OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: URGENT suggestion to FAQ 19991231-pl09
From: Matthias Andree (madt.e-technik.uni-dortmund.de)
Date: Mon Sep 18 2000 - 04:33:51 CDT


wietseporcupine.org (Wietse Venema) writes:

> Postfix, as released by me, runs no daemons chrooted.
>
> The problem is that every system needs different files in order to
> run chrooted, so the information in a general FAQ is not very useful
> except for explaining that running chrooted is complicated.

That is true, and proper documentation on setting up chroot()
environments is hardly available. It usually boils down to sending
things to a chroot, running some sort of syscall+libcall tracer and grep
for failed open and stat calls.

But that is _exactly_ what it is meant for: Have people look into their
master.cf, and if they are asking for help, report that they run things
chrooted and paste the output of `ls /var/spool/postfix/{etc,lib}' along
with their master.cf file and `postconf -n' output. And that people see
if it works if they switch the chroot off.

> The best suggestion I have to distributors is to ship Postfix such
> that it actually works out of the box (whether chrooted or not).

Things start to get ugly if a distributor changes the setup without
documenting that properly, or if a configuration tool is provided that
gets in the way. SuSEconfig still must not configure my mail
configuration anywhere for that reason, though it may have improved
since I last tried it one year ago, not to speak of the linuxconf
"configuracide" (massacres).

-- 
Matthias Andree