Re: Debian exim4 SRS forward only how-to

"Stuart D. Gathman" <[email protected]> Mon, 19 Dec 2005 13:36:11 -0500 (EST)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Mon, 19 Dec 2005 [email protected] wrote:

> I have a forwarding service running on Debian box and I got into the SRS
> topic only because my mail forwarding stopped to work. I suppose I am in a
> position of an average admin, who simply wants his server to act as it was
> set up to do in the pre SPF days.

Actually, forwarders shouldn't theoretically need to impelement SRS.
Your users should whitelist you as a trusted forwarder before checking
SPF.  However, since the little detail of listing forwarders is ignored
for most end-user SPF implementations, SRS is a tool that forwarders 
can use to help things "just work" for their users that check SPF.

> Can anyone answer these questions, however stupid they may be:

I can answer some of them.

> 0. Can I use just SRS, without SPF?

Yes.

> 1. Do I have to compile exim4 to get SRS working or can I just use some pipe 
> in .forward?

Although I am a sendmail guy, I don't think you need to recompile exim.  The
Perl SRS package from which I derived my Python SRS package had an Exim socket
map (which I translated to Python, but haven't tested).

> 2. What should my .forward file look like?

I am assuming that like the sendmail socketmap, Exim doesn't need any
changes to .forward.

> 3. What should the srs.secret file look like?

Anything an attacker won't guess.

> 4. Do I need any other files than I already have (see below)?

No.  Unless you prefer Python to Perl scripts.

> 5. What changes in exim config are needed?

Enable the socketmap.  Details will need to come from an Exim person.

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flamis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.