Re: Postfix error checking (Was *panic* Open relay ...)

From: Liviu Daia (no email)
Date: Mon Apr 01 2002 - 17:00:46 EST


On 1 April 2002, <> wrote:
>
> On Tue, 2 Apr 2002, Liviu Daia wrote:
>
> > That won't work as long as some files / sockets / whatever
> > associated to maps are opened before going into the chroot jail
> > while others are opened (not necessarily by Postfix --- think MySQL)
> > after that operation.
>
> It does not have to catch all problems, it just has to be useful. If
> the map checks are part of "postfix validate" rather than "postfix
> check" false positives for error conditions are OK.

    IMO, a "postfix validate" should actually do what is says: validate
the config. IOW, it should be 100% accurate. The utility you suggest
is simply too fragile --- it would both generate false positives and
miss real problems (f.i. for reasons related to permissions).

    Also, how often do you change the map _paths_?

[...]
> The "postconf" variable expansion issue is I believe the
> main obstacle to success: all my DB maps are specified as
> btree:$config_directory/filename.
>
> The postmap and postfix-script changes would be simple.

    Yes, Wietse already pointed that out.

    Regards,

    Liviu Daia

-- 
Dr. Liviu Daia               e-mail:   
Institute of Mathematics     web page: http://www.imar.ro/~daia
of the Romanian Academy      PGP key:  http://www.imar.ro/~daia/daia.asc
-
To unsubscribe, send mail to  with content
(not subject): unsubscribe postfix-users







Hosted Email Solutions

Invaluement Anti-Spam DNSBLs



Powered By FreeBSD   Powered By FreeBSD