OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: 2.2.8 + amavisd + postgrey

From: Bill Bradford (mrbillmrbill.net)
Date: Mon Feb 06 2006 - 11:09:33 CST


On Mon, Feb 06, 2006 at 12:06:05PM -0500, Victor Duchovni wrote:
> But, with permit_mx_backup this is rather non-trivial, because this
> is the negation of the restriction one really wants:
> - Old style: check_relay_domains or permit_auth_destination
> This is a "final" relay rights check, and fundamentally aAll
> UCE checks go into smtpd_client_restrictions, ...
> that recipient restrictions is about relay control only!
> - New style: reject_unauth_destination
> This filters out unauthorized relaying and allows relay authorized
> mail to be subjected to further scrutiny. This makes the "put
> everything in one place" approach possible.

So, in short, I should ditch permit_mx_backup, list all the domains I'm
backup MX for in relay_domains, and use reject_unauth_destination?

Bill

--
Bill Bradford
Houston, Texas