PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Logiciels d'hébergement > comp.mail.sendmail > LDAP route outbound mail?
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
comp.mail.sendmail Configuring and using the BSD sendmail agent.

LDAP route outbound mail?

Réponse
 
LinkBack Outils de la discussion
Vieux 04/09/2007, 20h54   #1
cliff.patterson08@gmail.com
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut LDAP route outbound mail?

I have a problem that I'm hoping can be solved with a Sendmail based
solution.

There is a community of organizations who need to share sensitive
information via email. As an organization that is trusted by all
parties, we host a smarthost service through which all participating
orgs send all of their outbound email. The smarthost contains the
central list of participating domains and routes email among
participants and/or the Internet. This smarthost ensures that all
email flowing to/from participating orgs is secured within an
authenticated TLS session. The business has deemed this sufficient
security to exchange sensitive information among participating
organizations.

This solution is complemented by an LDAP service that provides a list
of participating organizations' recipients, so that end users know to
whom they can send sensitive information.

We would like to offer some flexibility to the participating orgs such
that they don't have to send Internet-bound email through us. And we
want to do this without introducing a new DNS service. We also don't
want organizations to have to make changes to their systems each time
we add a new organization (i.e. central administration of email routes
required).

We're thinking of having the participating organizations' email
gateways applying the following logic:

For each outbound message:
1) Check the LDAP directory to see if the recipient in the To: field
is participating in the federation.
2) If the recipient is found, send to the smarthost.
3) If the recipient is not found (and we're sure LDAP is functioning),
then use Internet DNS resolve domains and route the message.

To optimize performance, we would like to publish "domain" objects in
the LDAP directory so that the entire (large) directory doesn't have
to be parsed for each message. Additional performance could be had by
caching the list of participating domains that is fetched from the
LDAP directory.

How might we do this with Sendmail? Are there any appliances that
offer such rich outbound routing capabilities?

Thanks for considering my problem.

  Réponse avec citation
Vieux 06/09/2007, 01h12   #2
Robert Harker
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: LDAP route outbound mail?

On Sep 4, 12:54 pm, cliff.patterso...@gmail.com wrote:
> For each outbound message:
> 1) Check the LDAP directory to see if the recipient in the To: field
> is participating in the federation.
> 2) If the recipient is found, send to the smarthost.
> 3) If the recipient is not found (and we're sure LDAP is functioning),
> then use Internet DNS resolve domains and route the message.


> How might we do this with Sendmail? Are there any appliances that
> offer such rich outbound routing capabilities?


I think you could do this with FEATURE(`ldap_routing') and defining
the class $={{LDAPRoute} as an LDAP lookup:
LDAPROUTE_DOMAIN_FILE(`@LDAP')
Look in the cf/README file for more information.

The only drawback is that classes are statically loaded into memory,
so if
you add a new domain to the class, you have to kill and restart the
sendmail
daemon. An ugly solution would be to restart the daemon on a periodic
basis
via cron. If new domains added infrequently, you could also just send
out
a daemon restart notice.

Hope this s

RLH

For info about our "Sendmail and DNS Handson Training or our in depth
"Managing Internet Mail, Setting Up and Trouble Shooting sendmail and
DNS" classes and a schedule of dates and locations, please send email
to info@harker.com, or visit www.harker.com

Robert Harker
Harker Systems
harker@harker.com


  Réponse avec citation
Vieux 06/09/2007, 01h12   #3
Robert Harker
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: LDAP route outbound mail?

On Sep 4, 12:54 pm, cliff.patterso...@gmail.com wrote:
> For each outbound message:
> 1) Check the LDAP directory to see if the recipient in the To: field
> is participating in the federation.
> 2) If the recipient is found, send to the smarthost.
> 3) If the recipient is not found (and we're sure LDAP is functioning),
> then use Internet DNS resolve domains and route the message.


> How might we do this with Sendmail? Are there any appliances that
> offer such rich outbound routing capabilities?


I think you could do this with FEATURE(`ldap_routing') and defining
the class $={{LDAPRoute} as an LDAP lookup:
LDAPROUTE_DOMAIN_FILE(`@LDAP')
Look in the cf/README file for more information.

The only drawback is that classes are statically loaded into memory,
so if
you add a new domain to the class, you have to kill and restart the
sendmail
daemon. An ugly solution would be to restart the daemon on a periodic
basis
via cron. If new domains added infrequently, you could also just send
out
a daemon restart notice.

Hope this s

RLH

For info about our "Sendmail and DNS Handson Training or our in depth
"Managing Internet Mail, Setting Up and Trouble Shooting sendmail and
DNS" classes and a schedule of dates and locations, please send email
to info@harker.com, or visit www.harker.com

Robert Harker
Harker Systems
harker@harker.com


  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 19h22.


Édité par : vBulletin® version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières ©2000-2008
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,12163 seconds with 11 queries