OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: permit_sasl_authenticated in default recipient restrictions [Re: greets & howto local smtp + remote sasl smtp]

From: Victor Duchovni (Victor.DuchovniMorganStanley.com)
Date: Sat Feb 02 2008 - 01:44:24 CST


On Fri, Feb 01, 2008 at 11:04:23PM +0100, mouss wrote:

> wouldn't it be nice to make permit_sasl_authenticated part of the
> default settings?

Perhaps so, because "smtpd_sasl_auth_enable = no" is still the default.
So one would have to enable SASL auth first to accidentally allow SASL
users to relay by accident without first weeding out insecure logins, ...

Not sure whether the small convenience is worth the incompatibility.

> and while I am in, wouldn't it be good to allow
> smtpd_recipient_restrictions=
> to mean the default builtin setup?

Absolutely not. To use a default value, delete the setting from main.cf.

--
        Viktor.

Disclaimer: off-list followups get on-list replies or get ignored.
Please do not ignore the "Reply-To" header.

To unsubscribe from the postfix-users list, visit
http://www.postfix.org/lists.html or click the link below:
<mailto:majordomopostfix.org?body=unsubscribe%20postfix-users>

If my response solves your problem, the best way to thank me is to not
send an "it worked, thanks" follow-up. If you must respond, please put
"It worked, thanks" in the "Subject" so I can delete these quickly.