Gordano Knowledge Base
Article Q0199

What is APOP authentication?

Question Background:
What is APOP?
Am I able to configure this type of authentication in GMS?

Answer:
If you have validated your UserID and Password against the POP3 server without using authentication, this does not give 100% protection against hackers who use programs that "sniff" passwords. The reason this is not secure is because the password is sent across in plain text format.

APOP (Authenticated POP) is an extension of the standard POP3 protocol. Authenticating to a POP server will mean your userid and password are both encrypted by the client before being passed "over the Internet".
The receiving server must then be able to decrypt the password.

If you are using an emulator such as Telnet to establish a POP connection, it is easy to determine if APOP has been enforced.
In addition to the standard greeting..."+OK POP3 server ready", additional information is provided, such as...
+OK POP3 server ready <13541519300002@test.dom>

Using the options in Security > Connections you may:

  1. Disallow people from using APOP.
  2. Allow anyone to use APOP.
  3. Require everyone to use APOP.

APOP is not available for NT User Database accounts or accounts managed via the Authentication DLL.

For more information please see: NTMail Administrators Guide sections 10.1 & 12.4.

Bookmark this KB:
Feedback:
Did this article answer your question? Yes No
Applicable to version(s): 4 and later
Last updated: 16-Sep-2002
Key Words: APOP, security, authentication, POP
Email this article to:
 
To Print this article hold down the control key and press 'P' on your keyboard.
On a Mac, hold down the Apple key and press 'P'
divclear
Log in to
Gordano Support
System
Customer Ref:
EMail:
Password:


- Forgot your password? click here for help.






  © Copyright 1994 - 2010 Gordano Limited Privacy