Re: Webmail accessive Dovecot logins

2015-10-30 Thread Steffen Kaiser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Thu, 29 Oct 2015, David Mehler wrote: I've seen this issue before, running a imap/smtp/database server on localhost and adding in a webmail interface, in this case Roundcube. In my maillog I'm seeing accessive Dovecot connections and logouts

Re: Webmail accessive Dovecot logins

2015-10-30 Thread Joseph Tam
"A. Schulze" writes: David Mehler: Second question, in the doveconf -n there's reference to my ssl_cipher am I using current tls ciphers that support pfs? ssl_cipher_list = ALL:!LOW:!SSLv3:!SSLv2:!EXP:!aNULL some non pfs cipher would be still active. check yourself: # openssl ciphers

Re: Webmail accessive Dovecot logins

2015-10-30 Thread A. Schulze
David Mehler: Second question, in the doveconf -n there's reference to my ssl_cipher am I using current tls ciphers that support pfs? ssl_cipher_list = ALL:!LOW:!SSLv3:!SSLv2:!EXP:!aNULL some non pfs cipher would be still active. check yourself: # openssl ciphers -v

Webmail accessive Dovecot logins

2015-10-29 Thread David Mehler
Hello, I've seen this issue before, running a imap/smtp/database server on localhost and adding in a webmail interface, in this case Roundcube. In my maillog I'm seeing accessive Dovecot connections and logouts just from my own transaction of logging in, going to compose a message, sending, and