/*++ /* NAME /* proxymap 8 /* SUMMARY /* Postfix lookup table proxy server /* SYNOPSIS /* \fBproxymap\fR [generic Postfix daemon options] /* DESCRIPTION /* The \fBproxymap\fR(8) server provides read-only or read-write /* table lookup service to Postfix processes. These services are /* implemented with distinct service names: \fBproxymap\fR and /* \fBproxywrite\fR, respectively. The purpose of these services is: /* .IP \(bu /* To overcome chroot restrictions. For example, a chrooted SMTP /* server needs access to the system passwd file in order to /* reject mail for non-existent local addresses, but it is not /* practical to maintain a copy of the passwd file in the chroot /* jail. The solution: /* .sp /* .nf /* local_recipient_maps = /* proxy:unix:passwd.byname $alias_maps /* .fi /* .IP \(bu /* To consolidate the number of open lookup tables by sharing /* one open table among multiple processes. For example, making /* mysql connections from every Postfix daemon process results /* in "too many connections" errors. The solution: /* .sp /* .nf /* virtual_alias_maps = /* proxy:mysql:/etc/postfix/virtual_alias.cf /* .fi /* .sp /* The total number of connections is limited by the number of /* proxymap server processes. /* .IP \(bu /* To provide single-updater functionality for lookup tables /* that do not reliably support multiple writers (i.e. all /* file-based tables that are not based on \fBlmdb\fR). /* .PP /* The \fBproxymap\fR(8) server implements the following requests: /* .IP "\fBopen\fR \fImaptype:mapname instance-flags\fR" /* Open the table with type \fImaptype\fR and name \fImapname\fR, /* with initial dictionary flags \fIinstance-flags\fR. The reply /* contains the actual dictionary flags (for example, to distinguish /* a fixed-string table from a regular-expression table). /* .IP "\fBlookup\fR \fImaptype:mapname instance-flags request-flags key\fR" /* Look up the data stored under the requested key using the /* dictionary flags in \fIrequest-flags\fR. /* The reply contains the request completion status code, the /* resulting dictionary flags, and the lookup result value. /* The \fImaptype:mapname\fR and \fIinstance-flags\fR are the same /* as with the \fBopen\fR request. /* .IP "\fBupdate\fR \fImaptype:mapname instance-flags request-flags key value\fR" /* Update the data stored under the requested key using the /* dictionary flags in \fIrequest-flags\fR. /* The reply contains the request completion status code and the /* resulting dictionary flags. /* The \fImaptype:mapname\fR and \fIinstance-flags\fR are the same /* as with the \fBopen\fR request. /* .sp /* To implement single-updater maps, specify a process limit /* of 1 in the master.cf file entry for the \fBproxywrite\fR /* service. /* .sp /* This request is supported in Postfix 2.5 and later. /* .IP "\fBdelete\fR \fImaptype:mapname instance-flags request-flags key\fR" /* Delete the data stored under the requested key, using the /* dictionary flags in \fIrequest-flags\fR. /* The reply contains the request completion status code and the /* resulting dictionary flags. /* The \fImaptype:mapname\fR and \fIinstance-flags\fR are the same /* as with the \fBopen\fR request. /* .sp /* This request is supported in Postfix 2.5 and later. /* .IP "\fBsequence\fR \fImaptype:mapname instance-flags request-flags function\fR" /* Iterate over the specified database, using the dictionary flags /* in \fIrequest-flags\fR. The \fIfunction\fR is either /* DICT_SEQ_FUN_FIRST or DICT_SEQ_FUN_NEXT. /* The reply contains the request completion status code, the /* resulting dictionary flags, and a lookup key and result value /* if found. /* The \fImaptype:mapname\fR and \fIinstance-flags\fR are the same /* as with the \fBopen\fR request. /* .sp /* This request is supported in Postfix 2.9 and later. /* .IP "Not implemented: close" /* There is no \fBclose\fR request, nor are tables implicitly closed /* when a client disconnects. The purpose is to share tables among /* multiple client processes. Due to the absence of an explicit or /* implicit \fBclose\fR, updates are forced to be synchronous. /* .PP /* The request completion status is one of OK, RETRY, NOKEY /* (lookup failed because the key was not found), BAD (malformed /* request) or DENY (the table is not approved for proxy read /* or update access). /* SERVER PROCESS MANAGEMENT /* .ad /* .fi /* \fBproxymap\fR(8) servers run under control by the Postfix /* \fBmaster\fR(8) /* server. Each server can handle multiple simultaneous connections. /* When all servers are busy while a client connects, the \fBmaster\fR(8) /* creates a new \fBproxymap\fR(8) server process, provided that the /* process limit is not exceeded. /* Each server terminates after serving at least \fB$max_use\fR clients /* or after \fB$max_idle\fR seconds of idle time. /* SECURITY /* .ad /* .fi /* The \fBproxymap\fR(8) server opens only tables that are /* approved via the \fBproxy_read_maps\fR or \fBproxy_write_maps\fR /* configuration parameters, does not talk to /* users, and can run at fixed low privilege, chrooted or not. /* However, running the proxymap server chrooted severely limits /* usability, because it can open only chrooted tables. /* /* The \fBproxymap\fR(8) server is not a trusted daemon process, and must /* not be used to look up sensitive information such as UNIX user or /* group IDs, mailbox file/directory names or external commands. /* /* In Postfix version 2.2 and later, the proxymap client recognizes /* requests to access a table for security-sensitive purposes, /* and opens the table directly. This allows the same main.cf /* setting to be used by sensitive and non-sensitive processes. /* /* Postfix-writable data files should be stored under a dedicated /* directory that is writable only by the Postfix mail system, /* such as the Postfix-owned \fBdata_directory\fR. /* /* In particular, Postfix-writable files should never exist /* in root-owned directories. That would open up a particular /* type of security hole where ownership of a file or directory /* does not match the provider of its content. /* DIAGNOSTICS /* Problems and transactions are logged to \fBsyslogd\fR(8) /* or \fBpostlogd\fR(8). /* BUGS /* The \fBproxymap\fR(8) server provides service to multiple clients, /* and must therefore not be used for tables that have high-latency /* lookups. /* /* The \fBproxymap\fR(8) read-write service does not explicitly /* close lookup tables (even if it did, this could not be relied on, /* because the process may be terminated between table updates). /* The read-write service should therefore not be used with tables that /* leave persistent storage in an inconsistent state between /* updates (for example, CDB). Tables that support "sync on /* update" should be safe (for example, Berkeley DB) as should /* tables that are implemented by a real DBMS. /* CONFIGURATION PARAMETERS /* .ad /* .fi /* On busy mail systems a long time may pass before /* \fBproxymap\fR(8) relevant /* changes to \fBmain.cf\fR are picked up. Use the command /* "\fBpostfix reload\fR" to speed up a change. /* /* The text below provides only a parameter summary. See /* \fBpostconf\fR(5) for more details including examples. /* .IP "\fBconfig_directory (see 'postconf -d' output)\fR" /* The default location of the Postfix main.cf and master.cf /* configuration files. /* .IP "\fBdata_directory (see 'postconf -d' output)\fR" /* The directory with Postfix-writable data files (for example: /* caches, pseudo-random numbers). /* .IP "\fBdaemon_timeout (18000s)\fR" /* How much time a Postfix daemon process may take to handle a /* request before it is terminated by a built-in watchdog timer. /* .IP "\fBipc_timeout (3600s)\fR" /* The time limit for sending or receiving information over an internal /* communication channel. /* .IP "\fBmax_idle (100s)\fR" /* The maximum amount of time that an idle Postfix daemon process waits /* for an incoming connection before terminating voluntarily. /* .IP "\fBmax_use (100)\fR" /* The maximal number of incoming connections that a Postfix daemon /* process will service before terminating voluntarily. /* .IP "\fBprocess_id (read-only)\fR" /* The process ID of a Postfix command or daemon process. /* .IP "\fBprocess_name (read-only)\fR" /* The process name of a Postfix command or daemon process. /* .IP "\fBproxy_read_maps (see 'postconf -d' output)\fR" /* The lookup tables that the \fBproxymap\fR(8) server is allowed to /* access for the read-only service. /* .PP /* Available in Postfix 2.5 and later: /* .IP "\fBdata_directory (see 'postconf -d' output)\fR" /* The directory with Postfix-writable data files (for example: /* caches, pseudo-random numbers). /* .IP "\fBproxy_write_maps (see 'postconf -d' output)\fR" /* The lookup tables that the \fBproxymap\fR(8) server is allowed to /* access for the read-write service. /* .PP /* Available in Postfix 3.3 and later: /* .IP "\fBservice_name (read-only)\fR" /* The master.cf service name of a Postfix daemon process. /* SEE ALSO /* postconf(5), configuration parameters /* master(5), generic daemon options /* README FILES /* .ad /* .fi /* Use "\fBpostconf readme_directory\fR" or /* "\fBpostconf html_directory\fR" to locate this information. /* .na /* .nf /* DATABASE_README, Postfix lookup table overview /* LICENSE /* .ad /* .fi /* The Secure Mailer license must be distributed with this software. /* HISTORY /* .ad /* .fi /* The proxymap service was introduced with Postfix 2.0. /* AUTHOR(S) /* Wietse Venema /* IBM T.J. Watson Research /* P.O. Box 704 /* Yorktown Heights, NY 10598, USA /* /* Wietse Venema /* Google, Inc. /* 111 8th Avenue /* New York, NY 10011, USA /* /* Wietse Venema /* porcupine.org
/*--*/
while (strncmp(map_type_name, PROXY_COLON, PROXY_COLON_LEN) == 0)
map_type_name += PROXY_COLON_LEN; /* XXX The following breaks with maps that have ':' in their name. */ if (strchr(map_type_name, ':') == 0)
PROXY_MAP_FIND_ERROR_RETURN(PROXY_STAT_BAD); if (htable_locate(proxy_auth_maps, map_type_name) == 0) {
msg_warn("request for unapproved table: \"%s\"", map_type_name);
msg_warn("to approve this table for %s access, list %s:%s in %s:%s",
proxy_writer == 0 ? "read-only" : "read-write",
DICT_TYPE_PROXY, map_type_name, MAIN_CONF_FILE,
PROXY_MAP_PARAM_NAME(proxy_writer));
PROXY_MAP_FIND_ERROR_RETURN(PROXY_STAT_DENY);
}
/* proxymap_sequence_service - remote sequence service */
staticvoid proxymap_sequence_service(VSTREAM *client_stream)
{ int inst_flags; int request_flags;
DICT *dict; int request_func; constchar *reply_key; constchar *reply_value; int dict_status; int reply_status;
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Hier finden Sie eine Liste der Produkte des Unternehmens