Hello all, I've been monitoring this list for a bit watching for updates
and waiting for the release of 1.18.
Another option, that we chose to do here is to use ipsec between our
perdition box and our imap boxes. We also use ipsec between our web mail
boxes and the perdition box.
We use SSL (port 993) between our clients and the perdition box and SSL
(port 443) on the web mailers. It's worked very well for us so far.
We also think our server subnet is pretty secure but frankly you just
never know what will occur. We'd been running the setup for a while now
but only started enforcing it for all of our users recently. It works
well for us.
Clark
Vincent Fox wrote:
I work in the UC Davis Data Center we have about
70K users plus or minus a few hundred.
When more than a couple of systems end up getting attached
to your "private" network, at some point you will have
to do a LENGTHY investigation when some system
you didn't even know about, gets hacked and then the
security folks wonder whether 70K users could have
had their passwords sniffed. Let's not get into proper
security practice discussion, if you work in a Data Center
you know you have enough systems something will go
wrong or maybe you'll just get hit with a 0-day sploit.
Things do go wrong and I prefer to not trust anything
will take advantage of any layers of security handy.
IMO plaintext is not worth the trouble. I like the added security
of being able to say "I didn't trust the network" because
sometimes you really can't unless it's a one-man show
with a handful of systems.
If you are not using this in a big shop and do not
have these problems then by all means. I can tell you
from running Perdition in this mode, the CPU on our
4 Perdition frontends are barely ticking over at load peak
of MAYBE 0.2 during the Fall quarter rush. Our frontends
are nothing exciting really just some COTS 1U Opterons.
We use internally generated certs for Perdition to backend
mail-store and that is no big deal to set up.
It is very nice having Perdition in the front, we can migrate
users around in the backend to all kinds of mail-stores Exchange
or Cyrus or whatever, it's transparent. We just update the record
in LDAP as to what backend they are stored on.
I just wish Perdition had GSSAPI support.
______________________________________________
Perdition-users mailing list
Perdition-users(a)vergenet.net
http://lists.vergenet.net/listinfo/perdition-users
--
____________________________________
Clark W. Coffman - System Admin - EduTech (education technology services)
North Dakota State University - 1320 Albrecht Blvd, IACC 218D
Clark.Coffman(a)Sendit.Nodak.Edu
Work: 701-231-8825 - Fax: 701-231-8541
Hamster: Whack!!
Rabbit: Did you just whack me with a carrot? ...
Hamster: Whoa! Oh boy!!
------------------------------------