19 Mar
2019
19 Mar
'19
3:50 p.m.
Hello,
I've run into the issue detailed at https://wiki2.dovecot.org/AuthDatabase/CheckPassword#Security
Understandably I don't have the skills to modify checkpassword so if I do the suggested will it work?
If you can't change the script, you can make Dovecot's checkpassword-reply binary setuid or setgid (e.g. chgrp dovecot /usr/libexec/dovecot/checkpassword-reply; chmod g+s /usr/libexec/dovecot/checkpassword-reply)
-- Best regards, Niamh mailto:niamh@fullbore.co.uk