OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: How to match SASL logged user and MAIL FROM address.

From: Truong Tan Son (sonttfcv.fujitsu.com)
Date: Wed Jun 01 2005 - 23:21:37 CDT


Dear Sir,

It's ready exist two field on "smtpd_sasl_login_maps" file and postmap this file

userXXtest.com userXX
userYYtest.com userYY
...

Please allow me to narrow this problem:

Now, in my LAN, if user has SASL authen, he can fake MAIL FROM of someone to send mail to all
staffs.

Because this matter, I want to fix:

SASL user = userAtest.com then MAIL FROM = userAtest.com

If MAIL FROM = userBtest.com on this case, the server must reject this message

What should I do ?

Regards,

> On Thu, Jun 02, 2005 at 11:02:04AM +0700, Truong Tan Son wrote:
>
>> Mail server rejects immediately, with notice:
>>
>> ..:Sender address rejected: not owned by user, ..
>>
>> ( In fact, that users already permit on server )
>>
>> Can't put "reject_sender_login_mismatch" *before*
>> "permit_sasl_authenticated"
>>
>
> Isn't that what you wanted (disallow mail unless login owns sender
> address)? What is in your smtpd_sasl_login_maps?
>
> Please explain your problem as clearly as you can.
>
> --
> Viktor.
>
> Disclaimer: off-list followups get on-list replies or get ignored.
> Please do not ignore the "Reply-To" header.
>
> To unsubscribe from the postfix-users list, visit
> http://www.postfix.org/lists.html or click the link below:
> <mailto:majordomopostfix.org?body=unsubscribe%20postfix-users>
>
>