4 ms·
I believe Dovecot can be configured not to even advertise AUTH capability until after you've upgraded to TLS capability. Does anyone know if that would stop thi
by BuildTheRobots 6y ago
I believe Dovecot can be configured not to even advertise AUTH capability until after you've upgraded to TLS capability. Does anyone know if that would stop this problem?
Saying that, someone with MITM capability could just modify the response and advertise auth pre-tls, so it probably wouldn't help.
- mjevans 6y agoThe correct response is to require TLS before auth clientside (as well) unless expressly configured to not attempt TLS auth.
- jlgaddis 6y ago> Does anyone know if that would stop this problem? Based on my experiences with Dovecot, I believe it would, > Saying that, someone with MITM capability could just modify the response and advertise auth pre-tls, so it probably wouldn't help. Well, hopefully your client isn't braindead and will negotiate an encrypted session first, before sending credentials unencrypted -- especially if you've configured it to use STARTTLS.