OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Postfix Archives: Re: 2 SMTP Relays, depending on the From: add

Re: 2 SMTP Relays, depending on the From: address


Subject: Re: 2 SMTP Relays, depending on the From: address
From: Craig Sanders (castaz.net.au)
Date: Mon Jan 03 2000 - 18:04:13 CST


On Tue, Jan 04, 2000 at 12:35:40AM +0100, Martin Schulze wrote:
> > sorry, but it IS a brain-damaged implementation. relay control should be
> > by IP address, not by domain name in the From: address. i.e. local IP
>
> What happens if you can't (or don't want) to afford more machines?

huh? you don't need two machines to run two instances of postfix.

in any case, the brain-damagedness that i'm referring to is not your
setup/workaround. the stupidity is in using the From: domain for relay
control.

> I.e. finlandia.infodrom.north.de == finlandia.infodrom.org == stachel.de
> kuolema.infodrom.north.de == kuolema.infodrom.org
> carelia.infodrom.north.de == carelia.infodrom.org
>
> I don't want to run two big servers and don't walk around with two
> laptops just because the MTA is too stupid to implement source
> based routing.

you can run multiple instances of postfix on one machine, each with a
different config file and spool directory.

> You forgot that I MUST NOT use the non-commercial leased line for
> ANY commercial activities. Thus uucp over tcp would be technically
> possible but is not a legal solution. Anyway, you will still need
> to split outgoing mail by policy, i.e. commercial -> uucp, non-commercial
> using smtp.

show me *any* MTA which can distinguish between commercial and
non-commercial email.

probably the best you can do is use a transport map to send mail for
particular domains via your non-commercial link and mail for everything
else via your commercial link.

non-technical problems generally aren't all that amenable to technical
solutions. you'll have to kludge it and occasionally there will be
mistakes. excrement occurs.

> > if you can find a uucp provider who uses stunnel or similar to allow
> > ssl encrypted uucp connections. see http://taz.net.au/postfix/uucp/
> > for an example of how to set this up (a howto on setting up uucp with
> > stunnel...it assumes you already know taylor uucp reasonably well).
>
> You're hopelessly missing the point, sorry.

hey, it was you who mentioned uucp as a possible solution. i just
provided some extra information on a way of making uucp over tcp more
secure.

i don't know about your situation - if a solution isn't viable for you
then you shouldn't suggest it.

craig

--
craig sanders



This archive was generated by hypermail 2b27 : Mon Jan 03 2000 - 18:05:49 CST