OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Postfix article in Free Software Magazine

From: Matt Fretwell (mattfbauchan.org)
Date: Fri Mar 04 2005 - 11:35:38 CST


Kirk Strauser wrote:

> > The smtpd_helo_restrictions are not final, they are followed by
> > smtpd_sender_restrictions and smtpd_recipient_restrictions.
>
> That was my understanding. Thanks for confirming this - I had a minor
> panic attack when I read Rob's mail.

 I admit, the way it was phrased did make Rob's reply sound like you were
an open relay :) However, Rob's snippet below:

> > you missed the opportunity to explain DUNNO in access maps, and give
> > an example that is an open relay to any host identifying itself as
> > woozle.

 I think he meant, I may be wrong, that you didn't give an example of how
NOT to use helo checks under recipient restrictions in a way that would
make the system an open relay. I don't know if that sounds any clearer :)

 But, seeing as you use the same method as I, and put restrictions under
their respective classes, it would be somewhat irrelevant to your specific
howto.

All the best,

Matt