[Dovecot] SSL/TLS handshake stays forever without timeout
morrison
morrisonli at 126.com
Tue Jan 14 18:42:48 EET 2014
Hi,
I am a system admin and I am evaluating using dovecot as our email server. In my test, I found that if I telneted to 993 port and did not do anything or I telneted to 143 port, sent starttls command and then did not do anything, the connection stayed forever without timeout. This will make our mail server vulnerable to DOS attack. I dig into dovecot Wiki and did not find any solution. This seems to me that dovecot does not handle SSL/TLS handshake timeout. I am wondering if this is a known issue and will be fixed in near future.
Thanks,
More information about the dovecot
mailing list