[2627] in SIPB_Linux_Development

home help back first fref pref prev next nref lref last post

disabling relaying in sendmail

daemon@ATHENA.MIT.EDU (Jered J Floyd)
Sun Feb 14 18:51:43 1999

To: linux-dev@MIT.EDU
From: Jered J Floyd <jered@MIT.EDU>
Date: 14 Feb 1999 18:51:22 -0500


cfox points out that we really should disable relaying from Linux-Athena
machines (or at the very least disable relaying from non-MIT hosts.) I
used the check_mail package to do this on vorlon.

This package (which sendmail.org recommends) can be found at:
http://www.sendmail.org/%7Eca/email/check.html

The .m4 files are installed in the subdirectory 'cf/hack' for sendmail
8.8. Many have been incorporated into sendmail 8.9.  Using check_rcpt4
is most relevant and effective for disabling relaying, as I have used 
below.

I allow relaying from other MIT hosts; I only use the IP acl'ing
feature, but this package allows you to set hostnames that can relay
through you, IP addresses who can relay through you, or hosts that can
be relayed *to*.  (commented out lines below show how to do these.)
The contents of /etc/mail/LocalIP on vorlon: 
18

vorlon's sendmail.mc (with irrelevant hacks removed):
divert(-1)
#
# Copyright (c) 1983 Eric P. Allman
# Copyright (c) 1988, 1993
#       The Regents of the University of California.  All rights reserved.
#
# Redistribution and use in source and binary forms, with or without
# modification, are permitted provided that the following conditions
# are met:
# 1. Redistributions of source code must retain the above copyright
#    notice, this list of conditions and the following disclaimer.
# 2. Redistributions in binary form must reproduce the above copyright
#    notice, this list of conditions and the following disclaimer in the
#    documentation and/or other materials provided with the distribution.
# 3. All advertising materials mentioning features or use of this software
#    must display the following acknowledgement:
#       This product includes software developed by the University of
#       California, Berkeley and its contributors.
# 4. Neither the name of the University nor the names of its contributors
#    may be used to endorse or promote products derived from this software
#    without specific prior written permission.
#
# THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
# ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
# ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
# FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
# DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
# OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
# HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
# LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
# OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
# SUCH DAMAGE.
#
divert(0)
define(`LOCAL_RELAY',`athena.mit.edu')dnl
define(`PROCMAIL_MAILER_PATH',`/usr/bin/procmail')dnl
define(`confPRIVACY_FLAGS',`noexpn,novrfy')dnl some privacy please.

VERSIONID(`v1.3')
OSTYPE(linux)
MASQUERADE_AS(`mit.edu')
FEATURE(nouucp)
FEATURE(local_procmail)
FEATURE(allmasquerade)
FEATURE(masquerade_envelope)
FEATURE(always_add_domain)
HACK(use_ip)dnl 'Local' addresses in /etc/mail/LocalIP
dnl HACK(use_names)dnl 'Local' names in /etc/mail/LocalNames
dnl HACK(use_relayto)dnl Valid relay addresses in /etc/mail/RelayTo
HACK(check_rcpt4)

MAILER(local)
MAILER(smtp)dnl

FE/etc/localusers
FL/etc/localusers
divert(-1)

home help back first fref pref prev next nref lref last post