You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In #210 we had a conversation about whether or not to keep support for the AUTH_SERVER_ALLOW_NOTLS_PASSWORDS macro, which, if enabled, allows authentication over unsecured connections. The arguments in favor of this feature are that there might be scanners/copiers or other hardware which would need to send emails, but doesn't support modern TLS ciphers. This is a good point, but I'm still reluctant to leave this feature as it is. Perhaps we could use a hostlist instead of a boolean variable, to make this insecurity possible, but only for selected hosts?
The text was updated successfully, but these errors were encountered:
Or we just remove it, we can put my examples in the wiki. If people really need it, they can put it there and we don't clutter our config files (hoping that it is not needed).
In #210 we had a conversation about whether or not to keep support for the
AUTH_SERVER_ALLOW_NOTLS_PASSWORDS
macro, which, if enabled, allows authentication over unsecured connections. The arguments in favor of this feature are that there might be scanners/copiers or other hardware which would need to send emails, but doesn't support modern TLS ciphers. This is a good point, but I'm still reluctant to leave this feature as it is. Perhaps we could use a hostlist instead of a boolean variable, to make this insecurity possible, but only for selected hosts?The text was updated successfully, but these errors were encountered: