OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
RE: 554 Client host rejected Access denied

From: Brian Carroll (BCarrollsecurenetdesigns.com)
Date: Tue Mar 04 2008 - 21:28:15 CST


> -----Original Message-----
> From: owner-postfix-userspostfix.org [mailto:owner-postfix-
> userspostfix.org] On Behalf Of Victor Duchovni
> Sent: Tuesday, March 04, 2008 10:16 PM
> To: postfix-userspostfix.org
> Subject: Re: 554 Client host rejected Access denied
>
> On Tue, Mar 04, 2008 at 10:09:21PM -0500, Brian Carroll wrote:
>
> > virtual_gid_maps = static:89
> > virtual_minimum_uid = 89
> > virtual_uid_maps = static:89
> >
> >
> > Also, if you see anything that seems incorrect in my config, feel
free
> > to point it out.
>
> DO NOT use the postfix uid/gid (89) as the owner of user mailboxes.
This
> uid should ONLY be used as the owner of the Postfix spool directories.

As I understand my config, Postfix is my LDA. I use Dovecot for
POP/IMAP. I thought I needed to have Postfix as the owner of the
mailboxes since it is LDA. If I change to a *different* (purpose
created?) user, how do I allow Postfix to then deliver the mail? Is
using Postfix as the LDA a no-no also?

Sorry of my questions seem uneducated. This is the first time I've built
something like this. I was hoping I was done but it seems there is more
cliff to scale in my learning.

>
> Use a *different* uid for POP/IMAP service and user mailboxes.
>
> --
> Viktor.
>
>

Brian Carroll