> Wietse Venema via Postfix-users <[email protected]>:
> 
> Gerald Galster via Postfix-users:
>> 3) SOCKS5 (uncommon)
>> 
>> This approach requires tools like socksify or proxychains which use 
>> LD_PRELOAD
>> to intercept system calls to make apps SOCKS5 compatible. On the VPS side 
>> you'd
>> need a SOCKS5 server such as Dante or just use sshd's SOCKS5 proxy (ssh -D),
>> which also encrypts the otherwise plaintext SOCKS5 traffic.
> 
> I was thinking of adding libsocks library calls for inbound or
> outbound remote SMTP connections.  If I'm not mistaken, socksify
> etc. want to intercept not only TCP but also DNS. Would that work
> with DNSSEC?

Documentation on this topic is sparse but according to socks.conf [1],
which socksify uses, resolveprotocol values are "udp", "tcp" (which
both resolve locally) and "fake", which sends the hostname to the SOCKS
server for remote resolution. Chances are you get unaltered results using
the local variants.

In general DNS over SOCKS5 should work but DNSSEC UDP responses may exceed
the 512 byte legacy limit. Dante adresses this with its "udpassociate" option
[2 / Socksified system calls], but some implementations are described as flaky
in this regard. 

The SOCKS protocol was not designed for the server case, so it may
not be supported by all implementations [3 / Protocol operations]:

  The SOCKS protocol is not really designed for the type of traffic
  reception found in servers, where an arbitrary number of clients
  connect to a single server port, but rather to the type of traffic
  reception found in some applications, such as active-mode FTP,
  where a single connection is expected from a known source. However,
  some SOCKS servers (such as Dante) support extensions to the SOCKS
  protocol that allow ordinary server applications to accept client
  requests via the SOCKS server.

For traffic originating from external hosts you will also need bindreply
(udpreply), see [4 / example at the end of "Server configuration"]

Given all these quirks the container/jail/VM approach seems like the better 
option.

Best regards,
Gerald

[1] https://www.inet.no/dante/doc/1.4.x/socks.conf.5.html
[2] https://www.inet.no/dante/doc/latest/config/client.html
[3] https://www.inet.no/dante/doc/latest/config/socks.html
[4] https://www.inet.no/dante/doc/latest/config/auth.html

_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to