[SLUG] Sendmail security or bust?

From: Brett Simpson (Simpsonb@hillsboroughcounty.org)
Date: Tue Apr 09 2002 - 09:27:23 EDT


I appreciate the feddback I have recieved but now I know where the comments dealing with security came into play from my manager. The main reason is he wants to replace Sendmail with the Groupwise Internet agents. Does anyone have any comments on what my manager has wrote? Due to the nature of us being government I can't suggest using Postfix without being overridden in favor of Groupwise. As a side note our Groupwise system has crashed on numerous occasions under heavy and light loads (2000 users) but despite this I have to defeat this header information thing in order to keep Sendmail in place. Government is a crazy!

Here's the email:
"My original question that kicked this off is that Sendmail can be tricked into sending header information back to the recipient to give more clues up as to who we are and what our IP numbers and conventions are. In no way was I saying that Sendmail is an insecure product on the whole, however I think we need to revisit putting GroupWise directly onto the Internet."

Brett Simpson



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 19:57:05 EDT