https://www.reddit.com/r/postfix/ Well there is a subreddit for postfix. News to me but I just joined it. I do my best to stay out of these "conversations" on the listserv and reserve my posts for when I am really stumped. But since I am posting put me in the firewall geofence crowd. I have done this for a two years now and it vastly reduces the hacking on my server. I block all email ports other than 25 from countries I have no plan on visiting. This is really only practical for a personal email server. I also have a list of data centers that I give the same treatment. I see the snowshoe hackers on my web server and I assume they are on my email but I don't read the postfix logs as often. I haven't seen a hacker hammer my server in a long time. It is all snowshoe these days. I am not a fan of fail2ban or sshguard on my low powered VPS. I find dynamically adding IPs to the firewall is a high CPU usage event. It may be a consequence of having a huge list of IP space to block. My assumption is firewalld has to add the IPs in an efficient to search manner and arranging the table/database is CPU intensive. It would send the VPS to 100%. (My personal data center blocking list is about 40k lines of CIDRs.) I was choking the server adding IPs for what would otherwise be a low impact event. Sometimes I think a VPS is lower CPU power than a R Pi. Firewalld itself is a very low CPU usage program once the table/database is established. It does use a fair amount of RAM which again must be related to the table/database it creates. I have no fear of my passwords being breached. It is a personal server so every password was created by me and all are generated by an algorithm to achieve high entropy. I've been using 20 characters as a standard since that seems to work on most websites as well. They are SHA512 on the server. Regarding setting up postfix and Dovecot it is best to follow a guide. This is what I used: https://blog.andreev.it/?p=1975 It isn't complete as far as postfix goes but I implement features I find discussed on the postfix listserv as they come up. I doubt I could just read the man pages for postfix and Dovecot to set up an email server. Too many options. Back to lurker mode.
Good feedback - typically I’d have some comments but since we’ve wandered a fair bit off the reserve here, I will refrain. If anyone wants to continue this at Reddit or somewhere else more appropo, let me know… On 26 Apr 2022, at 11:56, Lefteris Tsintjelis wrote:
|
- Re: password security Bill Cole
- Re: password security patpro
- Re: password security Byung-Hee HWANG
- Re: password security Viktor Dukhovni
- Re: password security Byung-Hee HWANG
- Re: password security Antonio Leding
- Re: password security Antonio Leding
- Re: password security Fred Morris
- Re: password security Lefteris Tsintjelis
- Re: password security Antonio Leding
- Re: password security lists
- Re: password security AndrewHardy
- Re: password security lists
- Re: password security Ansgar Wiechers
- Re: password security Jaroslaw Rafa
- Re: password security Michael Ströder
- Re: password security Jahnke-Zumbusch, Dirk
- Re: password security Michael Ströder
- Re: password security Viktor Dukhovni
- Re: password security Michael Ströder
- Re: password security Antonio Leding