below:
<mailto:majordomopostfix.org?body=unsubscribe%20postfix-users>

If my response solves your problem, the best way to thank me is to not
send an "it worked, thanks" follow-up. If you must respond, please put
"It worked, thanks" in the "Subject" so I can delete these quickly.