Dňa 9. 10. o 8:44 Kirill Miazine via mailop napísal(a):

The reason for a long retry is that I have to manually decrypt mailstore partition in case of server reboot. Exim would accept the message, but defer delivery until the mount appears. I wanted to have some time in case of a reboot and me not being easily available to mount the partition.

Consider to spend some time to setup auto decrypt on boot, doing that manually has little security enhancement on servers, as once decrypted, the content is available to OS and thus to potentional attacker too (the only restrictions are access rights).

When you store decrypt key on separate disk (eg. USB stick), you are safe even after disk replace...

regards

--
Slavko

_______________________________________________
mailop mailing list
mailop@mailop.org
https://list.mailop.org/listinfo/mailop

Reply via email to