From 58d11757d242fbdc525c491873e0366ff82b37c1 Mon Sep 17 00:00:00 2001 From: kink Date: Thu, 8 Jun 2006 15:53:54 +0000 Subject: [PATCH] include note about password security in security doc git-svn-id: https://svn.code.sf.net/p/squirrelmail/code/trunk/squirrelmail@11186 7612ce4b-ef26-0410-bec9-ea0150e637f0 --- doc/security.txt | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/doc/security.txt b/doc/security.txt index fe20e6af..e6eff624 100644 --- a/doc/security.txt +++ b/doc/security.txt @@ -23,6 +23,12 @@ further improve the security of your webmail system. IMAP server. Note that this makes no sense if both are on the same machine. See doc/authentication.txt for info. +- config.php. Some options in conf.pl / config.php allow for passwords to + be set in that file, e.g. the addressbook/preferences DSN, and LDAP + addressbooks. When setting a sensitive password, check that config.php + is not readable for untrusted system users, and consider the possibility + of it being read by other users of the same webserver. + - Subscribe to the squirrelmail-announce mailinglist to be informed about new releases which may fix security bugs. If you run SquirrelMail packaged by your distribution, make sure to apply their security upgrades. -- 2.25.1