Hello,
I've run into the issue detailed at https://wiki2.dovecot.org/AuthDatabase/CheckPassword#Security
Understandably I don't have the skills to modify checkpassword so if I do the suggested will it work?
If you can't change the script, you can make Dovecot's checkpassword-reply binary setuid or setgid (e.g. chgrp dovecot /usr/libexec/dovecot/checkpassword-reply; chmod g+s /usr/libexec/dovecot/checkpassword-reply)
-- Best regards, Niamh mailto:niamh@fullbore.co.uk
Hello,
Tuesday, March 19, 2019, 1:50:44 PM, I wrote:
NHvd> I've run into the issue detailed at NHvd> https://wiki2.dovecot.org/AuthDatabase/CheckPassword#Security
Just for clarity this is djb's checkpassword
-- Best regards, Niamh mailto:niamh@fullbore.co.uk
participants (1)
-
Niamh Holding