[EMAIL PROTECTED] wrote:
>> [EMAIL PROTECTED] wrote:
>>> Not at all, but you must know that with the qmail-smtpd distributed with
>>> the toaster is not possible to accept _ONLY_ authenticated (and TLS as
>>> an
>>> option)
>> When RELAYCLIENT is not set everyone must authenticate, no? Otherwise I
>> think it'd be an open relay.
> 
> Nope, when RELAYCLIENT is not set you can authenticate and send email to
> any domain, or don't authenticate and send a mail to one of the rcpthosts.
> A RBL'd spammer on port 25 can send spam to your domains over the
> submission port.
> 
> I didn't say openrelay, i meant spam to your own domains (as port 25
> without RBL's)
> 

I see. Thanks for clearing that up for me, David. I'm certainly no expert on
all this (yet), but the fog is lifting, albeit slowly.

I really like the rfc2476 writeup you sent. It helps a lot to think of
Message Submission Agent (MSA) and Message Transfer Agent (MTA) separately,
even though both rolls are played by qmail-smtp (and supporting cast).
That's always been a confusing point to me. I hope that the toaster can make
these separate at some point in the future. I think that would help (me, at
least).

>>> If you configure a smtpd server on 587 with current qmail-smtd and
>>> disabling RBL you let spammers pass over your RBL checks!
>> RBL checks yes, but not authentication, providing you don't set the
>> RELAYCLIENT variable.

I'm obviously (now) wrong here. Local and virtual domains are wide open.
Think MTA, not MSA.

Thanks again for clearing this up for me, David.

>>> Someone has a working conf of submission for ONLY relay users ???
>> Not me. I'm purely hypothetical! :) (not really)
>>
>>> I was working on patching an alternative qmail-smtpd but with not too
>>> much
>>> luck and no too much time now :-(
>> I've not much time either, but qmailtoaster-plus is nearly ready for
>> release. ;)
> 
> Well you are very productive. :-)

Thanks, but I'm afraid most of my productivity has only been with
qmailtoaster-plus. Not a bad thing though. ;)

-- 
-Eric 'shubes'

---------------------------------------------------------------------
     QmailToaster hosted by: VR Hosted <http://www.vr.org>
---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to