
fafaforza at gmail
Apr 23, 2013, 2:31 PM
Post #4 of 5
(370 views)
Permalink
|
|
Re: SMTP AUTH allows any sender via SSL, but only correct auth via non-SSL
[In reply to]
|
|
On 4/23/2013 5:01 PM, Kyle Wheeler wrote: > On Tuesday, April 23 at 04:05 PM, quoth Darek: >> Hi there, I'm running Qmail on FreeBSD 9.1 (port version >> qmail-1.03_8) with the SMTP-AUTH patch from ports. I run it using >> tcpserver and daemontools, with the exact file, except the smtps port >> running through stunnel. > > Stunnel is your problem. Essentially, all stunnel connections look, to > qmail, like they're coming from localhost, and localhost is (usually) > allowed to send mail without authenticating. > > One solution would be to make it so that localhost cannot send mail > without authenticating, but that can have complications, depending on > what software you use that relies on being able to send email via SMTP > to localhost (e.g. webmail or various mailing list software packages). > > Another solution is to use a DIFFERENT way of tunneling SMTPS, such as > mailfront or Frederik Vermeulen's SSL patch to qmail or tcpserver-ssl. Ah, makes sense. patching tcpserver would likely be easier than rebuilding qmail, and whatever else would need to be redone. Thanks a million! -- Darek > > ~Kyle
|