From owner-freebsd-questions@FreeBSD.ORG Sun Mar 24 08:25:16 2013 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by hub.freebsd.org (Postfix) with ESMTP id 2D0FA1358 for ; Sun, 24 Mar 2013 08:25:16 +0000 (UTC) (envelope-from bc979@lafn.org) Received: from zoom.lafn.org (zoom.lafn.org [108.92.93.123]) by mx1.freebsd.org (Postfix) with ESMTP id 091A03FB for ; Sun, 24 Mar 2013 08:25:15 +0000 (UTC) Received: from [10.0.1.2] (static-71-177-216-148.lsanca.fios.verizon.net [71.177.216.148]) (authenticated bits=0) by zoom.lafn.org (8.14.3/8.14.2) with ESMTP id r2O8PFHC066652 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO); Sun, 24 Mar 2013 01:25:15 -0700 (PDT) (envelope-from bc979@lafn.org) Content-Type: text/plain; charset=iso-8859-1 Mime-Version: 1.0 (Mac OS X Mail 6.3 \(1503\)) Subject: Re: Client Authentication From: Doug Hardie In-Reply-To: Date: Sun, 24 Mar 2013 01:25:13 -0700 Content-Transfer-Encoding: quoted-printable Message-Id: <21ECABE0-0946-469F-8A6C-08194571A8D9@lafn.org> References: To: Waitman Gobble X-Mailer: Apple Mail (2.1503) X-Virus-Scanned: clamav-milter 0.97 at zoom.lafn.org X-Virus-Status: Clean Cc: "freebsd-questions@freebsd.org List" X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 24 Mar 2013 08:25:16 -0000 On 24 March 2013, at 01:10, Waitman Gobble wrote: >=20 >=20 > You might consider disabling external smtp auth service and using ssh = tunnel to server to connect to mail. Also provide web based convenience = service.=20 I am not convinced that a ssh tunnel is going to be easy for my users. = We do provide a web based mail client, but I wouldn't describe it as = convenient. I find it a pain in the neck, but so many users requested = it that we provide it. It is password authenticated but so slow it will = never be attacked with password guessing. >=20 > It might be interesting to encrypt mail to the user's cloud service = that operates in a gpg zone. I think this operation could be mostly = transparent to the user, so kids and granpamas can use it without = concern. This one I don't understand. Can you provide pointers to this type of = service?=