Re: Sendmail and security



Anne Wilson:
>> A user of another distro has remarked that I should uninstall sendmail.
>> <quote> Sendmail simply has too many security issues to leave it on any
>> machine. </quote>
>>
>> Surely a box kept up to date would not have those security issues. Am I
>> missing something?

John Summerfied:
> Only if RH is:-)
>
> It's still the default MTA installed by Red Hat's installer.

Though, by default, it doesn't pay attention to anything other than the
local box. So, like most things, I'd say it's the configuration of it
that makes it good/bad, not *it* in itself.

I think it's probably old news, very old news, as someone else pointed
out. Similar comments have been made about postfix, it being unsafe, it
being open to all and sundry, etc. Again, I think that was old news.

If one was going to open up any sort of SMTP server to the WWW, I'd be
researching all the information about how to make it secure. But if
it's only for internal mail, or it acts as your mail gateway to send
local mail out to the WWW, then you've got far less to worry about.

As it comes (with FC4), you've got to fiddle around with your
configuration so that you can use it as an SMTP server, at all.

> sendmail has an enormous share of the "market" - it can't be _that_ bad.

Hmm, shall I resist the urge... No, I won't... ;-) Windows has an
enormous share of the market, and it's very bad. Proliferation isn't
something I'd use to gauge the goodness of something. :-\

--
Don't send private replies to my address, the mailbox is ignored.
I read messages from the public lists.

--
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list



Relevant Pages

  • Re: problem installing Sendmail
    ... This appears to be the configuration for local mail only. ... your SMTP server, which will route mail to the outside world. ... to rewrite the sender address with a publicly valid one, ...
    (Debian-User)
  • Re: What memory board is this?
    ... Major issues to consider when comparing MCA-compatible memory boards ... are easy to configure at installation time. ... they have a more complicated configuration procedure. ... First, the good news: All the boards we tested work, and work well. ...
    (comp.sys.ibm.ps2.hardware)
  • Re: Newsgroups, ot
    ... seem to have changed the name in your existing client configuration ... destination that Outlook Express contacts to get and post news. ... to save the settings for the account, ...
    (rec.pets.cats.anecdotes)
  • Re: Newsgroups, ot
    ... have changed the name in your existing client configuration rather than ... destination that Outlook Express contacts to get and post news. ... accounts, news, where eternal september is listed. ...
    (rec.pets.cats.anecdotes)
  • Re: Fake Gucci Indy Large - Black Alligator Fake HandBags
    ... Bellsouth doesn't seem to miss messages, but it doesn't seem to filter ... I have BellSouth's smtp server entered in my MacSOUP preferences, ... news, whereas I'm using MacSOUP for news and Mail for mail, so perhaps ...
    (comp.sys.mac.system)