Bug 44903 - selective SMTP access restrictions not possible
Summary: selective SMTP access restrictions not possible
Status: RESOLVED WORKSFORME
Alias: None
Product: UCS
Classification: Unclassified
Component: Mail
Version: UCS 4.1
Hardware: Other Linux
: P5 normal
Target Milestone: ---
Assignee: Erik Damrose
QA Contact: Sönke Schwardt-Krummrich
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-06-29 17:17 CEST by Tobias Birkefeld
Modified: 2018-11-27 12:07 CET (History)
4 users (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 2: Improvement: Would be a product improvement
Who will be affected by this bug?: 2: Will only affect a few installed domains
How will those affected feel about the bug?: 3: A User would likely not purchase the product
User Pain: 0.069
Enterprise Customer affected?: Yes
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number: 2017042721000845
Bug group (optional):
Customer ID: 08281
Max CVSS v3 score:
best: Patch_Available+


Attachments
patch für bug (14.06 KB, patch)
2017-07-28 10:00 CEST, Tobias Birkefeld
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Tobias Birkefeld univentionstaff 2017-06-29 17:17:08 CEST
Postfix allows you to specify lists of access restrictions for each stage of the SMTP conversation.

smtpd_client_restrictions
smtpd_helo_restrictions
smtpd_sender_restrictions
smtpd_relay_restrictions
smtpd_recipient_restrictions
smtpd_data_restrictions
smtpd_end_of_data_restrictions


UCS only use "smtpd_recipient_restrictions". But in some environments there will be a problem that you can't adjust specific restrictions.

In this case (Ticket#2017042721000845) an external mail server does "recipient address verification". In combination with restricted mailing lists, the address probes will fail because of our mis-configured sites that reject "MAIL FROM: <>" to this restricted mailing lists.

If we could configure the check for the listfilter (check_policy_service unix:private/listfilter) to "smtpd_data_restrictions" there will be no problem for the "recipient address verification" and the "real" mail will successful delivered to the restricted mailing list (if the sender is allowed to).
Comment 1 Sönke Schwardt-Krummrich univentionstaff 2017-07-07 15:49:56 CEST
Is bug 44473 sufficient to fix this issue?
Comment 2 Tobias Birkefeld univentionstaff 2017-07-28 10:00:55 CEST
Created attachment 9069 [details]
patch für bug
Comment 3 Erik Damrose univentionstaff 2018-11-27 12:07:12 CET
Individual configuration can be done in the main.cf.local, as introduced by bug 44473. Examples may be provided by an SDB article from bug 40377