View previous topic :: View next topic |
Author |
Message |
audiodef Watchman
Joined: 06 Jul 2005 Posts: 6656 Location: The soundosphere
|
|
Back to top |
|
|
Hu Administrator
Joined: 06 Mar 2007 Posts: 23062
|
Posted: Thu Jun 20, 2019 1:42 am Post subject: |
|
|
MD5 for password storage is long since deprecated, especially if it is not even salted. Wouldn't it be better to store the hashes using an algorithm that satisfies current best practices? |
|
Back to top |
|
|
audiodef Watchman
Joined: 06 Jul 2005 Posts: 6656 Location: The soundosphere
|
|
Back to top |
|
|
szatox Advocate
Joined: 27 Aug 2013 Posts: 3487
|
Posted: Thu Jun 20, 2019 4:10 pm Post subject: |
|
|
I guess you're not going to get much help with the original question anyway, so here's a little tip for the future improvement:
I've found delegating authentication to dovecot pretty convenient. Postfix still needs access to the database so it can read aliases, but with authentication delegated to dovecot, postfix does not limit your options to md5 anymore. |
|
Back to top |
|
|
audiodef Watchman
Joined: 06 Jul 2005 Posts: 6656 Location: The soundosphere
|
|
Back to top |
|
|
|