* Luca Cavana via Postfix-users <[email protected]> [260930 07:18]:
> > the "owner of mail address" is defined in smtp_sender_login_maps:
> Sure, and that's where I defined them via the regexp type table so that any
> sender gets an equal SASL username to be checked against.
> 
> > the regexp is just shortcut so every address is owned by the login name
> > same as the address.
> As above, that's why I did it.
> 
> I think I did not explain myself correctly, English is not my first
> language.
> First, I'm not debugging a setup which I don't know. I'm trying to
> understand how to reconcile something that I built from scratch and had to
> build it that way (namely, the regexp table that makes address == SASL
> username) to what it's actually documented.
> Reading from man 5 postconf:
> 
> "Reject  the  request when the client is authenticated with SASL, but either
> the MAIL FROM address is not listed in $smtpd_sender_login_maps, or the SASL
> login name is not an owner for that address.
> This prevents an authenticated client from using a MAIL FROM address that
> they do not explicitly own."
> 
> If we break down what is supposed to happen, according to the man page:
> 
> Reject  the  request when the client is authenticated with SASL
> WHEN
> (1) the MAIL FROM address is not listed in $smtpd_sender_login_maps
> OR
> (2) the SASL login name is not an owner for that address
> 
> Now, we need just one of (1) or (2) to be true. The point is that (2) never
> appears to be true; if it was true there would never have been the necessity
> of the third mapping table. Actually, if nobody had the need to send a
> message with a different MAIL FROM from it's SASL username there wouldn't be
> the need of any mapping table at all; but that's not what happens. If you
> remove the mapping table no message pass this check.
> 
> I probably already had a reply which explains this behavior from you:
> 
> > No. I guess it's easier to add mapping of address to login name than
> > remove it if it was there by default.
> So I just have to accept the man page is poorly worded and needs an update,
> short of a maintainer coming thru and explaining it (and if that's the case
> better clarify it in the man page for posterity also).

I think your confusion is based on equating SASL login names with email
addresses.  They are in separate name spaces.  There is no implicit
ownership by a SASL login name of any email address, including one that
matches the SASL login name.  There is no requirement that a SASL login
name be formed like an email address.

...Marvin

_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to