• The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Issue password encryption for mail users and roundcube error log

ESTUGO

Basic Pleskian
Hi there,

i use CentOS 7.2 with Plesk 12.5 MU#52

I have found the PLAIN TEXT password for mail_users in:
/usr/local/psa/admin/bin/mail_auth_view and in /var/log/plesk-roundcube/errors!

/usr/local/psa/admin/bin/mail_auth_view
Authentication database contents:
+--------------------------------------+-----+--------------------------------------+
| address |flags| password |
+--------------------------------------+-----+--------------------------------------+
| info@naeh | | PASSWORD in PLAIN TEXT |
| info@naeh | | PASSWORD in PLAIN TEXT |


cat /var/log/plesk-roundcube/errors
[04-Nov-2016 21:46:16 +0000]: <975ij0pc> IMAP Error: Login failed for info@naeh-******.de from **.90.**.**(X-Real-IP: **.90.***.***). AUTHENTICATE CRAM-MD5: A0001 NO Login failed. in /usr/share/psa-roundcube/program/lib/Roundcube/rcube_imap.php on line 193 (POST /roundcube/?_task=login&_action=login)
#2 /usr/share/psa-roundcube/index.php(118): rcmail->login('info@naeh-****...', 'PASSWORD in PLAIN TEXT', 'localhost', true)

1) It´s not a migration from other server!
2) How can i force password encryption"Flag E"?
3) Why does logged roundcube passwords in PLAIN TEXT !?

Many thanks in advance


Erik
 
Back
Top