Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
This website is powered by Openwall GNU/*/Linux security-enhanced OS
[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Tue, 03 Jun 2003 18:16:46 +1000
From: "Daniel" <daniel@...vatecage.com>
To: popa3d-users@...ts.openwall.com
Subject: Re: root mail.

Hi Craig,

>I'm using popa3d for just for an internal email system, so security
>isn't so important.

Security is *always* important. This goes equally for internal systems.
It's very easy these days to sniff traffic going over the internal network.

I like to login as root all the time rather that su. So I ensure
that at no time is the root's password transmitted in clear text,
whether it's over the Internet or on internal systems.

popa3d's default configuration to prevent pop3 root access is essential
to my network security plan.

Yes you can forward the root email to a non-root account. I don't like this
as the non-root account is not always secured like the root account is.

In regards to getting root email directly, I use an SSL/IMAP
solution (which also utilises popa3d of course ;-).

Or ssh/pop3 could be an option, but it's not a solution that is easily
transferable.

I can access root email anywhere via a secure web browser session.
(SquirrelMail, imap-uw and popa3d)

This is just for your consideration.

regards,

hotdiggedydog

*********** REPLY SEPARATOR  ***********

On 03/06/2003 at 3:19 pm Craig Hammond wrote:

>Hi,
>I have just starting using popa3d.
> 
>I'm figuring that you stop popa3d from serving roots mail for security
>reasons.
>The only reason I can think off is to stop stupid admins from sending
>the root password in cleartext over the internet.
> 
>I'm using popa3d for just for an internal email system, so security
>isn't so important.
>It is possible to change it so I can retrieve roots mail. If so, how.
> 
>Thanks,
>Craig



Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux