LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-26-2009, 03:47 PM   #1
scoop_yo
LQ Newbie
 
Registered: Mar 2007
Posts: 5

Rep: Reputation: 0
Courier-imaps using TLS or SSLv3 ?


Hello,
I have a courier imap (& courier imap-ssl) server for 30 email accounts with a lot of usage and the people that use them log in regularly from a lot of different places like home, university, work, wi-fi on cafeteria etc..

1) Well one thing is that the email password is the the same for shell access. I have denied to some of them shell access by setting their shell to /bin/false. Should this be set to /bin/nologin to deny shell usage and login or /bin/false is OK ?

2) I have written for the email users some intructions on how to use Thunderbird.
I set the security to connect to the server as TLS. Not TLS if available, but TLS.
Problem is that I saw that google uses instead of TLS SSL ( v3 I suppose) and that got me into some thinking !

Of course I could run both but is there any risk with TLS instead of SSLv3 ? Should I prefer SSLv3 for logins instead of TLS ?

In the courier imam-ssl configuration file, option IMAP_TLS_REQUIRED is set to 0 because it doesn't allow logins from the web interface that we use to access the e-mail which I don't administrate neiher host.
This web interface allows the usage of https to login.
 
Old 01-29-2009, 02:44 AM   #2
NaCo
Member
 
Registered: Jun 2002
Location: L.A.
Distribution: Fedora
Posts: 46

Rep: Reputation: 15
TLS replaced SSLv3 so you should be ok using TLS.
SSL was developed by Netscapte, TLS is a IETF Standard based on SSLv3, my understanding is that they are pretty much the same, where as SSLv2 has knwon secuirty holes.

Check it out at Wikipedia.org
http://en.wikipedia.org/wiki/Transport_Layer_Security

Good luck.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
errno: TLS definition in /lib64/libc.so.6 section .tbss mismatches non-TLS reference johnpaulodonnell Programming 2 07-25-2008 04:37 AM
error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure Carpo Slackware 1 07-10-2007 08:46 AM
posfix with courier maildrop and courier-imap Anuragn Linux - Enterprise 4 01-17-2007 04:33 AM
Configuring courier-imap courier-pop redsky Linux - Software 0 06-01-2004 12:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:59 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration