Re: Perdition config question
Clark Coffman <[email protected]>
| Newsgroups | gmane.mail.perdition.user |
|---|---|
| Organization | EduTech (education technology services) |
| Message-ID | <[email protected]> |
Hello all, I've been monitoring this list for a bit watching for updates and waiting for the release of 1.18. Another option, that we chose to do here is to use ipsec between our perdition box and our imap boxes. We also use ipsec between our web mail boxes and the perdition box. We use SSL (port 993) between our clients and the perdition box and SSL (port 443) on the web mailers. It's worked very well for us so far. We also think our server subnet is pretty secure but frankly you just never know what will occur. We'd been running the setup for a while now but only started enforcing it for all of our users recently. It works well for us. Clark Vincent Fox wrote: > I work in the UC Davis Data Center we have about > 70K users plus or minus a few hundred. > > When more than a couple of systems end up getting attached > to your "private" network, at some point you will have > to do a LENGTHY investigation when some system > you didn't even know about, gets hacked and then the > security folks wonder whether 70K users could have > had their passwords sniffed. Let's not get into proper > security practice discussion, if you work in a Data Center > you know you have enough systems something will go > wrong or maybe you'll just get hit with a 0-day sploit. > Things do go wrong and I prefer to not trust anything > will take advantage of any layers of security handy. > > IMO plaintext is not worth the trouble. I like the added security > of being able to say "I didn't trust the network" because > sometimes you really can't unless it's a one-man show > with a handful of systems. > > If you are not using this in a big shop and do not > have these problems then by all means. I can tell you > from running Perdition in this mode, the CPU on our > 4 Perdition frontends are barely ticking over at load peak > of MAYBE 0.2 during the Fall quarter rush. Our frontends > are nothing exciting really just some COTS 1U Opterons. > > We use internally generated certs for Perdition to backend > mail-store and that is no big deal to set up. > > It is very nice having Perdition in the front, we can migrate > users around in the backend to all kinds of mail-stores Exchange > or Cyrus or whatever, it's transparent. We just update the record > in LDAP as to what backend they are stored on. > > I just wish Perdition had GSSAPI support. > > > ______________________________________________ > Perdition-users mailing list > [email protected] > http://lists.vergenet.net/listinfo/perdition-users > -- ____________________________________ Clark W. Coffman - System Admin - EduTech (education technology services) North Dakota State University - 1320 Albrecht Blvd, IACC 218D [email protected] Work: 701-231-8825 - Fax: 701-231-8541 Hamster: Whack!! Rabbit: Did you just whack me with a carrot? ... Hamster: Whoa! Oh boy!! ------------------------------------ ______________________________________________ Perdition-users mailing list [email protected] http://lists.vergenet.net/listinfo/perdition-users