Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject:
PostPosted: Wed May 20, 2009 2:18 pm 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
reading my dovecot.conf/main.cf,
do you think that this is a secure configuration?

do you think that my VPS can be attaked to serve spam?
I'm really afraid about that, can I do more to improve my security?

I closed all the unused port, configured iptables with enforcing security...

thanks


Top
   
 Post subject:
PostPosted: Wed May 20, 2009 7:15 pm 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
I have one more question if possible...
Why thunderbird make me check email using SSL,
but I can't use "encrypted connection" option?
If I enable this option in thunderbird I've got, APOP not enable message.


Top
   
 Post subject:
PostPosted: Thu May 21, 2009 6:35 am 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
sblantipodi wrote:
I have one more question if possible...
Why thunderbird make me check email using SSL,
but I can't use "encrypted connection" option?
If I enable this option in thunderbird I've got, APOP not enable message.


I read tons of guide but I haven't solved this problem yet.
:( :cry:

/var/log/maillog
told this when the error occur:
May 21 13:53:55 li62-51 dovecot: pop3-login: Disconnected: rip=::ffff:[my_client_ip], lip=::ffff:[my_vps_ip], TLS


Top
   
 Post subject:
PostPosted: Thu May 21, 2009 6:08 pm 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
this is the complete maillog
when trying to send email from phone:

May 21 18:04:23 li62-51 dovecot: auth(default): new auth connection: pid=4319
May 21 18:04:25 li62-51 dovecot: pop3-login: SSL_accept() failed: error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure [::ffff:151.81.4.71]
May 21 18:04:25 li62-51 dovecot: pop3-login: Disconnected: rip=::ffff:my_client_ip, lip=::ffff:my_server_ip, TLS handshake


Top
   
 Post subject:
PostPosted: Fri May 22, 2009 7:32 am 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
I solved by add a comment on
smtpd_tls_auth_only = yes
in the main.cf file...

Do you think that this is terrible for security?


Top
   
 Post subject:
PostPosted: Fri May 22, 2009 9:19 am 
Offline
Senior Member
User avatar

Joined: Mon Dec 10, 2007 4:30 pm
Posts: 341
Website: http://markwalling.org
Did you bother to read the documentation for that parameter?


Top
   
 Post subject:
PostPosted: Fri May 22, 2009 9:24 am 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
mwalling wrote:
Did you bother to read the documentation for that parameter?


I know what this parameter means,
I'm only asking if commenting this parameter may create some security issue.


Top
   
 Post subject:
PostPosted: Sat May 23, 2009 7:29 pm 
Offline
Senior Member

Joined: Wed May 13, 2009 1:32 pm
Posts: 737
Location: Italy
sblantipodi wrote:
I know what this parameter means,
I'm only asking if commenting this parameter may create some security issue.


bump.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group