Server Team 2007-11-20 meeting minutes
Scott Kitterman
ubuntu at kitterman.com
Mon Nov 26 15:00:14 UTC 2007
On Saturday 24 November 2007 15:11, Ante Karamatić wrote:
> On Sat, 24 Nov 2007 13:52:11 -0500
>
> Scott Kitterman <ubuntu at kitterman.com> wrote:
> > I think we need to either provide no plain text mechanisms or provide
> > TLS. Since the default setting for smtp_sasl_security_options
> > (noplaintext, noanonymous) will not allow plain text mechanisms
> > without TLS, then this is safe.
>
> For both dovecot and postfix, TLS is enabled by default in Ubuntu.
>
> > It would be better, if it's achievable, to set up TLS and allow plain
> > text (LOGIN and PLAIN) since between those two virtually all mail
> > clients are supported. Perhaps, at a minimum, check for TLS and if
> > it's enabled, add:
> >
> > postconf -e "smtp_sasl_security_options = noanonymous"
> > postconf -e "broken_sasl_auth_clients = yes"
>
> I was considering those two, but I really wanted minimum for a start...
I think that's reasonable for now, but we ought to get Plain and Login in
there before Hardy's release. I think this option is a great one for people
who aren't experienced Postfix admins and so it's be a bit of a suprise to
them not to have these included.
Scott K
More information about the ubuntu-server
mailing list