[BlueOnyx:20115] Re: dovecot tcpwrappers

Herbert Rubin herbr at pfinders.com
Tue Sep 27 20:06:07 -05 2016


I was noticing an attack on saslauthd that seemed to eat up memory and hang
my server.

I wrote a Perl script to drop ips after a certain threshold of failures
from the maillog, but wanted to add it to /etc/hosts.deny also. Maybe even
adding it to the /etc/mail/access file as REJECT.

I read some things about dovecot being compiled with tcpwrappers but wanted
to ask the group before I started playing with it.

Herb


On Tue, Sep 27, 2016 at 4:38 PM, Michael Stauber <mstauber at blueonyx.it>
wrote:

> Hi Herbert,
>
> > How can I configure dovecot to use tcpwrappers?
> > I have BlueOnyx on SL 6.8.
> >
> > I hope its just a config file thing. But I wanted to ask before I edited
> > anything.
>
> May I ask why? :-)
>
> I experimented a bit with that in the past and the results were kind of
> discouraging. Dovecot doesn't like tcpwrappers at all and there is too
> much stuff that gets into the way.
>
> As is we run it directly as a service. You could try it and could
> disable the dovecot service and then provide your own wrappers in
> /etc/xinetd.d/
>
> However: Future dovecot updates might enable the dovecot service again,
> which will then conflict with your tcpwrapper configuration.
>
> --
> With best regards
>
> Michael Stauber
> _______________________________________________
> Blueonyx mailing list
> Blueonyx at mail.blueonyx.it
> http://mail.blueonyx.it/mailman/listinfo/blueonyx
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.blueonyx.it/pipermail/blueonyx/attachments/20160927/26f18413/attachment.html>


More information about the Blueonyx mailing list