Re: [Exim] never_users = root if exim_user != root ?

Top Page
Delete this message
Reply to this message
Author: Nigel Metheringham
Date:  
To: Andromeda
CC: Exim
Subject: Re: [Exim] never_users = root if exim_user != root ?
andromeda@??? said:
> Now the question remains... is it a good thing to let it run as root
> for local delivery? How would one deliver mail to the root user (as
> the administrator of the machine)?


You don't - the basic rule is that you do as little as possible as
root, so mail delivery and reading should be done by a different
account without privileges (and root's mail aliased to that user).

Reasons for doing this include such things as potential holes in (say)
metamail which could lead to a system compromise as opposed to an
account compromise if you run them as root.

You can never be too paranoid - and they are out to get you.

    Nigel.


-- 
[ Nigel Metheringham                  Nigel.Metheringham@??? ]
[ Phone: +44 1423 850000                         Fax +44 1423 858866 ]