File: SecurityTuning.txt

package info (click to toggle)
dovecot 1%3A2.3.19.1%2Bdfsg1-2.1%2Bdeb12u1
  • links: PTS, VCS
  • area: main
  • in suites: bookworm
  • size: 58,428 kB
  • sloc: ansic: 560,761; makefile: 7,838; sh: 5,908; cpp: 1,557; perl: 306; python: 255; yacc: 153; xml: 151; lex: 147; pascal: 27
file content (22 lines) | stat: -rw-r--r-- 942 bytes parent folder | download | duplicates (3)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
Security tuning
===============

Dovecot is pretty secure out-of-the box. It uses multiple processes and
privilege separation to isolate different parts from each others in case a
security hole is found from one part.

Some things you can do more:

 * Allocate each user their own UID and GID (see <UserIds.txt>)
 * Use a separate /dovecot-auth/ user for authentication process (see
   <UserIds.txt>)
 * You can chroot authentication and mail processes (see <Chrooting.txt>)
 * Compiling Dovecot with garbage collection ('--with-gc' configure option)
   fixes at least in theory any security holes caused by double free()s.
   However this hasn't been tested much and there may be problems.
 * There are some security related SSL settings (see
   <SSL.DovecotConfiguration.txt>)
 * Set 'first/last_valid_uid/gid' settings to contain only the range actually
   used by mail processes

(This file was created from the wiki on 2019-06-19 12:42)