<authentication>plain</authentication>
<!-- TODO Backend doesn't seem to be so differentiated, or does it automatically.
The UI and IDL API only knows "secure" auth on/off, whatever "secure" may mean. So, allowed values for now:
plain, secure
<!-- Could be: anonymous, plain, login, CRAM-MD5, DIGEST-MD5, KerberosV4, GSSAPI (Kerberos v5),
-->
<pop3>