Re: SSL SMTP Relay in DMZ

From: Adam Aube (aaube01_at_baker.edu)
Date: 02/10/04

  • Next message: stan: "Getting Net SNMPD to work for Cricket?"
    To: debian-user@lists.debian.org
    Date: Mon, 9 Feb 2004 20:32:48 -0500
    
    

    On Saturday 07 February 2004 03:10 pm, Curtis Vaughan wrote:
    > I would like to set up a mail server in a DMZ that would accept mail
    > only from those clients who have authenticated using SSL.

    Do you mean authenticate using username/password over SSL, or authenticate
    using an SSL certificate?

    If the former, setup SMTP AUTH to handle the authentication, and if your
    MTA supports TLS, use that to wrap the authentication in SSL. If not, use
    Stunnel.

    If the latter, have the MTA only listen on localhost. Setup Stunnel to
    only accept certain certificates, then forward those connection over
    localhost to the listening MTA.

    > Given that they have successfully passed that criteria, then this DMZ
    > mail server would pass the mail off to an internal mail server for
    > further delivery.

    Most MTAs support forwarding all mail to another server - just set this up
    for your MTA of choice.

    Adam

    -- 
    To UNSUBSCRIBE, email to debian-user-request@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: stan: "Getting Net SNMPD to work for Cricket?"

    Relevant Pages

    • Re: Exchange 2000 - Need relaying help bad
      ... > the mail server, and clients are set to authenticate to SMTP. ... > all computers which successfully authenticate to relay ...
      (microsoft.public.exchange2000.admin)
    • Exchange 2000 - Need relaying help bad
      ... Users of the mail server cannot send messages from offsite. ... They have connectivity to both the pop3 and smtp ports on ... and clients are set to authenticate to SMTP. ...
      (microsoft.public.exchange2000.admin)
    • Re: Outgoing mail
      ... What does your ISP say about your problem? ... >> to use their resources. ... >> If you are ON the same network as the mail server that you want to use, ... >> you probably don't have to authenticate (but that depends on the e-mail ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: Outgoing mail
      ... > you didn't authenticate to their server (to prove you have permission to ... > use their resources) and since you are coming from a different domain, ... > If you are ON the same network as the mail server that you want to use, ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: Exchange outgoing email on a Virtual PC
      ... I was able to telnet to both my ISP's mail server ... And, yes, I do need to authenticate with the ISP to relay, but not to send ... mail to other accounts at my domain. ... DNS will not work to send mail. ...
      (microsoft.public.exchange.setup)