Search The ForumSearch   RegisterRegister  LoginLogin

AfterLogic WebMail Lite 7

 AfterLogic Forum : AfterLogic WebMail Lite 7
Subject Topic: Webmail Auth uses PLAIN instead of CRAM-M Post ReplyPost New Topic
Author
Message << Prev Topic | Next Topic >>
rq3wa53a7d182e0
Newbie
Newbie
Avatar

Joined: 10 September 2015
Location: France
Online Status: Offline
Posts: 3
Posted: 10 September 2015 at 6:23am | IP Logged Quote rq3wa53a7d182e0

Hello,

I used to run a Roundcube installation, connecting to IMAPS locally with a dovecot server supporting :
auth_mechanisms = scram-sha-1 digest-md5 cram-md5

Now I've got a fresh installation of Webmail Lite running fine.
But I had to change my dovecot settings to allow PLAIN authentication, otherwise Webmail Lite wouldn't connect to it, with dovecot complaining it doesn't support PLAIN authentication.

Looking at the source code of Webmail Lite I saw some "// todo" comments near the auth mechanism section of the code. I didn't dig more, but are SCRAM-SHA-1, DIGEST-MD5 or CRAM-MD5 supposed to be supported by Webmail Lite ? It bothers me to lower the security level.
Is it supported in the Pro version ?

Thanks.
Back to Top View rq3wa53a7d182e0's Profile Search for other posts by rq3wa53a7d182e0
 
Igor
AfterLogic Support
AfterLogic Support


Joined: 24 June 2008
Location: United States
Online Status: Offline
Posts: 6044
Posted: 10 September 2015 at 6:53am | IP Logged Quote Igor

PHP version of AfterLogic WebMail uses AUTH LOGIN method by default, and it's also able to use AUTH PLAIN unless that option is disabled in data/settings/config.php file:

Code:
'login.enable-plain-auth' => 'false',


More secure methods are not currently supported, be it Lite or Pro. However, if you access IMAP server over SSL, that shouldn't be a problem.

--
Regards,
Igor, AfterLogic Support
Back to Top View Igor's Profile Search for other posts by Igor
 
rq3wa53a7d182e0
Newbie
Newbie
Avatar

Joined: 10 September 2015
Location: France
Online Status: Offline
Posts: 3
Posted: 11 September 2015 at 9:34am | IP Logged Quote rq3wa53a7d182e0

Thank you for that answer.
Back to Top View rq3wa53a7d182e0's Profile Search for other posts by rq3wa53a7d182e0
 

If you wish to post a reply to this topic you must first login
If you are not already registered you must first register

  Post ReplyPost New Topic
Printable version Printable version

Forum Jump

Powered by Web Wiz Forums version 7.9
Copyright ©2001-2004 Web Wiz Guide