[milters] Archive

Lists Index Date Thread Search

Article: 492
From: Anthony Howe
Date: 2005-04-13 01:24:20 -0400
Subject: Re: Exceptions in access.db

Removal...........: milters-request@milter.info?subject=remove
More information..: http://www.milter.info/#Support
--------------------------------------------------------

Oleg M. Golovanov wrote:
> For example I have to RELAY all 10.0.1 but without 10.0.1.44
> And I should not like to write as following
> 
> 10.0.1.1         RELAY
> 10.0.1.2         RELAY
> ....
> 10.0.1.43         RELAY
> 10.0.1.45         RELAY
> ....
> 10.0.1.254         RELAY

10.0.1				RELAY
10.0.1.44			SKIP

> i.e. I should like to generate only 1-2 lines for this needs.
> How it can be done so that there were 1-2 lines only
> and milter-sender with milter-spamc don't whitelist all 10.0.1 subnet?
> But with exceptions for some IPs.

Read sendmail's cf/README about SKIP. The milters all support it with 
all their tags.

For example to let sendmail relay and milter-sender to white list, but 
force milter-spamc to filter.

10.0.1				RELAY
10.0.1.44			SKIP
milter-spamc-connect:10.0.1	REJECT	

A negative value forces filtering in milter-spamc (ie. it only obeys 
white listing), but in milter-sender a negative value would reject 
(because of differences in what milter-sender does).

So to filter through both milters, but let sendmail relay:

10.0.1				RELAY
10.0.1.44			SKIP
milter-sender-connect:10.0.1	SKIP
milter-spamc-connect:10.0.1	SKIP

Should work. Changing the milter-spamc tag from REJECT to SKIP does not 
pose a problem (because it only obeys white listing). The SKIP tag short 
circuits the lookup and both milters proceed.

Note that the order of the tags in the access file is of no importance, 
since they are not stored with any order in the (hash or btree) 
database. So rearranging the access file to read like this:

milter-sender-connect:10.0.1	SKIP
milter-spamc-connect:10.0.1	SKIP
10.0.1.44			SKIP
10.0.1				RELAY

Might make for better human understanding, but does not affect the key 
lookups.

As this answer is pretty interesting to most people, I've CC'ed the 
[milters] mailing list to archive it.

-- 
Anthony C Howe                                 +33 6 11 89 73 78
http://www.snert.com/       ICQ:
7116561         AIM: Sir Wumpus

"held in my arms / his sun washed face / eyes closed" - Anthony

Lists Index Date Thread Search