OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: the purpose of smtpd_sasl_authenticated_header

From: Udo Rader (udo.raderbestsolution.at)
Date: Tue May 02 2006 - 15:01:43 CDT


Am Dienstag, den 02.05.2006, 21:35 +0200 schrieb Ralf Hildebrandt:
> * Udo Rader <udo.raderbestsolution.at>:
> > Hi,
> >
> > as we are currently testing 2.3 I would like to know the rationale
> > behind smtpd_sasl_authenticated_header.
> >
> > On one hand I find the flag useful for tracing purposes, but on the
> > other hand I already see hordes of script kiddies/spammers harvesting
> > the login names for brute force attacks.
> >
> > So what's the idea behind it?
>
> # postconf -d smtpd_sasl_authenticated_header
> smtpd_sasl_authenticated_header = no
>
> The idea is to activate it if YOU think it's useful.

yes, that is quite obvious, I am in control of any parameter, but I
would like to know what's the idea behind it.

If I was to setup a completely new, state of the art etc. server, (why)
would I enable it?

Udo Rader

--
BestSolution.at EDV Systemhaus GmbH
http://www.bestsolution.at

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQBEV7qnuhFd84GLxP8RAip0AKCGNA9PzFtegeI0EgOUto9evx7gawCggHBc
3z09ltAQKI5sV75z1ReMOgs=
=YbO6
-----END PGP SIGNATURE-----