Viktor Dukhovni via Postfix-users:
> > * Both postfix and the daemon need to be able to open and read and
> > write the socket. The sasl package adds a sasl group but not a sasl
> > user, so I added postfix to the users for the sasl group, and run the
> > daemon as postfix:sasl. The user/group for the daemon is set in
> > /etc/systemd/system/saslauthd.service.d/user.conf
> 
> I don't recommend running "saslauthd" as the "postfix" user, better to
> create a suitable dedicated user instead.

+1. Please don't run other programs with the 'postfix' uid or
'postdrop' gid. These are part of a multi-layer defense.

        Wietse
_______________________________________________
Postfix-users mailing list -- postfix-users@postfix.org
To unsubscribe send an email to postfix-users-le...@postfix.org

Reply via email to