• The APS Catalog has been deprecated and removed from all Plesk Obsidian versions.
    Applications already installed from the APS Catalog will continue working. However, Plesk will no longer provide support for APS applications.
  • Please be aware: with the Plesk Obsidian 18.0.78 release, the support for the ngx_pagespeed.so module will be deprecated and removed from the sw-nginx package.

Issue password encryption for mail users and roundcube error log

Jens Johansson

Basic Pleskian
Hi there,

i use CentOS 7.2 with Plesk 12.5 MU#52

I have found the PLAIN TEXT password for mail_users in:
/usr/local/psa/admin/bin/mail_auth_view and in /var/log/plesk-roundcube/errors!

/usr/local/psa/admin/bin/mail_auth_view
Authentication database contents:
+--------------------------------------+-----+--------------------------------------+
| address |flags| password |
+--------------------------------------+-----+--------------------------------------+
| info@naeh | | PASSWORD in PLAIN TEXT |
| info@naeh | | PASSWORD in PLAIN TEXT |


cat /var/log/plesk-roundcube/errors
[04-Nov-2016 21:46:16 +0000]: <975ij0pc> IMAP Error: Login failed for info@naeh-******.de from **.90.**.**(X-Real-IP: **.90.***.***). AUTHENTICATE CRAM-MD5: A0001 NO Login failed. in /usr/share/psa-roundcube/program/lib/Roundcube/rcube_imap.php on line 193 (POST /roundcube/?_task=login&_action=login)
#2 /usr/share/psa-roundcube/index.php(118): rcmail->login('info@naeh-****...', 'PASSWORD in PLAIN TEXT', 'localhost', true)

1) It´s not a migration from other server!
2) How can i force password encryption"Flag E"?
3) Why does logged roundcube passwords in PLAIN TEXT !?

Many thanks in advance


Erik
 
Back
Top