Re: [SLE] cyrus configuration

From: Tom Allison (tallison_at_tacocat.net)
Date: 10/12/03

  • Next message: Graham Smith: "Re: [SLE] Playing DVD zone 1 on zone 2 RPC-2 DVD player"
    Date: Sat, 11 Oct 2003 21:45:57 -0400
    To: tarjei+a_lists.suse@nu.no
    
    

    Tarjei Huse wrote:

    >hi
    >
    >
    >
    >>I have some basic questions and I'm not sure where to begin finding the
    >>answers.
    >>
    >>
    >Take a look at
    >
    >
    >>is cyrus-sasld required for cyrus to function? (appears to be a definite Yes)
    >>
    >>
    >YES. cyrus-sasl is required. SuSE comes with both (i.e. -imapd and -sasl).
    >
    >
    >>Authentication:
    >>I am attempting to configure my network with PAM_LDAP authentication.
    >>
    >>
    >Use saslauthd. Consider using saslauthd directly to the ldapserver. PAM
    >here is only a hassle.
    >
    >
    >>Attempting, in that I haven't gotten there yet.
    >>But I would also want to be able to create mail accounts for users who are
    >>not in my network or may be on a different domain name (two domains on one
    >>mail server).
    >>
    >>
    >
    >
    >
    >>Can I do this using LDAP with TLS?
    >>
    >>
    >TLS has nothing to do with it.
    >LDAP no problem - define differen usernames and map different domains to
    >them.
    >
    >
    >
    >>(I really don't want plaintext passwords unless it's between my LAN and DMZ)
    >>
    >>
    >Well, how big is this operation, it might be worth considering some kind
    >of digest-md5 auth. See
    >http://marc.theaimsgroup.com/?l=cyrus-sasl&m=105815526130121&w=2
    >
    >
    >
    >>What's the DEFAULT authentication model for cyrus?
    >>
    >>
    >Sasl :-)
    >
    >
    >
    >
    Thank you for the input.

    I've made some progress.

    I have plaintext authentication against my /etc/passwd file.
    This is not my preferred method of authentication, but it's a working
    email server and since IMAP is only from the LAN it might be OK.

    I'm still not sure how to limit a DMZ service to a LAN subnet only.
    I'm using ipcop as a firewall and have a DMZ of 192.168.0.1/24 and a LAN
    of 192.168.1../24. Although ipcop does not permit IMAP traffic to the
    DMZ from the outside, I would prefer to firewall the server to IMAP only
    from 192.168.1.1/24 as a matter of practice. But that's probably
    another chapter.

    Right now I'm still wondering if I should try LDAP authentication, but I
    have another problem that's even bigger.

    How do I get spamassassin back into action?
    It seems that the email that's coming in is not being filtered/scanned
    for spam. X-Virus-Scanned tags are good, but nothing from X-Spam-Status.

    -- 
    Check the headers for your unsubscription address
    For additional commands send e-mail to suse-linux-e-help@suse.com
    Also check the archives at http://lists.suse.com
    Please read the FAQs: suse-linux-e-faq@suse.com
    

  • Next message: Graham Smith: "Re: [SLE] Playing DVD zone 1 on zone 2 RPC-2 DVD player"

    Relevant Pages

    • Re: Exchange 2003 Front End/Back End Servers & Passwords
      ... Sort of negates the purpose of a DMZ. ... > The authentication was my concern - might be more sensible to post to ... you have to open up a LOT between the DMZ and LAN. ... > up the email server to the world any more than I have to. ...
      (microsoft.public.exchange.admin)
    • Re: [fw-wiz] NTLM authentication from DMZ
      ... Exchange server is part of the normal company domain, ... have one authentication database to deal with. ... Place the exchange server in the DMZ, but that would require a whole ... Place it on the LAN, but that would require opening ports from the ...
      (Firewall-Wizards)
    • Re: AD Authentication on a DMZ ?
      ... the last article proposed by Paul is talking about ports needed for replication between one DC in a DMZ and the other in the LAN. ... You understand me correctly and indeed, I would like to use AD authentication for applications located in my DMZ. ... If i understand you correct, you have an application that need's to contact the DC in the LAN, therefore you have to open the ports in the firewall. ...
      (microsoft.public.windows.server.active_directory)
    • Re: AD Authentication in a DMZ ?
      ... Is there a secure way to use AD Authentication for applications localized in a DMZ? ... One option is to use ADAM with userProxy objects which will forward authentication requests to Your AD in LAN. ... Other option is to use ADFS, but your application will have to be tested if it will work with ADFS. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Firewall and DMZ topology
      ... attacker cannot spread his influence across the network. ... If the DMZ resides between the public Internet and the ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
      (Security-Basics)