My solution to these licensing issues:

"Chris Travers" <[email protected]> Sat, 10 Jan 2004 11:12:30 +0700
Newsgroups gmane.mail.qmail.dist
Message-ID <018601c3d730$c2a08e50$97285e3d@winxp>
I sued to recomment qmail for everything, but I don't do so anylonger, in
part because I prefer the flexibility that open source software gives, and
qmail while freely redistributable is not open source in the sense of
allowing modified source distributions.  Qmail is great for what it does,
but there are a number of areas where it falls short (smtp-auth, etc.) and
for these patches need to be applied.

Rather than deal with patch management issues (and definitions of "what
consitutes distribution") I now only recommend Qmail where the basic
installation is good enough.  In other situations I currently recommend
Postfix because the terms of the license are more flexible.  For example, if
I need to apply a patch to Postfix I can do it to a centrally managed source
tree and then replicate this onto target servers or distribute to clients.
I cannot do the same with qmail.  I cannot even be sure that I can install
the software in a modified form on a client's system and be legally safe,
though I doubt that I need fear litigation over that one... Therefore I do
as follows:

Recommend Qmail for closed SMTP relays (in DMZ's for example)
Recommend Qmail for vanilla POP3 servers
Recommend Postfix for areas where auth-smtp and other advanced features are
required.
This works relatively well, for the most part.

BTW, I have a similar approach with djbdns-- recommend for external DNS
servers on firewalls or in DMZ's but otherwise BIND internally despite a
worse security record.  There are even circumstances (IPSec and oportunistic
encryption, for example) where external DNS servers may be better suited to
BIND.

Best Wishes,
Chris Travers

Best Wishes,
Chris Travers