Re: trusted_host breaks pretty much every form of whitelist

2008-06-25 Thread Jo Rhett
On Jun 22, 2008, at 10:12 AM, Matt Kettler wrote: The only case an unlimited trust would be useful is if you trust the mail, even if the host relays mail from untrusted hosts. But if the sources are untrusted, why are you trusting the mail just because it came through some super-trusted

Re: trusted_host breaks pretty much every form of whitelist

2008-06-25 Thread Jo Rhett
On Jun 20, 2008, at 1:19 PM, Henrik K wrote: You should know by now what SA network settings do. I don't know how complex your setup really is for them not to work. It's not complex at all. Everything is external, there are no firewalls. All public IP space documented in the external

Re: trusted_host breaks pretty much every form of whitelist

2008-06-25 Thread Matus UHLAR - fantomas
On 25.06.08 01:29, Jo Rhett wrote: On Jun 22, 2008, at 10:12 AM, Matt Kettler wrote: The only case an unlimited trust would be useful is if you trust the mail, even if the host relays mail from untrusted hosts. But if the sources are untrusted, why are you trusting the mail just because

Re: trusted_host breaks pretty much every form of whitelist

2008-06-25 Thread Jo Rhett
On Jun 25, 2008, at 2:50 AM, Matus UHLAR - fantomas wrote: As described in previous e-mails, host A cannot talk to host C except to relay via host B. Host A is trusted if relayed by host B. (anything is trusted if relayed by host B) If Host A appears to be connecting to host C, then it's

Re: trusted_host breaks pretty much every form of whitelist

2008-06-25 Thread Matus UHLAR - fantomas
On Jun 25, 2008, at 2:50 AM, Matus UHLAR - fantomas wrote: As described in previous e-mails, host A cannot talk to host C except to relay via host B. Host A is trusted if relayed by host B. (anything is trusted if relayed by host B) If Host A appears to be connecting to host C, then

Re: trusted_host breaks pretty much every form of whitelist

2008-06-25 Thread Jo Rhett
Because it's a public mail server which gets legitimate mail connections from all over the world. I mean, why to accept connections from anything other? I don't understand your question. My only answer you quoted above. -- Jo Rhett Net Consonance : consonant endings by net philanthropy,

Re: trusted_host breaks pretty much every form of whitelist

2008-06-22 Thread Matt Kettler
Jo Rhett wrote: I just realized something re: the previous message about SPF failure. trusted_hosts is also apparently blocking whitelist_from_rcvd from working. misconfigured trusted/internal networks breaks *MANY* things in SpamAssassin. Pretty much everything that looks at Received:

Re: trusted_host breaks pretty much every form of whitelist

2008-06-21 Thread Matthias Leisi
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Jo Rhett schrieb: | Why not allow me to say I trust everything from this host no matter what? Why would you run the mails through SpamAssassin if you trust everything from that host? A whitelist entry in the MTA would avoid wasting resources on

trusted_host breaks pretty much every form of whitelist

2008-06-20 Thread Jo Rhett
I just realized something re: the previous message about SPF failure. trusted_hosts is also apparently blocking whitelist_from_rcvd from working. This is getting out of control. I understand the original intent here, but basically what is happening is that by making a host trusted you

Re: trusted_host breaks pretty much every form of whitelist

2008-06-20 Thread Henrik K
On Fri, Jun 20, 2008 at 11:08:01AM -0700, Jo Rhett wrote: I just realized something re: the previous message about SPF failure. trusted_hosts is also apparently blocking whitelist_from_rcvd from working. This is getting out of control. I understand the original intent here, but

Re: trusted_host breaks pretty much every form of whitelist

2008-06-20 Thread Jo Rhett
On Jun 20, 2008, at 12:10 PM, Henrik K wrote: whitelist_from_rcvd is checked on external (internal_networks) border. If you set up internal and trusted right, there are no problems. Why not allow me to say I trust everything from this host no matter what? I could possibly set

Re: trusted_host breaks pretty much every form of whitelist

2008-06-20 Thread Henrik K
On Fri, Jun 20, 2008 at 01:01:53PM -0700, Jo Rhett wrote: On Jun 20, 2008, at 12:10 PM, Henrik K wrote: whitelist_from_rcvd is checked on external (internal_networks) border. If you set up internal and trusted right, there are no problems. Why not allow me to say I trust everything from this