Re: [Dovecot] Dovecot deliver with multiple UIDs (security question)

2010-07-12 Thread Timo Sirainen
On Mon, 2010-07-12 at 00:09 +0300, Buzai Andras wrote: dovecot unix - n n - - pipe flags=DRhu user=*mysudoeruser* argv=/usr/bin/sudo /usr/lib/dovecot/deliver -f ${sender} -d ${recipient} When you say that: * Basically the user that calls deliver via sudo

Re: [Dovecot] Dovecot deliver with multiple UIDs (security question)

2010-07-12 Thread Buzai Andras
Hi, Thank you for your answers :). When should I expect the final (production ready) release of Dovecot 2 (an approximate time period)? Thank you, Buzai Andras On Mon, Jul 12, 2010 at 5:35 PM, Timo Sirainen t...@iki.fi wrote: On Mon, 2010-07-12 at 00:09 +0300, Buzai Andras wrote:

Re: [Dovecot] Dovecot deliver with multiple UIDs (security question)

2010-07-12 Thread Charles Marcus
On 2010-07-12 1:20 PM, Buzai Andras wrote: When should I expect the final (production ready) release of Dovecot 2 (an approximate time period)? Sometime between now, and when it is released. ;) This is free software, and is released when it is ready... Since it is at rc2, I think you can

Re: [Dovecot] Dovecot deliver with multiple UIDs (security question)

2010-07-12 Thread Buzai Andras
Hi, I have one more question. It may sound like a dumb question but I'll ask anyway :). Since in Dovecot v2.0, LMTP is running as root isn't this a security risk of the same level as running deliver with sudo in Dovecot v1.2? Thank you, Buzai Andras On Mon, Jul 12, 2010 at 5:35 PM, Timo

Re: [Dovecot] Dovecot deliver with multiple UIDs (security question)

2010-07-12 Thread Timo Sirainen
On Mon, 2010-07-12 at 23:33 +0300, Buzai Andras wrote: I have one more question. It may sound like a dumb question but I'll ask anyway :). Since in Dovecot v2.0, LMTP is running as root isn't this a security risk of the same level as running deliver with sudo in Dovecot v1.2? LMTP runs as

Re: [Dovecot] Dovecot deliver with multiple UIDs (security question)

2010-07-11 Thread Timo Sirainen
On Sat, 2010-07-10 at 12:30 +0300, Buzai Andras wrote: I only call the deliver with sudo from inside Postfix and the sudoer user is only allowed to sudo on the deliver binary. My question is: Is this solution secure? Can It be used on a production environment? What exactly happens in the

Re: [Dovecot] Dovecot deliver with multiple UIDs (security question)

2010-07-11 Thread Buzai Andras
Hi, My master.cf Postfix file contains the following entry for this: dovecot unix - n n - - pipe flags=DRhu user=*mysudoeruser* argv=/usr/bin/sudo /usr/lib/dovecot/deliver -f ${sender} -d ${recipient} When you say that: * Basically the user that calls deliver

[Dovecot] Dovecot deliver with multiple UIDs (security question)

2010-07-10 Thread Buzai Andras
Hi all, I have a question related to using the Dovecot LDA (deliver) with a multiple UID setup as described on the http://wiki.dovecot.org/LDA page in the Multiple UIDs section. I run Postfix (virtual mailboxes) + Dovecot using multiple UIDs (one UID per virtual domain owner). I configured