DISCUSSION: HOWTO Setup a Secure Relaying Email Server
This thread is to discuss the article titled: HOWTO Setup a Secure Relaying Email Server
|
i followed this, as closely as i was able, but, had a few problems:
when i ran /bin/netstat -tp i got nothing like what was shown when i ran /usr/sbin/stunnel /etc/stunnel/myserver.conf i got Either -r, -l (or -L) option must be used Try 'stunnel -h' for more information. ive been really tryiing to get this to work... using redhat 8.0 any help, is greatly apprciated... im not a newbie to unix, and not all that new to linux, though i sure am haing some mail problems.... |
what do you get when running netstat on the server?
The -t is a filter to show only tcp, -p displays the pid of the program with the connection. you could try netstat -lp Code:
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name stunnel needs the -r or -l as used on the server to tell it how to connect. The config file contains the needed information. Be sure that the config file is correct and that the user running stunnel can access it. I run stunnel as root Code:
cat /etc/stunnel/www.conf your logs should tell you if stunnel has a problem starting, check /var/log/messages for more info on the problem. |
As for the windows client goes, how does this work with antivirus software that is also intercepting mail sent from the client on localhost, in order to scan outgoing mail for viruses?
-KS |
No problem as far as I have tested.
I have "Norton AV 2002" set to scan email, I also have it set to display a progress indicator when I send mail. The progress screen comes up and shows the scan as expected. I would expect other scanners to work as expected also. |
|
yes linuxnube it will work. the .dll files for openssl are found at stunnel.org in the download area, that's all you need on the client unless you intend to create certificates on the client. Then you would need to install openssl.
|
Can I setup "exim 4" mail server at "debian gnu linux 3.0" by following these instructions....I want to setp a secure mail server at debian and also a scanner for it's incoming and outgoing email....
|
This document covers setting up a secure tunnel to transfer mail over. You can use it to secure any mailserver you wish.
It does not cover mailserver installation or configuration. |
thanks...Now I understand...
|
According to the Article, one should setup stunnel and ssl on the client, too, to connect to e.g. a secure smtp server.
Fortunately, it is not so. I tested the setup and found that the mail client of Mozilla 1.5 can perfecly use the smtps server even if you do not have stunnel on the client! In my case I had a https server with client-server authentication using stunnel on the server, and, based on that setup, it took me not more than a minute to setup the new, smtps service. Stunnel and Mozilla rock! Thanks for the tip! |
Yes, that's true if your client supports it directly you can input the server instead of localhost. It does sound like your not using client certificate auth on the server if this works without using the client certificate. That's the difference.
Also not all clients will support it, so If yours does not you can do it with stunnel and ssl. If it does the choice is yours to decide. |
As a side note..
Normal smtp mailserver setup was not covered here, but be sure your port 25 is open on your firewall for incoming email. :) |
what affero button?
|
The one that says ( * affero ) on it! :)
|
All times are GMT -5. The time now is 12:04 PM. |