Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 19 May 2008 13:54:20 -0500
From:      David Kelly <dkelly@hiwaay.net>
To:        brad davison <demonichandextensions@hotmail.com>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: Lock down the all-staff email list? sendmail, alias, majordomo?
Message-ID:  <20080519185420.GA17546@Grumpy.DynDNS.org>
In-Reply-To: <BLU116-W11A011C21C8B3D4072FB71A1C50@phx.gbl>
References:  <BLU116-W11A011C21C8B3D4072FB71A1C50@phx.gbl>

next in thread | previous in thread | raw e-mail | index | archive | help
On Mon, May 19, 2008 at 03:23:30PM +0000, brad davison wrote:
> 
> Our company has a sendmail server 8.13.8 running on FBSD 6.2 with
> procmail.  We currently have an alias set up for our all-staff email
> (we only have about 200 users).  Someone recently sent out an email to
> the all-staff that someone didn't like, so now I have to restrict who
> can send to it.

If one is willing to consider replacing sendmail with postfix it appears
there may be several ways to restrict who may send messages to an
address. "man 5 access" and "man 5 header_checks" are my first guesses.

Header_checks seems to run before the message is queued. If there is a
match you can accept, reject, redirect, or many other things.

OTOH if only a few people are allowed to send to all-staff then maybe it
would be best to manually maintain a mail list in their personal address
books?

Another way to deal with it would be to rewrite the all-staff header
with a bogus undeliverable address so that the minions don't know what
the single whole world address is? So that if they reply it doesn't
deliver, or it only delivers to a few select people? Only the privileged
few know the real-all-staff email address.

I know, its "security by obscurity" but when absolute security is not
needed and all that is needed is protection from the ignorant its often
plenty good enough.

-- 
David Kelly N4HHE, dkelly@HiWAAY.net
========================================================================
Whom computers would destroy, they must first drive mad.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20080519185420.GA17546>