[Dovecot] Deliver prints passwort to the syslog

Timo Sirainen tss at iki.fi
Tue Sep 18 16:52:57 EEST 2007


On Tue, 2007-09-18 at 12:16 +0200, Dominik Schulz wrote:
> Hi,
> I've got the problem that dovecot's deliver prints the authentification 
> information to the syslog.
> 
> Like this:
> Sep 18 12:11:22 mail deliver(user at domain.tld): auth input: 
> user=user at domain.tld
> Sep 18 12:11:22 mail deliver(user at domain.tld): auth input: password=XXXX
> Sep 18 12:11:22 mail deliver(user at domain.tld): auth input: 
> home=/home/mail/domain.tld/user
> Sep 18 12:11:22 mail deliver(user at domain.tld): auth input: uid=8
> Sep 18 12:11:22 mail deliver(user at domain.tld): auth input: gid=8
> 
> I guess that it's only a configuration option but right now I can't figure out 
> which one I need to change to turn this off.

First of all it shouldn't be sent to deliver in the first place. What
userdb do you use and with what kind of a configuration? It shouldn't
return password field.

Once you've got that fixed, you can unset auth_debug=yes.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://dovecot.org/pipermail/dovecot/attachments/20070918/2349927b/attachment.bin 


More information about the dovecot mailing list