*BSD News Article 45293


Return to BSD News archive

Path: sserve!newshost.anu.edu.au!harbinger.cc.monash.edu.au!simtel!news.kei.com!news.mathworks.com!gatech!howland.reston.ans.net!math.ohio-state.edu!cyberstore.ca!vanbc.wimsey.com!ddsw1!not-for-mail
From: chilton@MCS.COM (Christopher Hilton)
Newsgroups: comp.unix.bsd.freebsd.misc
Subject: Re: smail-3.1.29.1 cannot lock mailboxes
Date: 9 Jun 1995 10:46:19 -0500
Organization: /usr/lib/news/organi[sz]ation
Lines: 54
Message-ID: <3r9qcb$bvc@Mars.mcs.com>
References: <3r29u3$9vm@Mars.mcs.com> <3r2ron$qap@bell.maths.tcd.ie> <3r313f$oaj@mars.mcs.com> <3r924n$5n7@bonnie.tcd-dresden.de>
NNTP-Posting-Host: mars.mcs.com

In article <3r924n$5n7@bonnie.tcd-dresden.de>,
J Wunsch <joerg_wunsch@uriah.heep.sax.de> wrote:
>Christopher Hilton <chilton@MCS.COM> wrote:
>
>>If you've got a sendmail.cf [...]
>
>Wrong approach.  While i admit that you still need some basic under-
>standing of who's who in sendmail.cf, it's generally no longer recomm-
>endable to tweak the sendmail.cf itself.  Setup your .mc file instead:
>
>	cd /usr/src/usr.sbin/sendmail/cf
>	lpr -p README		# that's the documentation
>	cd cf
>	vi myown.mc
>	make myown.cf
>	cp myown.cf /etc/sendmail.cf
>
>(Perhaps we should provide /usr/src/usr.sbin/sendmail/cf even for
>users who don't install the full source.)

This is a good idea. Also nice would be moving to sendmail 8.6.12 as
there is a lot of paranoia about sendmail v8.6.9 and earlier having a
lot of security holes.

My main problem with sendmail is that Eric Allman doesn't seem to
consider UUCP a valid mail transport method so the documentation of
the UUCP is stuff lacking. I'm open to the possiblity that I missed
something when reading the sendmail documentation but the anti-uucp
sentiment is something that I gleaned from the sendmail docs and have
read about in a post on this thread.

>
>Worse: yes.  But not worst.  I forgot the argumentation _why_ 1777 for
>the mail spool is a security hole.  Read the FreeBSD mailing list
>archives on freefall if you're interested.  I think, it's been
>discussed about a year ago there.  It's basically some sort of race
>condition.
>

In truth this isn't even necessary. You have to configure smail to
use the local mail agent to append to mailboxes. This is a
configuration issue that came up because I wanted to test the first
compiled copy of smail that I generated.

C.
-- 
Christopher Sean Hilton	                       E-mail: chilton@mcs.com
----------------------------------------------------------------------
ICBM address:           | "Thus it is said if you know them and know 
  42 07 39 N/87 49 44 W | yourself, your victory will not be imperiled.
For PGP key finger:     | If you know Heaven and you know Earth, your 
     chilton@mcs.com    | victory will be complete." - Sun Tsu
----------------------------------------------------------------------