John Simpson wrote:

On 2005-08-25, at 0907, Rick Macdougall wrote:

I do the same thing here and I run qmail-smtpd as root. Otherwise it doesn't work as you have seen.

part of the reason that qmail is broken into several parts is to limit the amount of damage that can be done by a security breach. running qmail-smtpd as root is not necessary, and is in fact dangerous. of course there is a $500 guarantee on the security of qmail's code, but (1) that doesn't apply if you're using any qmail patches (and nowadays, who isn't?) and (2) if somebody does find a security hole (and chances are it will be because of a problem with a patch rather than with qmail itself) do you want your system to be one of the first victims?

Not my choice. I just install and run it as per the managements requirements.



Reply via email to