On 02/16/12 0:26, Eric Shubert wrote:
As part of the upgrade to vpopmail, we're considering removing clear text passwords from the database. This will improve security, but at the same time remove some (somewhat insecure) capabilitiy.

The biggest impact I think this will have is that admins will no longer be able to look up someone's password. In the event that a user loses their password, the administrator would reset the password to something temporary, and the user would subsequently change it to whatever they like. This is the practice followed in many (if not most) other environments.

I use clear text password for:
- if my manager asked by his superior/co-manager to peek his sub-ordinate email-account
- jabberd authentication by creating a view on vpopmail's table

---------------------------------------------------------------------------------
Qmailtoaster is sponsored by Vickers Consulting Group 
(www.vickersconsulting.com)
   Vickers Consulting Group offers Qmailtoaster support and installations.
     If you need professional help with your setup, contact them today!
---------------------------------------------------------------------------------
    Please visit qmailtoaster.com for the latest news, updates, and packages.
To unsubscribe, e-mail: qmailtoaster-list-unsubscr...@qmailtoaster.com
    For additional commands, e-mail: qmailtoaster-list-h...@qmailtoaster.com


Reply via email to