Re: pre-announce: acceptutils patch (was Re: filtering ofmipd-submitted messages)

Shepherd Nhongo <[email protected]> Mon, 7 May 2018 21:50:34 +0200
Newsgroups gmane.mail.qmail.general
Message-ID <CAEY0h6pdS-G7nKqNccVTzePK8tNA81KxrMqLYLSk0c++xz9bKQ@mail.gmail.com>
That looks appealing.

I am using a compiled qmail installation other than netqmail. i will give
it a try and review the patch.

Well done on the great effort.

On Mon, May 7, 2018 at 4:47 PM, Amitai Schleier <[email protected]> wrote:

> On 28 Apr 2018, at 13:45, Amitai Schleier wrote:
>
> I'm nearly finished with a redesigned approach to SMTP AUTH for qmail, and
>> I've succeeded at not needing to think much about TLS yet.
>>
>> acceptutils, once released, will add a handful of small new programs that
>> fit together nicely with vanilla qmail/netqmail/mess822.
>>
>> It _may_ offer improved security -- if I've done a good job, I believe so
>> -- and will definitely offer improved functionality. Teaser: it makes both
>> ofmipd and pymsgauth useful in new ways.
>>
>> I'd love to get review and feedback on https://schmonz.com/qmail/acce
>> ptutils/, and/or to hear from folks who might be interested to try it
>> out.
>>
>
> With my code, vanilla ofmipd (or qmail-smtpd) injects into the queue with
> the privileges of the authenticated user. Inspect this message's headers
> for something like these:
>
>     Received: (qmail 25831 invoked by uid 1000); 7 May 2018 14:32:19 -0000
>     Received: (ofmipd 127.0.0.1); 7 May 2018 14:31:57 -0000
>
> (I'm UID 1000 on my server.)
>
> As a result, I'm pretty sure you'll be reading this message without my
> having seen or manually replied to a qsecretary challenge. Even though I'm
> not sending from an MUA directly on the server, pymsgauth will have handled
> qsecretary for me.
>
> I'd love to hear comments on my approach :-)
>
> - Amitai
>



-- 
Shepherd Nhongo

Do not Queue mail with SENDMAIL, send mail with QMAIL

Botswana  # +267 744 760 40
Zimbabwe # +263 772 688 072