Skip site navigation (1)Skip section navigation (2)
Date:      23 Feb 98 20:30:46 +0100
From:      leifn@image.dk (Leif Neland)
To:        freebsd-questions@FreeBSD.ORG
Subject:   Re: POP3/IMAP e-mail boxes without users
Message-ID:  <2d5_9802240919@swimsuit.swimsuit.roskildebc.dk>
References:   <ML-3.3.888252872.5988.patl@asimov>

next in thread | previous in thread | raw e-mail | index | archive | help
At 23 Feb 98 17:54:32 patl@phoenix.volant.org  wrote regarding Re: POP3/IMAP
e-mail boxes without users

 DV> I would like to create POP3/IMAP e-mail boxes without adding
 DV> accounts for all the users, with Cryus. I need to build to use
 DV> some other form of authentication than /etc/passwd.

 >> You can add users to /etc/passwd without giving them a shell or a home.

 p> But that potentially opens up other services (and possible
 p> security holes.)  For example, what happens if someone uses one
 p> of those accounts when logging into your FTP server?

If you give the popuser a shell like "/bin/false", the user can't telnet in.
And ftpd requires the shell to be in /etc/shells to allow ftp. So there is no
problem with these services.

 p> With cyrus, the easiest solution is to tweak pwcheck to use an
 p> auxilliary password file.  (Pwcheck comes with cyrus.  If you
 p> aren't using it already, you may need to re-configure and rebuild
 p> imapd to use the external verification.)

But will sendmail deliver to users not in /etc/passwd?


Leif Neland
leifn@image.dk

---
|Fidonet:  Leif Neland 2:234/49
|Internet: leifn@image.dk


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?2d5_9802240919>