How to avoid plaintext authentication for POP3 and IMAP?

Created:

2016-11-16 13:11:53 UTC

Modified:

2017-06-15 16:22:22 UTC

1

Was this article helpful?


Have more questions?

Submit a request

How to avoid plaintext authentication for POP3 and IMAP?

Applicable to:

  • Plesk 12.5 for Linux
  • Plesk 12.0 for Linux

Question

What are the methods to avoid plaintext authentication showing up for ports 143 and 110?

Answer

To disable plaintext authentication for POP3 and IMAP, use the following command:

# /usr/local/psa/admin/bin/pci_compliance_resolver --enable courier

To ensure PLAIN method is not shown for POP3 and IMAP, use the following commands:

# grep -v "#" /etc/courier-imap/pop3d | grep -v '^$' | grep AUTH
POP3AUTH="LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256"
POP3AUTH_ORIG="LOGIN CRAM-MD5 CRAM-SHA1 CRAM-SHA256"


# grep -v "#" /etc/courier-imap/imapd | grep -v '^$' | grep AUTH
IMAP_CAPABILITY="IMAP4rev1 UIDPLUS CHILDREN NAMESPACE THREAD=ORDEREDSUBJECT THREAD=REFERENCES SORT QUOTA AUTH=CRAM-MD5 AUTH=CRAM-SHA1 AUTH=CRAM-SHA256 IDLE"
IMAP_CAPABILITY_ORIG="IMAP4rev1 UIDPLUS CHILDREN NAMESPACE THREAD=ORDEREDSUBJECT THREAD=REFERENCES SORT QUOTA AUTH=CRAM-MD5 AUTH=CRAM-SHA1 AUTH=CRAM-SHA256 IDLE"
Have more questions? Submit a request
Please sign in to leave a comment.