[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kolab-devel
Subject:    Re: [Kolab-devel] reason for unencrypted services beeing
From:       Gunnar Wrobel <wrobel () kolabsys ! com>
Date:       2010-08-26 16:01:52
Message-ID: 20100826180152.74511i791qefta80 () kolab ! kolabsys ! com
[Download RAW message or body]

Hi,

Zitat von Silvan Marco Fin <silvan@kernelconcepts.de>:

> Hi!
>
>   Is there a particular reason, why the kolab services (imap, smtp,
> http, ldap) are configured to accept unencrypted connections per
> default? In case of smtp, the situation is clearly a bit more
> complicated, but postfix can be tweaked, to accept either unencrypted
> and unauthenticated connections (relaying or SMTP host) or only
> encrypted and authenticated (for kolab users). For the other services I
> can't think of a reason, why they should accept incoming connections in
> unencrypted form after the default installation.

I assume there were some good reasons in the past to choose the  
defaults as we have them now. And one might have been "Outlook". But I  
don't think this is something that is absolutely fixed and we can  
always discuss and change it.

Maybe the more important point would be some good documentation at a  
prominent place that highlights some important security measures.  
Assuming that we choose a more secure default then we'd need to  
document on how to open the system up. Either because some users are  
unable to connect otherwise or because the server is in a special  
network or whatever other reason I can't think of now.

Cheers,

Gunnar

>
>   Kind regards,
>    Silvan (silvan@kernelconcepts.de)
>
> _______________________________________________
> Kolab-devel mailing list
> Kolab-devel@kolab.org
> https://kolab.org/mailman/listinfo/kolab-devel
>



--
Gunnar Wrobel
Developer, Kolab Systems AG

e: wrobel@kolabsys.com
t: +49 700 6245 0000
w: http://www.kolabsys.com

pgp: 9703 43BE

----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.

_______________________________________________
Kolab-devel mailing list
Kolab-devel@kolab.org
https://kolab.org/mailman/listinfo/kolab-devel
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic