Topic: Implementing security recommendations
==== Required information ====
- iRedMail version:
- Store mail accounts in which backend (LDAP/MySQL/PGSQL):
- Linux/BSD distribution name and version:
- Related log if you're reporting an issue:
======== Required information ====
- iRedMail version: 0.8.6
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Linux/BSD distribution name and version: Debian 7.1
- Related log if you're reporting an issue:
====
Hello Zhang,
I was following the recent security discussions and I found out that the current iRedMail installation could be improved a bit according to https://bettercrypto.org/static/applied … dening.pdf
I was implementing most of the recommendations of Apache, Dovecot and Postfix and it works very well with all of our customers.
Maybe you can review the changes (these are only a few which are required) and implement these secure defaults into the standard iRedMail installations.
In addition it would be great to have SMTP via SSL (TCP Port 465) activated by default in Postfix and iptables Firewall.
I wonder why it's commented out in the master.cf file.
Thank you!
Best regards,
Bernhard
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.