Problems with MailScanner and SELinux compatibility

Martin Hepworth maxsec at gmail.com
Thu Jun 9 18:40:20 IST 2011


MArk

Ok beyond the usual reply that using FC for a 'server' is a bad idea due to
the short build/support cycle and bleeding edge features... :-) (use centos)

Put mailScanner on a dedicated box that sits between the internet and the
actual mailserver. That way if one of the duties of either mailscanning or
mailserving you don't take out both functions at the same time. I've helped
a couple of installations where both duties where on the same box and
upgrades, maintanance becomes 'interesting' and frought quote quickly.

I also tend to turn off SELinux as I tend it more trouble than it's worth -
either that or I'm just too darn lazy to get my head arounf SElinux. :-)

-- 
Martin Hepworth
Oxford, UK


On 9 June 2011 16:53, Mark L. Wise <mark at alpha2.com> wrote:

> Sorry if this is a second post...  I am still debugging my new mail server
> and I did not see the first post come back to me from the list...
>
> I have just built a new box based on Fedora Core 15 (2.6.38.7-30).  I am
> going to use this box as a mail server.  I am using sendmail (8.14.4),
> spamassassin (3.3.2-r929478), clamav (0.97), dovecot (2.0.13) and
> MailScanner (4.83.5).
>
> Everything appears to be configured well and working, except when I turn on
> MailScanner I get errors in the maillog file that indicate a problem writing
> (apparently temporary) files.
>
> After a bit of research, it appears that this may be a conflict between
> MailScanner and SELinux.
>
> Does anyone have a SELinux policy or know of a way to fix this issue?  I
> really would like to have SELinux enforcing AND MailScanner checking my
> mail.
>
> Thanks in advance for any help you can give me.
>
> Mark
>
> --
> Mark L. Wise
>
> Alpha II Service, Inc.
> 1312 Epworth Ave
> Reynoldsburg, Ohio 43068-2116
> USA
>
> Office: (614) 868-5033
> Fax: (614) 868-1060
> Email: mark at alpha2.com
> WEB: www.alpha2.com
>
> "People do not quit playing because they grow old; they grow old because
> they quit playing."
>
> Oliver Wendell Holmes
> --
> MailScanner mailing list
> mailscanner at lists.mailscanner.info
> http://lists.mailscanner.info/mailman/listinfo/mailscanner
>
> Before posting, read http://wiki.mailscanner.info/posting
>
> Support MailScanner development - buy the book off the website!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20110609/fbab1143/attachment.html


More information about the MailScanner mailing list