APOP auth (was Re: [suse-security] nscd and other demons)
It would be cool if the popper rpm came with APOP already configured for qpopper. APOP uses a different database for passwords (so if you crack the password, you still cant login via shell..you can just check mail), and also sends the passwords over an encrypted channel. but then again.. you cant have apop AND clear text.. and alot of email clients dont support apop (Qualcomm's Eudora for win32 does ;).. so maybe have two copies of qpopper. One that does clear text and one that does APOP ..and uncomment the one you prefer out of inetd.conf I love APOP:)
By the way; pop3, imap, ftp, telnet, samba without encrypt passwords, nis are not secure. So, if you´re planing to sell a secure distribution, you must not distribute netscape, because all users can configure a pop3 account. ;) pop3 without ssl, oder imap without ssl is a high risc.
participants (1)
-
Chrissy LeMaire