LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > *BSD
User Name
Password
*BSD This forum is for the discussion of all BSD variants.
FreeBSD, OpenBSD, NetBSD, etc.

Notices


Reply
  Search this Thread
Old 06-09-2011, 10:32 PM   #1
methodtwo
Member
 
Registered: May 2007
Posts: 146

Rep: Reputation: 18
FreeBSD is my mutt and dovecot imaps config correct?


Hi
I can connect from my mutt client box to my dovecot server after mkcert.sh has been run and the cert and key are in the correct location(according to dovecot config file) and "enable_plaintext_authentciation = no" is also in the dovecot.conf, as well as ssl = yes. Does this mean that user authentication is being performed by SSL or just that SSL is protecting an interior protocol that performs it's own authentication?. What i'm trying to say is....
If i run:
Code:
#openssl s_client -quiet -connect my_dovecot_server.domain:993
I get this in reponse:
Code:
verify return:1
* OK [CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE AUTH=PLAIN AUTH=LOGIN] Dovecot ready.
What confused me was that i read somewhere that in an imaps connection that the client sent the server a public key. I can connect from the mutt client host by typing my password. But, like i said before, is proper SSL authentication happening here?; To get proper encrypted authentication and sessions do you have to be your own CA(and give the client host a cert) or go to an official CA etc etc or does the response i received and the fact that i can connect when enable_plaintext_authentication = no, indicate that I've already got these things? Or just one of them(authentication)?. I will post my configs if necessary.
Since writing the first edit of this post i've come to understand this: The message i received indicates that i can offer secure IMAPS to clients. It doesn't protect my server from bogus clients logging in. To do that i think(not 100% sure) that i would have to be my own CA(use CA.pl openssl script) and issue certs to my clients. Or go to an official CA and get a cert/chain of certs from them, then issue these certs to my clients. Or just offer IMAPS to internal clients and firewall the other IMAPS requests
Please correct me if i'm wrong
cheers
Thank you very much for shedding some light on the subject

Last edited by methodtwo; 06-12-2011 at 02:13 AM. Reason: needed updating
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] TLS / SASL authentication, dovecot and postfix - does this config look correct? TonyAR Linux - Server 2 10-14-2010 11:40 AM
LXer: Using Secure Mutt Connections with IMAPS LXer Syndicated Linux News 0 02-01-2009 01:41 AM
IMAPS, dovecot, mutt... tofee Linux - Newbie 4 11-22-2006 02:34 AM
FC3, dovecot connection close after correct login... jingi Fedora - Installation 0 11-28-2005 03:25 AM
Dovecot IMAPs SSL certificate nyk Linux - Software 1 11-14-2005 07:58 AM

LinuxQuestions.org > Forums > Other *NIX Forums > *BSD

All times are GMT -5. The time now is 05:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration