OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: alias management -- suggestions and best practices

From: Kurt Lieber (kurt.liebergmail.com)
Date: Sat Jan 28 2006 - 06:23:54 CST


On 1/27/06, Victor Duchovni <Victor.Duchovnimorganstanley.com> wrote:
> This allows any user to redirect (steal) mail from any other user.

It could be abused for this, yes. However, creating new aliases is
limited to superusers...regular users are merely able to edit existing
aliases within a set of directories that we specify. Sensitive
aliases (like postmaster, abuse, etc.) are placed in another directory
that has tighter permissions. Sorry if I didn't make this clear in my
original email.

> Postfix has no such system. You can build one or more consolidated aliases files
> in fixed locations using whatever secure or insecure logic you see fit.

OK, fair enough. We may also look at placing the aliases in ldap.
Not sure yet, but thanks for the help.

--kurt