Re: [Exim] Limited relaying

Top Page
Delete this message
Reply to this message
Author: Tabor J. Wells
Date:  
To: Joe Wagg
CC: exim-users
Subject: Re: [Exim] Limited relaying
On Thu, Sep 04, 2003 at 02:11:52PM -0500,
Joe Wagg <jwagg1@???> is thought to have said:

> I'd like to permit relaying from any host that authenticates with a valid
> username & password. How easy and secure is it?
>
> I'm using Exim v4.0 and Slackware 8.0


It's trivial to do. The docs state very clearly how to set up
SMTP AUTH. You should read them.

It's as secure as you make it. By this I mean, you can advertise SMTP AUTH
but you should probably only advertise the PLAIN/LOGIN AUTH mechanisms over
a STARTTLS encrypted connection since the passwords are essentially sent in
the clear. CRAM-MD5 is safe to use over an unencrypted SMTP session though.

--
--------------------------------------------------------------------
Tabor J. Wells                                     twells@???
Fsck It!                 Just another victim of the ambient morality