OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Another change to smtp_sasl_auth.

From: Victor Duchovni (Victor.DuchovniMorganStanley.com)
Date: Wed Nov 21 2007 - 14:56:02 CST


On Wed, Nov 21, 2007 at 08:13:19PM +0000, Keean Schupke wrote:

> Okay, that gives me a two step development program for this feature.
>
> 1) implement verify using gateway/user/pass hashes to cache failures.
>
> 2) extend the verify service to allow using a database backend. As we
> know the approximate password update frequency (say monthly new
> passwords) setting a cache time of 2-3 months would stop the database
> growing in size indefinitely.

Verify already uses a database as a backend, but it is effectively
Berkeley DB only. No support for SQL at this time.

> I think even just (1) gives useful functionality, so I will submit a
> patch for review at this stage, before going on to (2).

Even (1) is esoteric enough that I am not sure it should be adopted.

Will anyone else need such a feature? It is a hack to work around "titanic
bureaucracy", and questionable overloading of services designed to serve
entirely different goals.

Is account lock-out a common behaviour for SOHO email submission via ISP
outbound hosts? Is using the verify service in this way a reasonably
useful safety mechanism for SOHO users or a single-site feature?

--
        Viktor.

Disclaimer: off-list followups get on-list replies or get ignored.
Please do not ignore the "Reply-To" header.

To unsubscribe from the postfix-users list, visit
http://www.postfix.org/lists.html or click the link below:
<mailto:majordomopostfix.org?body=unsubscribe%20postfix-users>

If my response solves your problem, the best way to thank me is to not
send an "it worked, thanks" follow-up. If you must respond, please put
"It worked, thanks" in the "Subject" so I can delete these quickly.