Re: Secure it up a bit please...

1999-12-10 Thread Jason Costomiris
On Thu, Dec 09, 1999 at 11:01:08PM -0600, Steve Borho wrote: : Hashed passwords are not necessarily more secure than plaintext ones... It : still boils down to protecting the file the passwords are stored in. If a : person gets root access on your e-mail server, no password encryption : scheme is

Re: Secure it up a bit please...

1999-12-09 Thread Steve Borho
On Thu, Dec 09, 1999 at 10:20:35PM -0500, Michael H. Warfield wrote: > On Thu, Dec 09, 1999 at 08:58:16PM -0500, Jason Costomiris wrote: > > On Thu, Dec 09, 1999 at 08:50:27PM -0500, Michael H. Warfield wrote: > > : I don't agree that you have to store the passwords on the server > > : in clear

Re: Secure it up a bit please...

1999-12-09 Thread Michael H. Warfield
On Thu, Dec 09, 1999 at 08:58:16PM -0500, Jason Costomiris wrote: > On Thu, Dec 09, 1999 at 08:50:27PM -0500, Michael H. Warfield wrote: > : I don't agree that you have to store the passwords on the server > : in clear text. I've got one server with APOP configured and it stores > : hashes.

Re: Secure it up a bit please...

1999-12-09 Thread Jason Costomiris
On Thu, Dec 09, 1999 at 08:50:27PM -0500, Michael H. Warfield wrote: : I don't agree that you have to store the passwords on the server : in clear text. I've got one server with APOP configured and it stores : hashes. They are different hashes from the normal password hashes, so : you have

Re: Secure it up a bit please...

1999-12-09 Thread Michael H. Warfield
On Thu, Dec 09, 1999 at 08:43:18PM -0500, Jason Costomiris wrote: > On Fri, Dec 10, 1999 at 09:30:28AM +1100, Dan Horth wrote: > : I know that Eudora supports Kerberos and APOP authentication as well > : as cleartext passwords... I was just wondering if either of these > : options are more secur

Re: Secure it up a bit please...

1999-12-09 Thread Jason Costomiris
On Fri, Dec 10, 1999 at 09:30:28AM +1100, Dan Horth wrote: : I know that Eudora supports Kerberos and APOP authentication as well : as cleartext passwords... I was just wondering if either of these : options are more secure, and if so how would I go about setting up : our server to use these.

Re: Secure it up a bit please...

1999-12-09 Thread Alan Mead
At 09:30 AM 12/10/99 +1100, Dan Horth wrote: >I know that Eudora supports Kerberos and APOP authentication as well >as cleartext passwords... I was just wondering if either of these >options are more secure, and if so how would I go about setting up >our server to use these. Kerberos is suppo