SnertSoft: We Serve Your Server

milter-ahead/1.10
«Call Ahead to Reserve»


Description & Usage ° Installation & Notes ° License & Support

WARNING

THIS IS MAIL FILTERING SOFTWARE AND WILL BLOCK MAIL THAT FAILS TO PASS A GIVEN SET OF TESTS. SNERTSOFT AND THE AUTHOR DO NOT ACCEPT ANY RESPONSIBLITY FOR MAIL REJECTED OR POSSIBLE LOSS OF BUSINESSS THROUGH THE USE OF THIS SOFTWARE. BY INSTALLING THIS SOFTWARE THE CLIENT UNDERSTANDS AND ACCEPTS THE RISKS INVOLVED.

Description

This Sendmail mail filter allows a gateway mail server to call-ahead to another MX server or internal mail store before accepting mail for recipients of a message. Think of it as a lazy man's LDAP. It could also be used by fallback MX servers to verify recipients with the primary MX. This milter was derived from a similar facility found in milter-sender.

milter-ahead can use its own database and/or use Sendmail's FEATURE(`mailertable'), which is passed to the milter through {rcpt_addr}, {rcpt_host}, and {rcpt_mailer} macros.

snert.com       esmtp:[pop.snert.net]

With the square-brackets around a host name or IP address, the route is well defined and the postmaster knows exactly which server is the next hop for mail in the recipient domain. This milter does not perform MX lookups when the square brackets are missing by default and thus would skip the call-ahead test (see mx-lookup).

Usage

milter-ahead [options ...][arguments ...]

Options can be expressed in four different ways. Boolean options are expressed as +option or -option to turn the option on or off respectively. Options that required a value are expressed as option=value or option+=value for appending to a value list. Note that the +option and -option syntax are equivalent to option=1 and option=0 respectively. Option names are case insensitive.

Some options, like +help or -help, are treated as immediate actions or commands. Unknown options are ignored. The first command-line argument is that which does not adhere to the above option syntax. The special command-line argument -- can be used to explicitly signal an end to the list of options.

The default options, as shown below, can be altered by specifying them on the command-line or within an option file, which simply contains command-line options one or more per line and/or on multiple lines. Comments are allowed and are denoted by a line starting with a hash (#) character. If the file option is defined and not empty, then it is parsed first followed by the command-line options.

Note that there may be additional options that are listed in the option summary given by +help or -help that are not described here.

Options

access-db=
The type and location of the read-only access key-value map. It provides a centralised means to black and white list hosts, domains, mail addresses, etc. The following methods are supported:
text!/path/map.txtR/O text file, memory hash
/path/map.dbBerkeley DB hash format
db!/path/map.dbBerkeley DB hash format
db!btree!/path/map.dbBerkeley DB btree format
sql!/path/databaseAn SQLite3 database
socketmap!host:portSendmail style socket-map
socketmap!/path/local/socketSendmail style socket-map
socketmap!123.45.67.89:portSendmail style socket-map
socketmap![2001:0DB8::1234]:portSendmail style socket-map

If :port is omitted, the default is 7953.

The access-db contains key-value pairs. Lookups are performed from most to least specific, stopping on the first entry found. Keys are case-insensitive.

An IPv4 lookup is repeated several times reducing the IP address by one octet from right to left until a match is found.

tag:192.0.2.9
tag:192.0.2
tag:192.0
tag:192

An IPv6 lookup is repeated several times reducing the IP address by one 16-bit word from right to left until a match is found.

tag:2001:0DB8:0:0:0:0:1234:5678
tag:2001:0DB8:0:0:0:0:1234
tag:2001:0DB8:0:0:0:0
tag:2001:0DB8:0:0:0
tag:2001:0DB8:0:0
tag:2001:0DB8:0:0
tag:2001:0DB8:0
tag:2001:0DB8
tag:2001

A domain lookup is repeated several times reducing the domain by one label from left to right until a match is found.

tag:[ipv6:2001:0DB8::1234:5678]
tag:[192.0.2.9]
tag:sub.domain.tld
tag:domain.tld
tag:tld
tag:

An email lookup is similar to a domain lookup, the exact address is first tried, then the address's domain, and finally the local part of the address.

tag:account@sub.domain.tld
tag:sub.domain.tld
tag:domain.tld
tag:tld
tag:account@
tag:

If a key is found and is a milter specific tag (ie. milter-ahead-Connect, milter-ahead-From, milter-ahead-Auth, milter-ahead-To), then the value is processed as a pattern list and the result returned. The Sendmail variants cannot have a pattern list. A pattern list is a whitespace separated list of pattern-action pairs followed by an optional default action. The supported patterns are:

[network/cidr]actionClassless Inter-Domain Routing
!pattern!actionSimple fast text matching.
/regex/actionPOSIX Extended Regular Expressions

The CIDR will only ever match for IP address related lookups.

A !pattern! uses an astrisk (*) for a wildcard, scanning over zero or more characters; a question-mark (?) matches any single character; a backslash followed by any character treats it as a literal (it loses any special meaning).

!abc!exact match for 'abc'
!abc*!match 'abc' at start of string
!*abc!match 'abc' at the end of string
!abc*def!match 'abc' at the start and match 'def' at the end, maybe with stuff in between.
!*abc*def*!find 'abc', then find 'def'

For black-white lookups, the following actions are recognised: OK or RELAY (white list), REJECT or ERROR (black list), DISCARD (accept & discard), SKIP or DUNNO (stop lookup, no result), and NEXT (opposite of SKIP, resume lookup). Its possible to specify an empty action after a pattern, which is treated like SKIP returning an undefined result. Other options may specify other actions.

Below is a list of supported tags. Other options may specify additional tags.

  
milter-ahead-Connect:client-ip  value   § Can be a pattern list.
Connect:client-ip  value
 
milter-ahead-Connect:[client-ip]  value   § Can be a pattern list.
milter-ahead-Connect:client-domain  value   § Can be a pattern list.
milter-ahead-Connect:  value   § Can be a pattern list.
Connect:[client-ip] value
Connect:client-domain value
 
All mail sent by a connecting client-ip, unresolved client-ip address or IP addresses that resolve to a client-domain are black or white-listed. These allows you to white-list your network for mail sent internally and off-site, or connections from outside networks. Note that Sendmail also has special semantics for Connect: and untagged forms.
 
milter-ahead-From:sender-address  value   § Can be a pattern list.
milter-ahead-From:sender-domain  value   § Can be a pattern list.
milter-ahead-From:sender@  value   § Can be a pattern list.
milter-ahead-From:  value   § Can be a pattern list.
From:sender-address value
From:sender-domain value
From:sender@ value
 
All mail from the sender-address, sender-domain, or that begins with sender is black or white-listed. In the case of a +detailed email address, the left hand side of the +detail is used for the sender@ lookup. Note that Sendmail also has special semantics for From: and untagged forms.
 
milter-ahead-Auth:auth_authenvalue   § Can be a pattern list.
milter-ahead-Auth:value   § Can be a pattern list.
 
All mail from the authenticated sender, as given by sendmail's {auth_authen} macro, is black or white-listed. The string searched by the pattern list will be the sender-address. The empty form of milter-ahead-Auth: allows for a milter specific default only when {auth_authen} is defined.
 
milter-ahead-To:recipient-address  value   § Can be a pattern list.
milter-ahead-To:recipient-domain  value   § Can be a pattern list.
milter-ahead-To:recipient@  value   § Can be a pattern list.
milter-ahead-To:  value   § Can be a pattern list.
Spam:recipient-address value   * (FRIEND or HATER are recognised)
Spam:recipient-domain value   * (FRIEND or HATER are recognised)
Spam:recipient@ value   * (FRIEND or HATER are recognised)
To:recipient-address value
To:recipient-domain value
To:recipient@ value
 
All mail to the recipient-address, recipient-domain, or that begins with recipient is black or white-listed. In the case of a +detailed email address, the left hand side of the +detail is used for the recipient@ lookup. Note that Sendmail also has special semantics for Spam:, To:, and untagged forms.
 

The milter-ahead-Connect:, milter-ahead-From:, and milter-ahead-To: tags provide a milter specific means to override the Sendmail variants. For example, you normally white list your local network through any and all milters, but on the odd occasion you might want to actually scan mail from inside going out, without removing the Connect: tag that allows Sendmail to relay for your network or white listing for other milters. So for example if you have Sendmail tags like:

To:mx.example.comRELAY

You might have to add milter specific overrides in order to make sure the mail still gets filtered:

To:mx.example.comRELAY
milter-ahead-To:mx.example.comSKIP

Some additional examples:

milter-ahead-Connect:80.94 [80.94.96.0/20]OK  REJECT
 
Accept connections from the netblock 80.94.96.0/20 (80.94.96.0 through to 80.94.111.255) and rejecting anything else in 80.94.0.0/16.
 
milter-ahead-Connect:192.0.2 /^192\.0\.2\.8[0-9]/OK  REJECT
 
Accept connections from 192.0.2.80 through to 192.0.2.89, reject everything else in 192.0.2.0/24.
 
milter-ahead-From:example.com /^john@.+/OK  /^fred\+.*@.*/OK  REJECT
 
Accept mail from <john@example.com> and <fred@example.com> when fred's address contains a plus-detail in the address. Reject everything else from example.com.
 
milter-ahead-To:example.net !*+*@*!REJECT  !*.smith@*!REJECT  /^[0-9].*/REJECT
 
Reject mail to example.net using a plus-detail address or to any user who's last name is "smith" or addresses starting with a digit. No default given, so B/W processing would continue.
 

Normally when the access.db lookup matches a milter tag, then the value pattern list is processed and there are no further access.db lookups. The NEXT action allows the access.db lookups to resume and is effectively the opposite of SKIP. Consider the following examples:

milter-ahead-From:com
From:com
/@com/REJECT  NEXT
OK
 
Reject mail from places like compaq.com or com.com if the pattern matches, but resume the access.db lookups otherwise.
 
milter-ahead-From:aol.com  
From:fred@aol.com  
/^[a-zA-Z0-9!#$&'*+=?^_`{|}~.-]{3,16}@aol.com$/NEXT  REJECT
OK
 
AOL local parts are between 3 and 16 characters long and can contain dots and RFC 2822 atext characters except % and /. The NEXT used above allows one simple regex to validate the format of the address and proceed to lookup white listed and/or black listed addresses.
 
+backup-mx
For a backup MX or gateway, accept mail when the down stream mail server is unreachable or when the server returns 421 server busy or 554 no service responses.
cache-accept-ttl=604800
The cache time-to-live in seconds for positive responses. The cache remembers the results of a previous call-ahead.
cache-file=/var/db/milter-limit.db
The file path used for BDB or flatfile cache types.
cache-gc-frequency=250
This option specifies the cache garbage collection frequency, which is based on the number of SMTP connections (not messages) handled by the milter. Every N connections, the cache is traversed to remove expired entries.
cache-reject-ttl=90000
The cache time-to-live in seconds for negative responses. The cache remembers the results of a previous call-ahead.
cache-type=bdb
The cache type can be one of: bdb, flatfile, hash.
call-ahead-host=
Force the call-ahead always to this host, overriding the {rcpt_host} determined by Sendmail. This option is undefined by default. This option overrides mx-lookup.
call-ahead-db=
When specified, the parameter is the type and location of a read-only key-value map. The following variants are supported:
text!/path/map.txtR/O text file, memory hash
/path/map.dbBerkeley DB hash format
db!/path/map.dbBerkeley DB hash format
db!btree!/path/map.dbBerkeley DB btree format
sql!/path/databaseAn SQLite3 database
socketmap!host:portSendmail style socket-map
socketmap!/path/local/socketSendmail style socket-map
socketmap!123.45.67.89:portSendmail style socket-map
socketmap![2001:0DB8::1234]:portSendmail style socket-map

The recipient's domain is first used as the lookup key followed by each parent domain component that makes up the domain name. If no key is found, then the value of {rcpt_host} will be used.

When a key is found, then the value returned must be the name or IP of the mail server to consult surrounded by square brackets. An optional :port specifier may follow the closing square bracket. To consult the MX of another domain specify the other domain name to lookup. This only works when mx-lookup is enabled. Note that :port cannot be used in this case, because using an MX implies SMTP port 25.

Below is an example of what the database file might look like with using IPv4, IPv6, hostname, and MX of domain values:

snert.biz [192.0.2.7]
snert.com [192.0.2.7]:1234
snert.eu [2001:0DB8::beef]
snert.fr [2001:0DB8::beef]:1234
snert.info [pop.snert.example]
mx.snert.net [smtp.snert.example]:1234
snert.net snert.org
+is-blind-mx
Test whether the call-ahead host is blind MX and cache the result so that furture call-aheads to a blind MX can be ignored. A blind MX is a host which accepts any recipient only to bounce later. Some servers like Exchange in their default configuration behave this way. Also catch-all addresses will cause this behaviour too.
-mx-lookup
Enable MX lookups of the {rcpt_host} or of the domain found in the call-ahead-db.
-mx-reject=all
A comma separated word list. Reject an MX that resolves to RFC 3330, 3513, or 3849 reserved IP addresses.
all all reserved IP address  
0 accept all.  
benchmark 198.18.0.0/15 RFC 2544
link-local 169.254.0.0/16, FE80::/10 RFC 3330, 3513
localhost 127.0.0.1, ::1 RFC 3330, 3513
loopback 127.0.0.0/8 excluding 127.0.0.1
multicast 224.0.0.0/4, FF00::/8 RFC 3330, 3513
private-a 10.0.0.0/8 RFC 3330
private-b 172.16.0.0/12 RFC 3330
private-c 192.168.0.0/16 RFC 3330
reserved IPv6 unassigned prefixes RFC 3513
site-local FEC0::/10 RFC 3513
test-net 192.0.2.0/24, 2001:DB8::/32 RFC 3513, 3849
this-net 0.0.0.0/8, ::0 RFC 3330, 3513
+daemon
Start as a background daemon or foreground application.
file=/etc/mail/milter-ahead.cf
Read the option file before command line options. This option is set by default. To disable the use of an option file, simply say file=''
-help or +help
Write the option summary to standard output and exit. The output is suitable for use as an option file.
-ignore-rcpt-host
When using the call-ahead-db option, in particular to call-ahead past an anti-virus server for example, falling back on the {rcpt_host} for the call-ahead would result often in a redundant connection to a machine that accepts any recipient. This option disables the call-ahead when {rcpt_host} is the target.
max-failures=5
Maximum number of call-ahead failures initiated from the same client IP before being blocked until the cache entry expires.
milter-socket=unix:/var/run/milter/milter-ahead.socket
A socket specifier used to communicate between Sendmail and milter-ahead. Typically a unix named socket or a host:port. This value must match the value specified for the INPUT_MAIL_FILTER() macro in the sendmail.mc file. The accepted syntax is:
{unix|local}:/path/to/file
A named pipe. (default)
inet:port@{hostname|ip-address}
An IPV4 socket.
inet6:port@{hostname|ip-address}
An IPV6 socket.
milter-timeout=7210
The sendmail/milter I/O timeout in seconds.
pid-file=/var/run/milter/milter-ahead.pid
The file path of where to save the process-id.
-primary-up-reject
We are a backup MX and we want to reject mail when the primary MX is available. This does not conform with RFC 974 & 2821 mail routing, which only requires mail clients attempt delivery to the primary first, before trying other MXes.

Spammers often attempt to by-pass spam filters by sending email directly to secondary MX machines, which often have weaker requirements. This option essentially demands that a client only deliver to the primary MX when it is available.

-quit or +quit
Quit an already running instance of the milter and exit. This is equivalent to: kill -QUIT `cat /var/run/milter/milter-ahead.pid`
-reject-percent-relay
Reject a RCPT if it uses a routed address (the %-hack).
-relay-mail-from
Use the original MAIL FROM:<sender> given instead of the MAIL FROM:<> when performing the call-ahead. Note if the server being called ahead performs any call-back or call-ahead tests themselves, then this option may have negative undefined results.
-restart or +restart
Terminate an already running instance of the milter before starting.
run-group=milter
The process runtime group name to be used when started by root.
run-user=milter
The process runtime user name to be used when started by root.
smtp-timeout=120
Specify the socket timeout in seconds to wait for SMTP responses during the call ahead. A zero (0) value will set the timeout to indefinite.
-try-implicit-mx
Try the implicit MX for {rcpt_host} when no other MX answers. Used in special cases where for example departmental subdomain MXes point to a gateway MX and rely on the implicit MX rule with an A record to route the mail internally to the departmental mail store.
verbose=info
A comma separated list of how much detail to write to the mail log. Those mark with § have meaning for this milter.
§ all All messages
§ 0 Log nothing.
§ info General info messages. (default)
§ trace Trace progress through the milter.
§ parse Details from parsing addresses or special strings.
  debug Lots of debug messages.
§ dialog I/O from Communications dialog
  state State transitions of message body scanner.
§ dns Trace & debug of DNS operations
§ cache Cache get/put/gc operations.
§ database Sendmail database lookups.
§ socket-fd Socket open & close calls
§ socket-all All socket operations & I/O
§ libmilter libmilter engine diagnostics
work-dir=/var/tmp
The working directory of the process. Normally serves no purpose unless the kernel option that permits daemon process core dumps is set.

SMTP Responses

This is the list of possible SMTP responses generated by milter-ahead.

553 5.1.0 imbalanced angle brackets in path
The path given for a MAIL or RCPT command is missing a closing angle bracket
553 5.1.0 address does not conform to RFC 2821 syntax
The address is missing the angle brackets, < and >, as required by the RFC grammar.
553 5.1.0 local-part too long
The stuff before the @ is too long.
553 5.1.[37] invalid local part
The stuff before the @ sign contains unacceptable characters.
553 5.1.0 domain name too long
The stuff after the @ is too long.
553 5.1.7 address incomplete
Expecting a domain.tld after the @ sign and found none.
553 5.1.[37] invalid domain name
The domain after the @ sign contains unacceptable characters.
553 5.1.0 cannot deliver to null address
Sender said RCPT TO:<> and Sendmail didn't catch it.
550 5.7.1 routed address relaying denied
The recipient address tried to use the %-hack for routed address relaying. See reject-percent-relay option.
xyz x.7.1 server [^ ]+ for <[^>]+> communication error
An internal error occured. See the mail log for details.
xyz x.7.1 server [^ ]+ for <[^>]+> not answering
The server given by the {rcpt_host} macro or call-ahead-host option could not be reached.
xyz x.7.1 server [^ ]+ for <[^>]+> responded with a busy signal
The server given by the {rcpt_host} macro or call-ahead-host option return a 421 busy signal.
xyz x.7.1 server [^ ]+ for <[^>]+> provides no SMTP service
The server given by the {rcpt_host} macro or call-ahead-host option return a 554 no service.
xyz x.7.1 server [^ ]+ for <[^>]+> responded with \".*\"
The server given by the {rcpt_host} macro or call-ahead-host option return an unexpected welcome response.
xyz x.7.1 server [^ ]+ for <[^>]+> did not accept HELO
Received something other than a 250 return code for the HELO command.
xyz x.7.1 server [^ ]+ for <[^>]+> does not accept <> address as required by RFC 821, 1123, 2505, and 2821
The MAIL FROM:<> command was reject contrary to RFC requirements. See the relay-mail-from option.
xyz x.7.1 server [^ ]+ for <[^>]+> rejected sender address saying \".*\"
The MAIL FROM:<sender> was rejected. See the relay-mail-from option.
xyz x.7.1 server [^ ]+ for <[^>]+> rejected address saying \".*\"
The RCPT TO:<recipient> command was rejected.
450 4.7.1 primary MX [^ ]+ online and accepting mail
See the primary-up-reject option.

Installation

  1. Download:

    milter-ahead/1.10 md5sum Change Log
    LibSnert md5sum Change Log
    Sendmail 8.14   http://www.sendmail.org/
    Berkeley DB   http://www.sleepycat.com/
  2. If you have never built a milter for Sendmail, then please make sure that you build and install libmilter, which is not built by default when you build Sendmail. Please read the libmilter documentation. Briefly, it should be something like this:

    cd (path to)/sendmail-8.14.0/libmilter
    sh Build -c install
    
  3. The build process for libsnert and milter-ahead is pretty straight forward once you have libmilter installed:

    cd (path to)/com/snert/src/lib
    ./configure
    make build
    cd ../milter-ahead
    ./configure
    make build
    make install
    

    Both configuration scripts have some options that allow you to override defaults. Those options are listed with:

    ./configure --help
    
  4. An example ${prefix}/share/examples/milter-ahead/milter-ahead.mc is supplied. This file should be reviewed and the necessary elements inserted into your Sendmail .mc file and sendmail.cf rebuilt. Please note the comments on the general milter flags.

    
    
  5. Once installed and configured, start milter-ahead and then restart Sendmail. An example startup script is provided in ${prefix}/share/examples/milter-ahead/milter-ahead.sh. The default options can be altered by specifying them on the command-line or within a /etc/mail/milter-ahead.cf. The milter-ahead.cf is parsed first followed by the command-line options.

Notes

  • Currently tested platforms:

    Cobalt Qube 1 with Linux RH 5.1 (mips 2.0.34 kernel); Linux RH 5.1 (Intel x386 2.2.25 kernel); FreeBSD 4.8, 4.9 (Intel x386); OpenBSD 3.6 (Intel x386)
  • The minimum desired file ownership and permissions are as follows for a typical Linux system. For FreeBSD, NetBSD, and OpenBSD the binary and cache locations may differ, but have the same permissions.

    Process user ``milter'' is primary member of group ``milter'' and secondary member of group ``smmsp''. Note that the milter should be started as root, so that it can create a .pid file and .socket file in /var/run; after which it will switch process ownership to milter:milter before starting the accept socket thread.

    /etc/mail/root:smmsp0750 drwxr-x---
    /etc/mail/access.dbroot:smmsp0640 -rw-r-----
    /etc/mail/sendmail.cfroot:smmsp0640 -rw-r-----
    /etc/mail/milter-ahead.cfroot:root0644 -rw-r--r--
    /var/run/milter/milter-ahead.pidmilter:milter0644 -rw-r--r--
    /var/run/milter/milter-ahead.socketmilter:milter0644 srw-r--r--
    /var/db/milter-aheadmilter:milter0644 -rw-r--r-- (*BSD)
    /var/cache/milter-aheadmilter:milter0644 -rw-r--r-- (linux)
    /usr/local/libexec/milter-aheadroot:milter0550 -r-xr-x---
  • We would like to express our thanks to Derek Balling for his support at http://www.milter.org/ and to April Lorenzen for her poking and proding to create this milter.

User Feeback

April Lorenzen
We have a sendmail gateway in front of an IMail pop/webmail server. milter-ahead makes it effortless for the gateway to know both users and aliases on the pop server, without messy alias/user gathering scripts and cron jobs. milter-ahead allows us to reject mail to unknown users immediately, before accepting the message content. We are using it to reject thousands of dictionary attack spammers, viruses, and addresses that got on "millions of addresses" spammer cds from customers who used to have catch all accounts.

License Agreement 1.4

SNERTSOFT IS WILLING TO LICENSE THE SOFTWARE IDENTIFIED ABOVE TO YOU ONLY UPON THE CONDITION THAT YOU ACCEPT ALL OF THE TERMS CONTAINED IN THIS LICENSE AGREEMENT. PLEASE READ THE AGREEMENT CAREFULLY. BY DOWNLOADING OR INSTALLING THIS SOFTWARE, YOU ACCEPT THE TERMS OF THE AGREEMENT.

  1. Definitions

    1. ``Package'' means the identified above in source and/or binary form, any other machine readable materials provided (including, but not limited to documentation, sample files, data files), any updates or error corrections, and its derivative works.

    2. ``Private Individual'' means an individual using the Package for personal, private, and non-commercial use only.

    3. ``Organisation'' means a legal entity or an individual that does not qualify as a Private Individual defined above.

    4. ``You'' (or ``Your'') means a Private Individual or Organisation exercising rights under, and complying with all of the terms of, this License or a future version of this License issued under Section 5.1. For legal entities, ``You'' includes any entity which controls, is controlled by, or is under common control with You. For purposes of this definition,``control'' means (a) the power, direct or indirect, to cause the direction or management of such entity, whether by contract or otherwise, or (b) ownership of more than fifty percent (50%) of the outstanding shares or beneficial ownership of such entity.

    5. The Package is an original work written by Anthony C. Howe, hereto referred to as the ``Author''.

  2. License To Use

    1. If You are a Private Individual and so benefited from a reduced purchase price, then You may only compile, install, and use this Package, with or without private modifications, exclusively on a single machine You legally own or rent from a third party, provided You retain this notice, the Author's copyright notice, any and all license control methods (see below), and any links within the Package back to the most current online versions of this License and Disclaimer.

    2. Otherwise if You have paid the full purchase price, then You may compile, install, and use this Package, with or without private modifications, exclusively on machines You legally own or rent from a third party, provided You retain this notice, the Author's copyright notice, any and all license control methods (see below), and any links within the Package back to the most current online versions of this License and Disclaimer.

    3. You may copy, share, distribute, modify, and create derivative works from the user manuals and any related documentation solely for Your internal business purposes, such as in-house documentation, training manuals, or reference material.

  3. Restrictions

    1. Redistribution, including but not limited to books, CDROMS, download mirrors, floppy diskettes, hard disks, hardcopy print outs, online archives, solid state disks, streaming tapes, or other current or future forms of storage or communication media of the Package, with or without modifications, including any and all derivative works such as source patches, binaries, binary patches, or similar is expressly forbidden without prior written permission in hardcopy (letter or fax) signed and dated by the Author.

    2. It is expressly forbidden for You to use the Package, in whole or in part, in any other software, except those designated by the Author.

    3. It is expressly forbidden for You to use the Package to develop any software or other technology having the same primary function as the Package, including but not limited to using the Package in any development or test procedure that seeks to develop like software or other technology, or determine if such software or other technology performs in a similar manner as the Package.

    4. You may not sell, rent, lease, or transfer the Package to third parties without prior written permission in hardcopy (letter or fax) signed and dated by the Author.

  4. Termination

    1. This Agreement is effective until terminated. You may terminate this Agreement at any time by destroying all copies of the Package. This Agreement will terminate immediately without notice from the Author if You fail to comply with any provision of this Agreement. Either party may terminate this Agreement immediately should any portion of the Package become, or in either party's opinion be likely to become, the subject of a claim of infringement of any intellectual property right. Upon Termination, You must destroy all copies of the Package.

  5. Versions Of The License

    1. New Versions. The Author may publish revised and/or new versions of the License from time to time. Each version will be given a distinguishing version number.

    2. Effect of New Versions. Once a version of the Package has been published under a particular version of the License, You may always continue to use it under the terms of that License version. You may also choose to use such Package under the terms of any subsequent version of the License published by the Author. No one other than the Author has the right to modify the terms applicable to the Package created under this License.

Disclaimer

THIS SOFTWARE IS PROVIDED "AS IS" AND ANY EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO WAY SHALL THE AUTHOR OR LICENSEE BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

License Control

The Package may use one or more license control methods including, but not limited to, license key activation, periodic reporting of Package details and IP address of installation to SnertSoft, remote license verification by SnertSoft, or other future technical means. Any information reported to or gathered by SnertSoft shall remain strictly confidential and the private property of SnertSoft. Under no circumstances will SnertSoft resell or release this information to third parties, unless demanded by court order.

Support

Support is only provided for the Author's original Package. Priority support can be purchased. Free support is limited, based on the Author's availability, though enhancements requests and problem reports are welcome. A community mailing list is available; please refer to SnertSoft web site Support area for details.

Gifts

Gifts from the author's Amazon US or Amazon UK wishlist (search by mail address <achowe at snert dot com>) are welcomed for the continued encouragement, moral support, and ego pumping needed to work in foreign non-english speaking lands.

pretzels since 24 January 2004