X-Git-Url: https://vcs.fsf.org/?p=squirrelmail.git;a=blobdiff_plain;f=doc%2Fsecurity.txt;h=e6eff624f67a30a2e70869f04fa50f2c691c1e41;hp=fe20e6afd05ef8f6ce3e955bf395e959445984be;hb=6872a6750379b6c17cf6a6dfec6150ade78f52a0;hpb=8c53808472ccfdb378e6054d177a75d9ca5cb142 diff --git a/doc/security.txt b/doc/security.txt index fe20e6af..e6eff624 100644 --- a/doc/security.txt +++ b/doc/security.txt @@ -23,6 +23,12 @@ further improve the security of your webmail system. IMAP server. Note that this makes no sense if both are on the same machine. See doc/authentication.txt for info. +- config.php. Some options in conf.pl / config.php allow for passwords to + be set in that file, e.g. the addressbook/preferences DSN, and LDAP + addressbooks. When setting a sensitive password, check that config.php + is not readable for untrusted system users, and consider the possibility + of it being read by other users of the same webserver. + - Subscribe to the squirrelmail-announce mailinglist to be informed about new releases which may fix security bugs. If you run SquirrelMail packaged by your distribution, make sure to apply their security upgrades.