OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: pop-before-smtp qpopper support
From: Greg A. Woods (woodsweird.com)
Date: Fri Jun 09 2000 - 01:20:36 CDT


[ On Thursday, June 8, 2000 at 21:38:21 (-0400), Bennett Todd wrote: ]
> Subject: Re: pop-before-smtp qpopper support
>
> As you say, you don't have to open up portmapper --- but even if you
> had to open it, you'd only have to open it to machine[s] where you
> are running pop/imapds. If you're able to use pop-before-smtp, then
> you probably don't need to open up portmapper to anything off the
> server, so DRAC really isn't that much awfuller.

The WHOSON server has built-in support for controlling which clients it
allows to connect, and since it's just a single TCP or UDP service it's
very easy to firewall with any kind of packet-filter too. It works just
as well in single-server systems (with UNIX sockets) as it does in
clusters. It'll also cache a specified number of entries for a
specified time if your auth server isn't capable of deleting them upon
"logout".

-- 
							Greg A. Woods

+1 416 218-0098 VE3TCP <gwoodsacm.org> <robohack!woods> Planix, Inc. <woodsplanix.com>; Secrets of the Weird <woodsweird.com>