(cc'ing users list since there's nothing private in here)

On Fri, Jan 19, 2007 at 09:55:14PM -0500, Brian Z wrote:
> I thought it was safe to run spamd as root?

Running the spamd parent as root is fine, but the children won't run
a message through as root as a security paranoia measure.  So if root
runs spamc, it calls spamd and says it's root, and the spamd child goes
"I'm not going to run as root!"

> Is there some other setup i need to do?

It really depends what you're doing.  If root is the only user that will ever
call spamd -- then setup SA in site-wide mode and run as a non-root user,
disable per-user configs and dbs, etc.

If you are doing things in per-user mode, and root is just calling spamd
because root is getting mail -- either a) have root call spamc with
"-u some_username" as appropriate, or b) as most places do, alias root
mail to be delivered to a different user/address.

-- 
Randomly Selected Tagline:
"What is a lie but the truth in masquerade." - Byron

Attachment: pgpIsK6zSyiqc.pgp
Description: PGP signature

Reply via email to