Re: *panic* Open relay question..?

From: Wietse Venema (no email)
Date: Mon Apr 01 2002 - 12:45:42 EST


Bill Landry:
> :
>
> >If you list check_sender_access under smtpd_recipient_restrictions,
> >an OK or RELAY result in that access table means OK for the recipient.
> >
> >If you don't want that to happen, then don't list check_sender_access
> >under smtpd_recipient_restrictions.
> >
> >List it under smtpd_sender_restrictions instead.
>
> Wietse, it looked like you were responding to me, and I was a bit confused
> by your response, so I wanted to clarify for my own understanding. Maybe I
> misunderstood, but in practice it also seems to mean OK for the sender. I
[...]
> smtpd_recipient_restrictions =
> reject_unauth_pipelining,
> permit_mynetworks,
> reject_unauth_destination,
> check_recipient_access hash:/etc/postfix/recipient-rules,
> check_sender_access hash:/etc/postfix/sender-rules,
> check_helo_access hash:/etc/postfix/hostname-rules,
> reject_invalid_hostname,
> reject_unknown_sender_domain,
> reject_unknown_recipient_domain,
> reject_maps_rbl,
> permit

And indeed, when the sender matches hash:/etc/postfix/sender-rules
with an OK rule, then the recipient is accepted.

        Wietse
-
To unsubscribe, send mail to with content
(not subject): unsubscribe postfix-users








Hosted Email Solutions

Invaluement Anti-Spam DNSBLs



Powered By FreeBSD   Powered By FreeBSD