This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

PostFix Not 100% Secure on ZPanel/Sentora
#4
RE: PostFix Not 100% Secure on ZPanel/Sentora
(09-15-2014, 05:28 AM)Me.B Wrote: I may not agree on using Black lists, this will reject a lot of spam but will result in painfull false positive. Far better to use it in scroring system.

Will check all the other settings.

Notice ALL help here over Sentora security is welcome.

M B

I agree. But the blacklists are an option. You don't have to turn them on. The most important part is to make sure you have the security settings in place to stop a relay attack. These settings are from 3 days of figuring out how to stop a massive relay attack. 

They successfully got through my ZPanel servers with the default Postfix settings so I am sharing this information in the hopes you don't have to go though the same thing I went through. I think if you include the additional settings in the distribution, it will help secure Postfix. Postfix is a really tricky animal and one setting can really throw everything off. 

Postfix is super robust and can handle a ton of email, however, it is very complex and the configs are not for the faint of heart. I know many other hosts and developers use other products because of the time and expertise it takes to make sure it is secure. I personally know Postfix pretty dam well and it is still a challenge to me many times. 

For example, GoDaddy and Hostek (Two big hosting companies) use SmarterMail just because it is more straightforward to administer and secure. It is also much easier to diagnose. I know its not an option here, however, maybe a simpler email open source server can be integrated into Sentora down the road. 

I know Postfix has the unique ability to read SQL lists from the DB so it may be tough to replace but I definitely recommend heavy security testing if you are going to keep it in the product. 
Reply
Thanks given by:


Messages In This Thread
RE: PostFix Not 100% Secure on ZPanel/Sentora - by smccarthy945 - 09-15-2014, 07:33 PM

Possibly Related Threads…
Thread Author Replies Views Last Post
user: 'postfix' host: 'localhost' (Got an error reading communication packets) cezars 0 2 ,781 02-01-2022, 08:58 PM
Last Post: cezars
Postfix mail.log to database stikekar 2 8 ,235 03-02-2019, 01:22 AM
Last Post: TGates
Using ssl certificate for Postfix and Dovecot in multiple domains. davi-dns 9 36 ,252 12-03-2018, 05:13 PM
Last Post: fearworks

Forum Jump:


Users browsing this thread: 5 Guest(s)