So far I have not implemented SMTP Auth for various reasons (on of them was the fact that I had no Postfix installed). Anyway, I would like to implement it, but since I have a relatively large base (>200K emails), I would like to do it in a non-disruptive way. I was thinking to implement something like a "bounce" message for each outgoing mail without authentication. That message will not stop the delivery of the email, but it will, simply, inform unauthenticated users about the fact that in a few days they will be forced to do so.
When D-day comes, I would like to return to unauthenticated users a custom DSN, not the build-in error.
Is there any way to do it? If not, is there any other way to do it?
B/R
P.
There are a number of reasons. Like for example, stopping emails from non-existed users, or stopping email bombing from "zombie" PCs.
The majority of emails in the queues of my MTA is backscatter and one of the ways to reduce it is SMTP Auth.
More important thought is the need to enable access to the MTA from other networks too, so, I need the SMTP AUTH.
----- Αρχικό μήνυμα -----
Απο: Larry Stone <lsto...@stonejongleux.com>
Προς: Peter Tselios <s91...@yahoo.gr>
Κοιν.: Postfix Users <postfi...@postfix.org>
Στάλθηκε: 4:32 μ.μ. Τετάρτη, 8 Φεβρουαρίου 2012
Θεμα: Re: Implement SMTP Auth in a non-disruptive way?
On Wed, 8 Feb 2012, Peter Tselios wrote:
> So far I have not implemented SMTP Auth for various reasons (on of them was the fact that I had no Postfix installed). Anyway, I would like to implement it, but since I have a relatively large base (>200K emails), I would like to do it in a non-disruptive way. I was thinking to implement something like a "bounce" message for each outgoing mail without authentication. That message will not stop the delivery of the email, but it will, simply, inform unauthenticated users about the fact that in a few days they will be forced to do so. When D-day comes, I would like to return to unauthenticated users a custom DSN, not the build-in error.
I still need the "DSN" style message back for those users and I hope to have some ideas.
----- Αρχικό μήνυμα -----
Απο: Jose Ildefonso Camargo Tolosa <ildefons...@gmail.com>
Προς: Postfix Users <postfi...@postfix.org>
Κοιν.:
Στάλθηκε: 5:49 π.μ. Πέμπτη, 9 Φεβρουαρίου 2012
Θεμα: Re: Implement SMTP Auth in a non-disruptive way?
Greetings,
Reindi, search through postfix docs for that:
+ permit_sasl_authenticated
+ permit_mynetworks (play with the mynetworks definition, so,
initially you allow all mail from your local network, and when *all*
of your users moved to new authenticated schema, you just removed
local network from here)
That one is not so important, but I have found it really useful in my
environment:
+ reject_authenticated_sender_login_mismatch (this is an interesting
one, that you can later replace with: reject_sender_login_mismatch ...
now, I use LDAP with all of this).
I am a little in a hurry now, but if you read the docs you may get the idea.
I hope this helps,
Ildefonso Camargo.