Re: Secure spamd server

2009-02-04 Thread Michael Parker
On Feb 4, 2009, at 11:06 AM, Andre wrote: On Wed, 4 Feb 2009, Matus UHLAR - fantomas wrote: On 03.02.09 21:39, Andre wrote: spamc is never called from Exim in this case, so the --ssl switch can't be used. At least that is my understanding (maybe mis-understanding?) of the situation.

Re: Secure spamd server

2009-02-04 Thread Andre
On Wed, 4 Feb 2009, Matus UHLAR - fantomas wrote: > On 03.02.09 21:39, Andre wrote: > > spamc is never called from Exim in this case, so the --ssl switch can't be > > used. At least that is my understanding (maybe mis-understanding?) of the > > situation. > > Doesn't exim even have the option fo

Re: Secure spamd server

2009-02-04 Thread Matus UHLAR - fantomas
> > mouss wrote: > > > stunnel may be more appropriate, and easier to setup and control than > > > ssh, in this particular case. > On Wed, 4 Feb 2009, Jason Haar wrote: > > What's wrong with spamc's native "--ssl" mode - plus a simple ACL at the > > spamd end to limit who can reach it? Chances are

Re: Secure spamd server

2009-02-03 Thread Andre
On Wed, 4 Feb 2009, Jason Haar wrote: > mouss wrote: > > stunnel may be more appropriate, and easier to setup and control than > > ssh, in this particular case. > > > > > What's wrong with spamc's native "--ssl" mode - plus a simple ACL at the > spamd end to limit who can reach it? Chances are t

Re: Secure spamd server

2009-02-03 Thread Jason Haar
mouss wrote: > stunnel may be more appropriate, and easier to setup and control than > ssh, in this particular case. > > What's wrong with spamc's native "--ssl" mode - plus a simple ACL at the spamd end to limit who can reach it? Chances are there's a firewall involved in this situation anyway.

Re: Secure spamd server

2009-02-03 Thread mouss
Andre a écrit : > I haven't thought about a VPN yet, but it could probably work. I only > thought about a ssh tunnel so far, which may also work. > stunnel may be more appropriate, and easier to setup and control than ssh, in this particular case. > Still, if anyone knows an esay off-the-shelf s

Re: Secure spamd server

2009-02-03 Thread Marc Perkel
Andre wrote: Hi, we run Exim (4.69) with mail scanned at smtp time via acl. We put an external spamd server to work (works fine). Now we want to extend that setup by permitting another mail server (Exim, same setup) to connect to the spamd server. However, that transport has to happen over th

Re: Secure spamd server

2009-02-03 Thread John Hardin
On Tue, 3 Feb 2009, Andre wrote: I haven't thought about a VPN yet, but it could probably work. I only thought about a ssh tunnel so far, which may also work. That's what I was going to suggest. It's a lot more lightweight than a VPN if this is going to be the only reason the two servers are

Re: Secure spamd server

2009-02-03 Thread Andre
I haven't thought about a VPN yet, but it could probably work. I only thought about a ssh tunnel so far, which may also work. Still, if anyone knows an esay off-the-shelf solution for exim I'd prefer that (if it exists). Thank you, -andre On Tue, 3 Feb 2009, Martin Gregorie wrote: > On Tue, 200

Re: Secure spamd server

2009-02-03 Thread Martin Gregorie
On Tue, 2009-02-03 at 14:46 -0500, Andre wrote: > However, we can't find a way to tell exim to connect via SSL (basically > the equivalent of 'spamc -S'). > > So, how do we enable SSL here? Is anyone running a similar setup? Are > we just missing something? Other stories to tell... > Would settin

Secure spamd server

2009-02-03 Thread Andre
Hi, we run Exim (4.69) with mail scanned at smtp time via acl. We put an external spamd server to work (works fine). Now we want to extend that setup by permitting another mail server (Exim, same setup) to connect to the spamd server. However, that transport has to happen over the open internet,