Hi all
To begin with, I am a little puzzled and I'm hoping some kind guru can advise. We are using the default webmail system on Plesk. I am told by support that the facility to change a password through webmail has been disabled, and that it is necessary for users to go in through Plesk to change passwords. I will return to that point later, but if, for example, a user has forgotten their password, how can they get it back or change it? The only way I can see is if the go to Plesk login and request password recovery. But if they can't get in to read their mail, how can they get their password?
I also have major concerns about letting users into Plesk, anyway. In my opinion, they should not be allowed to even see what has been set-up in there. A weak password would allow entry to anyone who could then set up mail groups (I assume, as that option seems available, though I haven't tried creating a group and mailing) and it wouldn't take them long to be using it as spam central.
As I said, support say that the only way to change a password in through Plesk as a security measure, but it seems an even bigger security hole to let users into a control panel area that can be abused. And if you've forgotten your password, how do you get in there in the first place? Yes, the user could contact me and ask me to reset it. But we have staff around the planet and I have no desire to get a phone call at 1am asking me to reset a password. And what if I happened to be away on holiday? They are stuck for a couple of weeks.
I do not doubt that I'm missing something here and I'm hoping that some kind soul will point it out.
Cheers
Ian
To begin with, I am a little puzzled and I'm hoping some kind guru can advise. We are using the default webmail system on Plesk. I am told by support that the facility to change a password through webmail has been disabled, and that it is necessary for users to go in through Plesk to change passwords. I will return to that point later, but if, for example, a user has forgotten their password, how can they get it back or change it? The only way I can see is if the go to Plesk login and request password recovery. But if they can't get in to read their mail, how can they get their password?
I also have major concerns about letting users into Plesk, anyway. In my opinion, they should not be allowed to even see what has been set-up in there. A weak password would allow entry to anyone who could then set up mail groups (I assume, as that option seems available, though I haven't tried creating a group and mailing) and it wouldn't take them long to be using it as spam central.
As I said, support say that the only way to change a password in through Plesk as a security measure, but it seems an even bigger security hole to let users into a control panel area that can be abused. And if you've forgotten your password, how do you get in there in the first place? Yes, the user could contact me and ask me to reset it. But we have staff around the planet and I have no desire to get a phone call at 1am asking me to reset a password. And what if I happened to be away on holiday? They are stuck for a couple of weeks.
I do not doubt that I'm missing something here and I'm hoping that some kind soul will point it out.
Cheers
Ian
Comment