[prev in list] [next in list] [prev in thread] [next in thread] 

List:       amavis-user
Subject:    [AMaViS-user] AUTH parameter to MAIL FROM
From:       "Alexander 'Leo' Bergolth" <leo () strike ! wu-wien ! ac ! at>
Date:       2007-06-15 21:05:23
Message-ID: 4672FF13.9050108 () strike ! wu-wien ! ac ! at
[Download RAW message or body]

Hi!

I'm using amavisd-new as a postfix smtpd_proxy_filter.
I've noticed that some mailers (some sendmail configurations) include an
AUTH parameter to the MAIL FROM command, which apparently postfix passes
to amavisd. However, amavisd rejects those mails because I have not
defined @auth_mech_avail.

-------------------- 8< --------------------
Jun 12 14:25:37 strike postfix/smtpd[611]: warning: proxy
127.0.0.1:10024 rejected "MAIL From:<xxx@yyy> SIZE=1841 AUTH=<>": "503
5.7.4 Error: authentication disabled".
-------------------- 8< --------------------

I've read Marks post on this topic some years ago:
http://thread.gmane.org/gmane.mail.virus.amavis.user/15970/focus=16013
... in which he argued that amavisd should not accept the AUTH parameter
if it isn't configured for authentication.

However, will simply enabling authentication by adding
@auth_mech_avail = qw(PLAIN LOGIN);
fix the problem for me? This will cause amavis accept the AUTH parameter
 in "MAIL TO" commands. But amavisd will then also handle the AUTH
command. Will postfix still block SMTP sessions using authentication
with wrong credentials before the mail is passed to amavis? (I believe,
amavis will reply with a positive "235 2.7.1 Authentication successful"
to every (supported and syntactically correct) authentication attempt
without checking the credentials if @auth_mech_avail is not empty.)

As the SMTPD_PROXY_README says "Postfix sends no other SMTP commands.",
postfix most likely won't pass an AUTH command to amavis anyway. So I'm
just looking for a confirmation in order to be able to put my mind at rest.

Thanks,
--leo
-- 
e-mail   ::: Alexander.Bergolth (at) wu-wien.ac.at
fax      ::: +43-1-31336-906050
location ::: Computer Center | Vienna University of Economics | Austria


-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
AMaViS-user mailing list
AMaViS-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/amavis-user
AMaViS-FAQ:http://www.amavis.org/amavis-faq.php3
AMaViS-HowTos:http://www.amavis.org/howto/
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic