OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: bare user names and {dk,sid}-milter

From: Tony Earnshaw (tericssonearnshawbarlaeus.nl)
Date: Tue Aug 01 2006 - 11:50:52 CDT


ty den 01.08.2006 Klokka 16:59 (+0200) skreiv Mark Martinec:

> > ty den 01.08.2006 Klokka 10:46 (+0200) skreiv Mark Martinec:
> > > On Tuesday August 1 2006 08:17, Tony Earnshaw wrote:
> > > > ps aux | grep dk-filter
> > > > root 31123 0.0 0.1 46392 1644 ? Ssl Jul26
> > > ^^^^
> > > > 0:05 /usr/bin/dk-filter -l -p inet:10003 ...
> > >
> > > A brave soul!
>
> > Hmmm ...
> > ps auxwww|grep dk-
> > postfix 14702 0.0 0.0 14284 1160 ? Ssl 11:35
> ^^^^^^^
> > 0:00 /usr/bin/dk-filter -l -p inet:10003 -d barlaeus.nl -
> > s /etc/certs/dk-filter/mail.private.pem -S mail -C dnserror=tempfail -u
> > postfix -H -D
> >
> > Seems to work, still signs mail ... now I'll have to change all my rpm
> > stuff, bother.
>
>
> http://www.postfix.org/MILTER_README.html :
>
> | To run a Milter application, see the documentation of the filter for
> | options. A typical command looks like this:
> | # /some/where/dk-filter -u userid -p inet:portnumberlocalhost ...
> | Please specify a userid value that isn't used for other applications
> | (not "postfix", not "www", etc.).
> ^^^^^^^^^^^^^

Okok ..

1075 [root:mercurius.intern] /etc/sysconfig # ps aux |grep dk-

milter 6422 0.0 0.0 15376 1160 ? Ssl 18:41
0:00 /usr/bin/dk-filter -l -p inet:10003 -d barlaeus.nl -
s /etc/certs/dk-filter/mail.private.pem -S mail -C dnserror=tempfail -u
milter -H -D

"Nu is het welletjes" as they say here in Holland, "No kan det vera nok"
in my homeland. I absolutely refuse to add a new milter user for each
milter application I add; I'm amenable to every security push I get,
until things begin to get ridiculous.

Thanks again (dunno what we'd do without amavisd.new 2.4)

--Tonni

--
Tony Earnshaw
tonni at barlaeus.nl