Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20030817000114.GA11307@openwall.com>
Date: Sun, 17 Aug 2003 04:01:14 +0400
From: Solar Designer <solar@...nwall.com>
To: popa3d-users@...ts.openwall.com
Subject: Re: Built In SSL Support

On Tue, Aug 12, 2003 at 03:31:26PM +1000, Daniel wrote:
> Are there any plans to progress popa3d with inbuilt support for SSL?

Yes, that's been on TODO for a long time now.  I don't agree with your
assertion that this is crucial, but I do see several reasons why SSL
support in popa3d would be preferred over stunnel:

- standalone mode with its session count limits (including per source
address), slightly smaller overhead, and consistent logging (this is
also helpful for POP-before-SMTP);

- the potential to support STARTTLS in addition to pop3s (but is there
any client which supports STARTTLS and not pop3s?);

- pop3s would be supported on OpenBSD out of the box (stunnel will
hardly ever get into their base tree).

Of course, implementing SSL support into popa3d would require that any
calls into OpenSSL are done from another forked process with reduced
privileges.

I don't know when I might get around to doing that.  It will
definitely not happen soon unless some company would want to sponsor
that work.  Meanwhile, stunnel should be fine for most uses.

-- 
Alexander Peslyak <solar@...nwall.com>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598
http://www.openwall.com - bringing security into open computing environments

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.