Topic: A newbie question about password encryption
I have the server set up and seemingly running, and I am beginning testing it. I am going to be using Mozilla Thunderbird as an IMAP client. When setting it up, I specified encrypted password for authentication, but the iredmail server apparently doesn't support this.
However, it does seem to support STARTTLS when you connect, which should ensure an encrypted connection. My question is, is the password broadcast as plain text before the connection is established, or after? What I'm wondering is if my password gets plain text broadcast over the network. If so, is there a way to avoid that?
Related question: since webmail is https, would the password not be visible without the key over the webmail connection?
Another related question: do all iredmail installations use the same TLS decryption key? I admit I'm not too up on how the certificates work, but if all installations use the same key, that would seem to be a security vulnerability. If I'm off here, feel free to correct me
Edit: Another probably dumb question. Is IRedMail configured, by default, to NOT be an open relay?
- Ubuntu 10.4 LTS
- iRedMail 0.7.4, mysql
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.