Re: Relay control in qmail

From: Scott Gifford (sgifford_at_suspectclass.com)
Date: 11/05/03

  • Next message: Hal Flynn: "New SecurityFocus article"
    Date: Wed, 5 Nov 2003 14:36:37 -0500
    To: Felipe <felipe@saint-jean.cl>
    
    

    Felipe <felipe@saint-jean.cl> writes:

    > I's been a while since I installed my qmail but I belive the
    > configuration file for controling reliying is
    >
    > /etc/tcp.smtp
    >
    > mine looks like
    >
    > 127.0.0.1:allow,RELAYCLIENT=""
    > 192.168.1.:allow,RELAYCLIENT=""
    > :deny
    >
    > Meaning, that the default behaviour is to deny relaying, but accept
    > from localhost, 192.168.1.*

    That actually means the default behavior is to deny connections at
    all, whether they are for relaying or final delivery. That would be a
    sensible configuration on a relay-only machine with no local domains,
    but not on a system that does mail delivery.

    Using :allow instead of :deny would allow the connection but prevent
    relaying.

    The OP still hasn't posted any info about his configuration or why he
    thinks he's an open relay, but this is probably better handled on the
    qmail list anyways:

        http://cr.yp.to/lists.html#qmail

    A warning: do your homework before posting, or you will almost
    certainly be flamed.

    ---ScottG.


  • Next message: Hal Flynn: "New SecurityFocus article"

    Relevant Pages

    • Re: BUG IN APACHE HTTPD SERVER (current version 2.0.47)
      ... >How to return files in a Apache Deny All directory. ... The server administrator further ... the configuration comparing between two config ...
      (Bugtraq)
    • Re: userPrincipalName with IIS security?
      ... My next question is perhaps predictable - what object might have a DENY ACE ... The primary failure was of the OWA website, but the per-user configuration ... I see there's a 'permissions' menu option on the IIS 'default web ...
      (microsoft.public.inetserver.iis.security)
    • Re: SMTP strange behavior
      ... In your post you say that relaying is prohibited to this internal domain. ... configuration should be straightforward, ... the internal server allows. ... > server and SMTP gateway to my internal network. ...
      (microsoft.public.inetserver.iis.smtp_nntp)
    • Re: Ex2003 - SMTP Virtual Server - Connection and Relay restrictions
      ... If I deny an IP address from connecting, then I don't need to deny it from ... And if I do allow an IP address to connect, but deny it from relaying, then ... mail comes in from a single server such as a spam/AV filter. ... If I deny an IP> address from connecting, then I don't need to deny it from relaying also,> correct? ...
      (microsoft.public.exchange.admin)
    • 2003 and relaying
      ... configuration issue. ... server to disallow anonymous relaying allowing only my ... mobile clients the ability to relay off the 5.5 server. ... My users cannot relay through the server, ...
      (microsoft.public.exchange.connectivity)