- To: jon@xxxxxxxxx
- Subject: [chat] RE: [SLUG] Statement of Attainment in Linux
- From: Kevin Saenz <ksaenz@xxxxxxxxxxxxxxx>
- Date: 02 Aug 2003 20:01:05 +1000
- Cc: slug-chat@xxxxxxxxxxx
- Cc: 'Del' <del@xxxxxxxxxxxx>
> -=> Very brave. My only beef with sendmail is that it is
> -=> usually full of holes. Every where I have worked we have
> -=> either implemented qmail or postfix both MTAs that are very
> -=> secure and going strong. Though my choice out of the two is
> -=> postfix.
>
> Mind explaining your reasons for the preference ?
My reasons for choosing Postfix. As far as I am aware there are no known
vulnerabilities in postfix.
This is a quote from www.cert.org "postfix has been designed to avoid
common security problems such as shell access, set-uid, buffer overruns
and DoS."
It is easy to implement the config file is plain English.
Probably designed for the lazy administrators. That is why Microsoft
products are so successful. :)
SpamAssassin, Razor, mailman, all run fine under postfix.
So for me the knowledge that postfix is reasonably secure. Less than
five months ago Sendmail had a buffer overflow issue, I am aware that it
was quickly resolved but to me it just doesn't cut it.