sendmail and reverse NDR
Christos Ricudis
ricudis at komodino.itc.auth.gr
Wed Jul 5 12:52:21 EEST 2006
I.Ioannou wrote:
> Ligh boithia apo tous sendmail gurus pls (Christo akous ?)
> Pws sto kalo stamataw to reverse NDR sto sendmail, h mallon
> gia tin akribia, pws stamataw to NDR na mhn periexei to full
> body, giati mou exoun spasei ta neyra na psaxnw na to brw.
> (malakismeno sendmail, mazi den kanoume kai xoria den mporoume)
>
Sendmail Installation and Operations Guide, selida SMM:08-71. Kai epeidh
eimai stis kales mou shmera, kanw KAI paste :
PrivacyOptions= opt,opt,... [p]
Set the privacy options. Privacy is really a misnomer; many of these
are just a way of insisting on stricter adherence to the SMTP protocol.
The options can be selected from:
public Allow open access
needmailhelo Insist on HELO or EHLO command before MAIL
needexpnhelo Insist on HELO or EHLO command before EXPN
noexpn Disallow EXPN entirely, implies noverb.
needvrfyhelo Insist on HELO or EHLO command before VRFY
novrfy Disallow VRFY entirely
noetrn Disallow ETRN entirely
noverb Disallow VERB entirely
restrictmailq Restrict mailq command
restrictqrun Restrict q command line flag
restrictexpand Restrict bv and v command line flags
noreceipts Don t return success DSNs
nobodyreturn Don t return the body of a message with DSNs
goaway Disallow essentially all SMTP status queries
authwarnings Put X-Authentication-Warning: headers in messages and log
warnings
The goaway pseudo-flag sets all flags except noreceipts ,
restrictmailq , restrictqrun , restrictexpand , noetrn , and
nobodyreturn . If mailq is restricted, only people in the same group as
the queue directory can print the queue. If queue runs are restricted,
only root and the owner of the queue directory can run the queue. The
restrictexpand pseudo-flag instructs sendmail to drop privileges when
the bv option is given by users who are neither root nor the
TrustedUser so users cannot read private aliases, forwards, or :include:
files. It will add the NonRootSafeAddr to the DontBlameSendmail
option to prevent misleading unsafe address warnings. It also overrides
the v (verbose) command line option to prevent information leakage.
Authentication Warnings add warnings about various conditions that may
indicate attempts to spoof the mail system, such as using a non-standard
queue directory.
--
Christos Ricudis ricudis at itc.auth.gr
Systems Administrator +30-2310-998656
IT Support Center
Aristotle University of Thessaloniki, GREECE
More information about the Linux-greek-users
mailing list