From owner-freebsd-questions@FreeBSD.ORG Mon Jan 26 12:31:19 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 7060416A4CE for ; Mon, 26 Jan 2004 12:31:19 -0800 (PST) Received: from fep19.tmt.tele.fi (tank-fep4-0.inet.fi [194.251.242.244]) by mx1.FreeBSD.org (Postfix) with ESMTP id 32B6B43D2D for ; Mon, 26 Jan 2004 12:31:17 -0800 (PST) (envelope-from reko.turja@liukuma.net) Received: from rekon ([62.71.30.51]) by fep19.tmt.tele.fi (InterMail vM.5.01.06.08 201-253-122-130-108-20031117) with SMTP id <20040126203113.HNCV13101.fep19.tmt.tele.fi@rekon>; Mon, 26 Jan 2004 22:31:13 +0200 Message-ID: <05c901c3e44b$576e4370$0a06a8c0@rekon> From: "Reko Turja" To: , "Jason Williams" References: <5.2.1.1.0.20040126105812.00a9c558@pop.courtesymortgage.com> Date: Mon, 26 Jan 2004 22:31:13 +0200 MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2800.1158 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165 Subject: Re: Question about Postfix + Cyrus-IMAPD X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 26 Jan 2004 20:31:19 -0000 ----- Original Message ----- From: "Jason Williams" To: > I've been able to get Postfix and Cyrus to gel correctly with my recent > testing. However, I have a question about one thing that continues to pop > up my my message logs. > > Jan 26 09:48:19 obsidian postfix/smtpd[6562]: OTP unavailable because can't > read/write key database /etc/opiekeys: Permission denied > > Anyone care to shed a little light as to why this was initially showing up? Cyrus (os SASL to be exact) tries to use OPIE as the loginmethod of choice. (It's more secure plaintext method as sending the "real" password over the net. Of course if you use TLS sending plaintext password is small concern. If you are not using/going to use OPIE there are several methods how to get rid of these messages. a) Just delete everything wchich name contains OPIE in usr/local/lib/sasl2/ b) Build SASL using the "WITHOUT_OTP=yes" knob In fact its a good idea to read through the main Makefile on the SASL directory in the ports and disable the unneeded athorisation methods using the port knobs. -Reko