Re: tls proxy in front of spamd?

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Kevin Chadwick
Date: Wednesday, May 5, 2010 - 7:30 am

> Well, spamd never actually tries to deliver mail.  In a normal
Doh! I had a bit of a homer moment from rushing things.

I'd even wrote most of the pf.conf and still didn't consider the rdr-to
white rule. I read in the mailing list that spamd didn't work with
starttls and didn't need to because it would fall back. I didn't look
closely enough and missed the point about white listed being passed
straight through. I was also thrown a bit by assuming (something I
usually try my best not to do) that allowed domains applied to all
connections, but it only applies to grey. Sorry for the noise and
thanks for ironing me out.


Do you not think it would be better for mail servers to try ssl on one
port and then plain on port 25 if a rst or timeout occurs. Then it
would be harder for attackers to force falling back to plain and
forcing only tls would be easier.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: tls proxy in front of spamd?, Ted Unangst, (Tue May 4, 1:08 pm)
Re: tls proxy in front of spamd?, Hugo Villeneuve, (Tue May 4, 5:57 pm)
Re: tls proxy in front of spamd?, Kevin Chadwick, (Wed May 5, 1:46 am)
Re: tls proxy in front of spamd?, Peter N. M. Hansteen, (Wed May 5, 3:18 am)
Re: tls proxy in front of spamd?, Kevin Chadwick, (Wed May 5, 7:30 am)
tls proxy in front of spamd?, Kevin Chadwick, (Wed May 5, 8:06 am)
Re: tls proxy in front of spamd?, Jussi Peltola, (Wed May 5, 8:41 am)
Re: [Bulk] Re: tls proxy in front of spamd?, Kevin Chadwick, (Wed May 5, 11:27 am)
Re: [Bulk] Re: tls proxy in front of spamd?, Jussi Peltola, (Wed May 5, 5:21 pm)
Re: tls proxy in front of spamd?, Chris Dukes, (Thu May 6, 10:00 am)
Re: [Bulk] Re: tls proxy in front of spamd?, Kevin Chadwick, (Wed May 12, 3:12 pm)