OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Postfix - remote controll (Diploma thesis)

From: David Cary Hart (PostfixMTATQMcube.com)
Date: Wed Aug 02 2006 - 13:23:46 CDT


On Wed, 2 Aug 2006 11:16:13 -0700, "Sheldon T. Hall"
<pftandem.artell.net> opined:
> This is certainly possible. Whether it is beneficial would be
> harder to determine.
>
> There are two things agsint which you'd have to guard; one is
> simple, one is much more difficult:
>
> Security - You would have to prevent unauthorized persons from
> making changes to the mailserver configuration.
>
> Operations - You would have to be sure that any change made by
> this method did not disable the mail system, or cause it to reject
> or ignore future reconfiguration messages. This could be fairly
> diffiult.
>
> One further consideration: Some Postifx main.cf configuration
> information is easy to change, using 'postconf -e', because the
> order of the parameters doesn't matter. Some other parts of
> main.cf, however, are sensitive to parameter order, and modifying
> them programatically would be more difficult.
>
> Although I am generally inclined towards automation and remote
> control of server processes, I'm not sure that e-mail is the proper
> way to achieve that in this particular case.
>
> -Shel
>
If I understand the question correctly, this is RC by email. I do
this for whitelisting using Swatch and warn of the subject line.
When swatch sees the pattern it triggers a script to modify (in this
case) access and then runs postmap.

--
Our DNSRBL - Eliminate Spam at the Source: http://www.TQMcube.com
               Don't Subsidize Criminals: http://boulderpledge.org