From: kink Date: Thu, 8 Jun 2006 15:53:54 +0000 (+0000) Subject: include note about password security in security doc X-Git-Url: https://vcs.fsf.org/?a=commitdiff_plain;h=58d11757d242fbdc525c491873e0366ff82b37c1;p=squirrelmail.git include note about password security in security doc git-svn-id: https://svn.code.sf.net/p/squirrelmail/code/trunk/squirrelmail@11186 7612ce4b-ef26-0410-bec9-ea0150e637f0 --- diff --git a/doc/security.txt b/doc/security.txt index fe20e6af..e6eff624 100644 --- a/doc/security.txt +++ b/doc/security.txt @@ -23,6 +23,12 @@ further improve the security of your webmail system. IMAP server. Note that this makes no sense if both are on the same machine. See doc/authentication.txt for info. +- config.php. Some options in conf.pl / config.php allow for passwords to + be set in that file, e.g. the addressbook/preferences DSN, and LDAP + addressbooks. When setting a sensitive password, check that config.php + is not readable for untrusted system users, and consider the possibility + of it being read by other users of the same webserver. + - Subscribe to the squirrelmail-announce mailinglist to be informed about new releases which may fix security bugs. If you run SquirrelMail packaged by your distribution, make sure to apply their security upgrades.