OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: POP-before-SMTP overrides evertyghing else
From: Ralf Hildebrandt (Ralf.Hildebrandtinnominate.de)
Date: Wed May 17 2000 - 08:57:49 CDT


On 17 May 2000 15:28:06 +0200, Mailing List Account <mlistsohoweb.net> wrote:

>I am using DRAC to provide POP-before-SMTP capability on my postfix server.
>However, I want anyone who passes the POP-before-SMTP check to bypass all
>other checks -- except header/virus checks. Right now, the MAPS DUL check

Those come last anyway.

>is keeping properly authenticated users (who connect using AOL) from sending.
>
>smtpd_client_restrictions =
> permit_mynetworks,
> check_client_access
>hash:/etc/postfix/access,
> reject_maps_rbl,
> reject_unauth_pipelining
>
>smtpd_sender_restrictions =
> permit_mynetworks,
> check_sender_access
>hash:/etc/postfix/access,
> reject_unknown_sender_domain,
> reject_maps_rbl
>
>smtpd_recipient_restrictions =
> permit_mynetworks,
> permit_mx_backup,
> check_client_access
>hash:/etc/mail/dracd,
> check_relay_domains
>
>
>Do I just need to add
> check_client_access
>hash:/etc/mail/dracd,
>To the top two sections, above the maps_rbl line?

Yes, the first match wins (like in IPCHAINS)

-- 
Ralf.Hildebrandtinnominate.de
                                                          innominate AG
                                                      networking people
fon: +49.30.308806-44 fax: -77  web: http://innominate.de  pgp: /pgp/rh