Force StartTLS/SSL on IMAP AUTH

Discussion in 'Feature Requests' started by CorSch, Nov 19, 2016.

  1. CorSch

    CorSch New Member

    Hi,

    could you please set "disable_plaintext_auth" to "yes" as a default in the dovecot.conf file?
    This option will force the usage of StartTLS instead of plantext for IMAP (TCP/143) Login.
    http://wiki.dovecot.org/SSL

    Best Regards,
    Corvin
     
  2. sjau

    sjau Local Meanie Moderator

    I tend to think this is a good suggestion
     
  3. CorSch

    CorSch New Member

    After reading the dovecot SSL documentation at http://wiki.dovecot.org/SSL/DovecotConfiguration
    I would recommend to add ssl=required instead of disable_plaintext_auth=yes.

     
    elmacus likes this.
  4. elmacus

    elmacus Active Member

    "ssl=required"
    This would be "best practise", people who wants to run unsecure should need to disable security.
     
    Taleman likes this.

Share This Page