OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: adding fetchmail to the mix?

From: Robert Felber (r.felberek-muc.de)
Date: Fri Oct 14 2005 - 08:55:07 CDT


On Fri, Oct 14, 2005 at 03:46:52PM +0200, Robert Felber wrote:
> On Fri, Oct 14, 2005 at 08:32:33AM -0500, S. Highlander wrote:
> > good afternoon all,
> >
> > question: i am wondering if my mail system would be a little more secure if
> > instead of forwarding mail from my gateway machine to my internal mail
> > server, i used a program like fetchmail on the internal mail server to pick
> > up mail from the gateway machine.
> >
> > i have an email gateway, named dmz, and an intranet mail server, named
> > internal, set up as described below. i set up both servers using
> > instructions from the following document:
> > http://www.postfix.org/STANDARD_CONFIGURATION_README.html#firewall .
>
> Why should a cleartext protocol (POP) be more secure than the option of
> forwarding mail from the gateway to internal vial SMTP TLS/SSL? Unless there
> are POP TLS/SSL implementations.

Ok, fetchmail supports SSL. However, I suppose setting up a POP daemon with
SSL suport is kind of overhead (using stunnel and the like).

But all in all - it would with no means ease thing or make things more
secure as they aleady are (supposed the existing transports are setup secure).

--
    Robert Felber (PGP: 896CF30B)
    Munich, Germany
--