[feature request] IMAP always uses PLAIN authentication [released]
adding an email account only has the option auth method (e.g encrypted pw) for smtp, imap always uses plain text auth.
We have moved to a new Sailfish OS Forum. Please start new discussions there.
adding an email account only has the option auth method (e.g encrypted pw) for smtp, imap always uses plain text auth.
Fixed in 1.1.2 / Yliaavanlampi, now the auths are selected according to the advertised capabilities, from more secure to less secure, supported auths are:
XOAUTH2 for google accounts
CRAM-MD5, PLAIN, LOGIN for general IMAP/SMTP accounts.
wait, do you mean that until now all IMAP connections sent the password in clear text?
I checked my mail over some unencripted holtel wifi networks while travelling knowing that the IMAP servers I used all provided strong authentication (IMAP SSL).
https://wiki.gandi.net/en/mail/standard-settings?s[]=imap#popimap_account
Did my IMAP passwords travel in clear text then? I'm sure the port configured in Mail was 993, the one of IMAP SSL.
Now I have the phone at Optima for warranty repair, so I can't double check (but I did a full /home/nemo backup, if you tell me where I can look)
Thank you
c.la ( 2015-03-03 17:19:03 +0300 )edit@VDVsx thank you for your reply. I still don't get how you can block the transmission of PLAIN (if I remember it's equivalent to not encrypted) authentication over an unencrypted channel, because after all even 3G connection is unencrypted, not just an open wifi network.
Thank you
c.la ( 2015-03-04 15:13:44 +0300 )editLike I said above authentication does not process until a SSL/TLS socket is open between server and device, if you want more details check the IMAP RFCs on that, and as I said when available we use even stronger methods like app token or MD5, but most servers don't support those.
VDVsx ( 2015-03-04 15:31:12 +0300 )editThis thread is public, all members of Together.Jolla.Com can read this page.
Asked: 2014-02-28 12:56:09 +0300
Seen: 351 times
Last updated: Mar 03 '15
IMAP IDLE / IMAP Push for the E-Mail app [released]
Bug: E-Mail synchronization does not work as configured [released]
A way to specify sender's name and e-mail in Google (and IMAP) account [released]
HowTo: temporarily fix the erratic email syncing problem [released]
email: cannot log in to MacOS IMAP server [released]
[Bug] Unable to force email check
Possibility to choose which IMAP folders to show in the mail app
We don't support anything else at the moment, this is not a bug, please change this to a feature request specifying the options you would like to see.
VDVsx ( 2014-03-03 10:51:01 +0300 )editCorrection we do support oauth2 as well for IMAP4 login, and CRAM-MD5 is coming.
VDVsx ( 2014-03-03 10:54:26 +0300 )editthanks for feedback, changed it, but nevertheless I think it's an usability bug.
kelvan ( 2014-03-04 20:47:30 +0300 )editIt's confusing to see the method at the end, but not in the IMAP section.
It isn't that obvious if the selection is for smtp or smtp+imap
CRAM-MD5 login on IMAP4 is still not supported (1.1.0.39) and the manual change of account settings described in (1) seems not to be working anymore.
Would CRAM-MD5 login on IMAP4 will be included sooner or later ?
(1) https://together.jolla.com/question/4336/email-cannot-log-in-to-macos-imap-server/
drno ( 2014-10-26 14:33:37 +0300 )editYes, at some point.
VDVsx ( 2014-10-28 09:04:26 +0300 )edit