OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: José Luis Tallón (jltallonadv-solutions.net)
Date: Wed Jul 03 2002 - 15:00:09 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    At 20:40 3/07/2002 +0200, you wrote:
    >On Wed, Jul 03, 2002 at 08:52:17PM +0200, Thomas -Balu- Walter wrote:
    >
    > > > Unless you try SASL.
    > >
    > > The only daemon using SASL would be smtpd?
    >
    >Yup. Now, if Wietse conceives the "policy" daemon, only THAT would
    >need SASL. And since it isn't exposed to the network, NOT chroot()ing
    >it doesn't hurt that much.
    >
    >Neat!

    Neat approach, yes

    > > So to have SASL supported (without having to put everything needed into
    > > chroot) I only have to unset chroot for smtpd in master.cf?
    >
    >Yes.

    Well... I needn't un-chroot() anything in my setup to get everything working...
    SASL -> PAM -> MySQL( via loopback TCP/IP ) [ or whatever you like,
    provided it doesn't try to read anything outside the jail.. ] LDAP or the
    like would work also :)

    >--
    >Ralf Hildebrandt (Im Auftrag des Referat V A) Ralf.Hildebrandtcharite.de
    >Charite Campus Virchow-Klinikum Tel. +49 (0)30-450 570-155
    >Referat V A - Kommunikationsnetze - Fax. +49 (0)30-450 570-916
    >Serious error.
    >All shortcuts have disappeared.
    >Screen. Mind. Both are blank.
    >
    >-
    >To unsubscribe, send mail to majordomopostfix.org with content
    >(not subject): unsubscribe postfix-users

    -
    To unsubscribe, send mail to majordomopostfix.org with content
    (not subject): unsubscribe postfix-users