[pfx] Correct (least-privilege) way to access /var/spool/postfix/public/qmgr

2024-08-28 Thread Laura Smith via Postfix-users
In its default configuration, Postfix makes /var/spool/postfix/public/qmgr world accessible whilst the parent directory /var/spool/postfix/public is not. This means that metric gathering is not able to connect to  /var/spool/postfix/public/qmgr. I'm guessing the wrong answer is to make the met

[pfx] Re: Correct (least-privilege) way to access /var/spool/postfix/public/qmgr

2024-08-28 Thread Wietse Venema via Postfix-users
Laura Smith via Postfix-users: > In its default configuration, Postfix makes /var/spool/postfix/public/qmgr > world accessible whilst the parent directory /var/spool/postfix/public > is not. The effect of permissions on UNIX-domain sockets is system dependent (in other words, not all the world is

[pfx] Re: Correct (least-privilege) way to access /var/spool/postfix/public/qmgr

2024-08-28 Thread Viktor Dukhovni via Postfix-users
On Wed, Aug 28, 2024 at 04:29:02PM +, Laura Smith via Postfix-users wrote: > In its default configuration, Postfix > makes /var/spool/postfix/public/qmgr world accessible whilst the > parent directory /var/spool/postfix/public is not. > > This means that metric gathering is not able to connec