Live data from Hacker News

Announcing Notqmail

schmonz.com

71–75 of 75 posts

Re: Announcing Notqmail

#71
post #48
post #47

Earlier quoted context omitted.

> saying "Postfix is worse because it had a security vulnerability in a component that qmail doesn't even support" is unfair to postfix. Ok, well that's your opinion, and hopefully now you at least know why I have mine. I can't imagine forgiving Microsoft for all those AD/SMB and explorer CVE just because Linux doesn't support those things, but it's not really that important to me. > In every enterprise setup I have…

>it sounds like you're talking about users relaying and not machines relaying there is such a thing as machine- or even application-specific accounts that can be terminated or their credentials rotated. Even better; you could use something like Vault ( https://www.vaultproject.io/ ) to manage such application-specific credentials. All of this is much better than relying on IP addresses never changing and never being…

Diversity is good!

Re: Announcing Notqmail

#72
post #50

Earlier quoted context omitted.

Sorry I'm confused. If your mail server is setup for control of a domain (e.g. domain.tld), then what stops someone from putting postmaster@domain.tld in this .qmail file?

People can put whatever they want in their own .qmail files. That doesn't affect anything unless qmail believes those .qmail files are relevant to what it's delivering. A user controls .qmail files for a domain if and only if an admin has configured qmail to delegate that domain to that user.

Ahh I see. So it's a per domain thing, and you can't restrict more granularly. That's a shame.

Re: Announcing Notqmail

#73

I run my own email server as well, and I've been using postfix/dovecot quite happily with zero issues. I've been contemplating opensmtpd as well, though I'm not sure where that stands when it comes to being run in production environments. Also, reconfiguring mailservers is a PITA, I'd rather stick with a setup which just works. Could someone explain why one might want to use qmail (or this, its newest incarnation) ov…

I'm an opensmtpd developer. As far as opensmtpd is concerned, it is production ready and has been used in high volume environments sending mails to millions of recipients daily, handling multi-million queues. The project was started in 2008 so when it comes to being run in production environments, I think we can claim that it's ready :-) Now as for the what you would gain, I won't do proselytism, we have published a…

Thank you very much! I shall have a look. I'm thinking of moving servers and setting everything up from scratch in order to modernize all my services and remove legacy cruft. I will definitely consider opensmtpd.

Re: Announcing Notqmail

#74
post #50

Earlier quoted context omitted.

People can put whatever they want in their own .qmail files. That doesn't affect anything unless qmail believes those .qmail files are relevant to what it's delivering. A user controls .qmail files for a domain if and only if an admin has configured qmail to delegate that domain to that user.

Ahh I see. So it's a per domain thing, and you can't restrict more granularly. That's a shame.

I haven't experienced a need for more granular restrictions. Can you give an example of a problem it would solve?

Re: Announcing Notqmail

#75
post #27

Earlier quoted context omitted.

The question is if notqmail isn't a bit too late. I'm maintaining a qmail setup for a customer and the amount of duct tape we've put on that thing is rather ridiculous. As it is now, I'd rather replace the whole thing with a regular Postfix/Dovecot setup and be done with it.

> As it is now, I'd rather replace the whole thing with a regular Postfix/Dovecot setup and be done with it. Any reason why you don't (can't?)?

The customer won't allow any non-security related changes to the platform. That's the only reason.
Post reply on HN