|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
--- exim-4.43/src/configure.default.pam 2004-12-16 13:27:55.000000000 +0000
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+++ exim-4.43/src/configure.default 2004-12-16 15:41:34.000000000 +0000
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
@@ -160,7 +160,7 @@ acl_smtp_data = acl_check_data
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# Allow any client to use TLS.
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
-# tls_advertise_hosts = *
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+tls_advertise_hosts = *
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# Specify the location of the Exim server's TLS certificate and private key.
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# The private key must not be encrypted (password protected). You can put
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
@@ -168,8 +168,8 @@ acl_smtp_data = acl_check_data
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# need the first setting, or in separate files, in which case you need both
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# options.
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
-# tls_certificate = /etc/ssl/exim.crt
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
-# tls_privatekey = /etc/ssl/exim.pem
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
c11786b |
+tls_certificate = /etc/pki/tls/certs/exim.pem
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
c11786b |
+tls_privatekey = /etc/pki/tls/private/exim.pem
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# In order to support roaming users who wish to send email from anywhere,
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# you may want to make Exim listen on other ports as well as port 25, in
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
@@ -180,8 +180,8 @@ acl_smtp_data = acl_check_data
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# them you should also allow TLS-on-connect on the traditional but
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# non-standard port 465.
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
-# daemon_smtp_ports = 25 : 465 : 587
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
-# tls_on_connect_ports = 465
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
+daemon_smtp_ports = 25 : 465 : 587
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
+tls_on_connect_ports = 465
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# Specify the domain you want to be added to all unqualified addresses
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
@@ -238,6 +238,24 @@
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
timeout_frozen_after = 7d
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# This setting, if uncommented, allows users to authenticate using
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# their system passwords against saslauthd if they connect over a
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# secure connection. If you have network logins such as NIS or
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# Kerberos rather than only local users, then you possibly also want
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# to configure /etc/sysconfig/saslauthd to use the 'pam' mechanism
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# too. Once a user is authenticated, the acl_check_rcpt ACL then
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# allows them to relay through the system.
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+#
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# auth_advertise_hosts = ${if eq {$tls_cipher}{}{}{*}}
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+#
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# By default, we set this option to allow SMTP AUTH from nowhere
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# (Exim's default would be to allow it from anywhere, even on an
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# unencrypted connection).
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+#
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# Comment this one out if you uncomment the above. Did you make sure
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+# saslauthd is actually running first?
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+#
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
+auth_advertise_hosts =
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
######################################################################
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
@@ -850,7 +837,7 @@ begin authenticators
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# driver = plaintext
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# server_set_id = $auth2
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# server_prompts = :
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
-# server_condition = Authentication is not yet configured
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
+# server_condition = ${if saslauthd{{$2}{$3}{smtp}} {1}}
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# server_advertise_condition = ${if def:tls_cipher }
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# LOGIN authentication has traditional prompts and responses. There is no
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
@@ -862,7 +849,7 @@ begin authenticators
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# driver = plaintext
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# server_set_id = $auth1
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# server_prompts = <| Username: | Password:
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
-# server_condition = Authentication is not yet configured
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
+# server_condition = ${if saslauthd{{$1}{$2}{smtp}} {1}}
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
5bfed37 |
# server_advertise_condition = ${if def:tls_cipher }
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
|
|
![](https://seccdn.libravatar.org/avatar/0988a4e1ba438efd5e1e90f8503938283125bffa0555f46da0ef90ddd186adb8?s=16&d=retro) |
cda8379 |
|