Re: IMAP TLS after upgrade from 3.1.17 to 3.2.3

Reindl Harald <[email protected]> Thu, 14 Jul 2016 14:32:23 +0200
Newsgroups gmane.mail.imap.dbmail
Organization the lounge interactive design
Message-ID <[email protected]>

Am 14.07.2016 um 14:26 schrieb Gordan Bobic:
>> and if it's only for security resons because dovecot makes the
>> authetication based on the dbmail database directly with the client
>> and until that was successful no single bit of a arbitary client
>> passes to dbmail
>
> The fact that you are running a different IMAP daemon as a proxy
> in front of it sounds pretty damning...

no it don't

* you can share the same auth for postfix submission instead
   mangle around with sasld and friends

* if you have had historical setups where users needed % instead
   of @ and don't want a support nightmare you need something
   like "auth_username_translation" from dovecot anyways

* if you consider setup a scalable infrastructure you would
   anyways put a proxy in front to have later easy options
   for split load on different backends like you are
   doing it with http

* if you grow and have to serve *really* high load you
   would anyways consider a proxy doing TLS offloading
   far away from the backend servers as you do it with http

_______________________________________________
DBmail mailing list
[email protected]
http://mailman.fastxs.nl/cgi-bin/mailman/listinfo/dbmail
signature.asc (application/pgp-signature, 181 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iEYEARECAAYFAleHhlcACgkQhmBjz394Anle6wCfW5VlM/KB3+dzc2c9qN8ZbjFh
yBQAn09sbSjFhYxM4moeGXf2I2bcrRaC
=QvEB
-----END PGP SIGNATURE-----