> Wietse Venema via Postfix-users <[email protected]>: > > Gerald Galster via Postfix-users: >> 3) SOCKS5 (uncommon) >> >> This approach requires tools like socksify or proxychains which use >> LD_PRELOAD >> to intercept system calls to make apps SOCKS5 compatible. On the VPS side >> you'd >> need a SOCKS5 server such as Dante or just use sshd's SOCKS5 proxy (ssh -D), >> which also encrypts the otherwise plaintext SOCKS5 traffic. > > I was thinking of adding libsocks library calls for inbound or > outbound remote SMTP connections. If I'm not mistaken, socksify > etc. want to intercept not only TCP but also DNS. Would that work > with DNSSEC?
Documentation on this topic is sparse but according to socks.conf [1], which socksify uses, resolveprotocol values are "udp", "tcp" (which both resolve locally) and "fake", which sends the hostname to the SOCKS server for remote resolution. Chances are you get unaltered results using the local variants. In general DNS over SOCKS5 should work but DNSSEC UDP responses may exceed the 512 byte legacy limit. Dante adresses this with its "udpassociate" option [2 / Socksified system calls], but some implementations are described as flaky in this regard. The SOCKS protocol was not designed for the server case, so it may not be supported by all implementations [3 / Protocol operations]: The SOCKS protocol is not really designed for the type of traffic reception found in servers, where an arbitrary number of clients connect to a single server port, but rather to the type of traffic reception found in some applications, such as active-mode FTP, where a single connection is expected from a known source. However, some SOCKS servers (such as Dante) support extensions to the SOCKS protocol that allow ordinary server applications to accept client requests via the SOCKS server. For traffic originating from external hosts you will also need bindreply (udpreply), see [4 / example at the end of "Server configuration"] Given all these quirks the container/jail/VM approach seems like the better option. Best regards, Gerald [1] https://www.inet.no/dante/doc/1.4.x/socks.conf.5.html [2] https://www.inet.no/dante/doc/latest/config/client.html [3] https://www.inet.no/dante/doc/latest/config/socks.html [4] https://www.inet.no/dante/doc/latest/config/auth.html _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
