On 24/04/12 09:08 PM, Jonathan Adams wrote:
Dovecot's take on Qmail (and other MTA's http://wiki.dovecot.org/MTA ) which states "qmail is an obsolete and unmaintained server. Its POP3 part can be taken over by Dovecot. Qmail started off boasting about speed and security in the mid-1990s, but has lots of unfixed bugs (this document includes patches where known), among them security bugs that remain unfixed, and the security guarantee (500 USD) denied. If you really intend to continue using it, read Dave Sill's Life with qmail which contains instructions to work around some of qmail's security issues. "
DJB coughed up the goods for the dnscache security hole. The qmail-smtpd one is rather contrived (read: only 'demonstrated' in a very particular setup with a particular compiler on a particular operating system) and most probably never going to see the light of day.
The only fair comment there is 'obsolete and unmaintained'. _______________________________________________ OpenIndiana-discuss mailing list [email protected] http://openindiana.org/mailman/listinfo/openindiana-discuss
