Re: [opensuse] Getting Rid of postfix and exim on my laptop



Carlos E. R. said the following on 10/22/2008 10:00 PM:



But openSUSE is not a big enterprise distro, it is a "user" distro.

So you re saying that this should not be used as a desktop Linux in an
enterprise?

Can I quote you on that?


But you see, if you "decouple" the requirement or dependency of an smtp
server by services such as cron, I could not have my preferred method of
having cron mail me.

Why do you conclude that?
You statement is only accurate in that cron would not be DIRECTLY
mailing you.

If you use a tool such as SWATCH or SEC then any syslog event can mail you.

Both those tools are smart enough to condense multiple lines down to one
'event'.

As it stands, cron can _only_ mail me. It will _always_ mail me.
Most of the time I'm not interested. I only want to know if something
is wrong.

Marcus Ranum, talking about firewalls and IDS, makes the analogy with an
umbrella that notifies you about every raindrop that hits it.

Having tools like cron mail me when everything is OK is like that.
Using tools like SWATCH or SEC lets _me_ decide what I need to be
notified of and how I will be notified (mail, sms, pager, phone, popup,
whatever ...)

Nothing is stopping you from having cron notify you by mail - via syslog.

http://www.estpak.ee/~risto/sec/

This thread began about a dependency. There are other dependencies in
other threads - bluetooth for example.

These is also the issue of the context of the installation. laptops
have been cited.

Finally there is the situation that is very common where the "user" (you
said this was a "user" installation) does not make use of the stem mail
facilities but rather reads mail using a web interface such as gmail, or
uses something like Thunderbird to read the mail at their ISP via POP or
IMAP and uses Thunderbird's own SMTP service to send directly to the
ISP. I would imagine this would be quite common with "home" "users" and
laptop "users". After all, Postfix is an "enterprise" level MTA.
Wietse Venema, its designer and author, intended it as such. While its
easier to set up than sendmail, it is a very powerful and capable tool.
It is most definitely intended for a enterprise level mail hub (I have
been using it for many years as such on my dedicated mail host) and
needs a fair bit of consideration to set up correctly.

But CRON isn't the only wacky dependency.
Have a look at the ldap software you are _required_ to have loaded.
Try uninstalling the openldap client or ldap_pam.
LDAP is bolted in to a whole pile of things like your printer
management, inetd management and http server management. You have to
have this even if you don't use LDAP.

Now LDAP should be an option, like NIS/YP,that controlled by something
like the nsswitch. The whole point of PAM is that its _pluggable_. If
you don't plug that module in its never used.

Once again I point to other implementations that have figured this out
and not been faced with this crazy situation.

Failing to install LDAP shouldn't mean that I can't use YAST to
configure printers, add users or point my laptop and samba server.

Try for yourself. In the software installer do a SEARCH for "ldap" with
only "RPM REQUIRES". We get such things as Thunderbird, Adobe reader,
cURL, and Kgpg. Try some other values to search for and see what other
wacky dependencies you can find.

I mention this because LDAP is most certainly an _enterprise_ tool, not
one would normally install on a laptop. A single user system, a
non-enterprise "user" can get by with the /etc/passwd (&family) file(s).
That's what nsswitch is for. If you comment out the "nis" and "ldap"
from there, then those facilities never get used.

Once again, PAM is pluggable. The SYSLOG model allows you to select
whether you want to know about various events. In a "user" setting many
of these *MANDATORY* things are pure overhead. Simple "users" will read
their mail on the web - that's what the internet is for! Simple users
won't set up Samba server but may connect to them. Simple users won't
set up DNS servers but will connect to them.

Carlos, you seem to want it both ways. You say openSUSE is a "user"
system not an enterprise one, but its set up to force the installation
of enterprise software that is not appropriate to the context a simple
"user".



--
We succeed only as we identify in life, or in war, or in anything else,
a single overriding objective, and make all other considerations bend to
that one objective.
Dwight D. Eisenhower, speech, April 2, 1957
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx



Relevant Pages

  • Re: Problem installing office 2007
    ... The link to microsoft support ... "Bob I" wrote: ... considering you are putting on an Enterprise edition. ... so I wondered if it was a bad installation file (as I ...
    (microsoft.public.office.misc)
  • Re: Problem installing office 2007
    ... Also Enterprise editions are supported through your IT people and directly by Microsoft as they are volume licensed only. ... so I wondered if it was a bad installation file. ... Each time I have tried without uninstalling my current version of office and I have tried with uninstalling office 2003. ... The program then terminates and there is no error message to check. ...
    (microsoft.public.office.misc)
  • Re: Office 2007 Professional Plus - Group policy - Error
    ... This the link for the information that led me to believe GPO was a good ... requiring the enterprise license in order to use GPO. ... For the 2007 Office system a basic oNIP (Office network Installation Point) is a CD image. ... I am attempting to setup my Group policy installation package for my Office ...
    (microsoft.public.office.setup)
  • Re: Office 2K3 Professional Home Use Program Product Key Invalid
    ... They gave up that version of the VL of Office 2003 Pro and switched to the Enterprise. ... Your key will now not work anymore and you either have to get the Enterprise version from them with a new key or purchase a retail version of Office Pro with a license ... seperate processes like it is with the installation of Windows itself. ...
    (microsoft.public.office.setup)
  • Re: enable LDAP-SSL without a root-CA
    ... You need a cert that chains to a trusted root on ... >> enterprise root-CA? ... >> certificates to enable SSL over LDAP on one server? ...
    (microsoft.public.win2000.security)