10 msgheader check question
12 msgverify parameters
4 msgConfigure postfix in big env
2 msgenvelope sender '<>' via uucp gets rewrit...
2 msgSpam filtering only for specific email accounts
3 msgPostfix 2.4 to 2.5: smtp(d)_tls_session_cache_d...

Question about 'standards' WRT BATV and SAV
\ Robert Fournerat (8 May 2008)
. \ mouss (8 May 2008)
. \ (Wietse Venema) (8 May 2008)
. . \ Mike Selner (12 May 2008)
. . . \ Victor Duchovni (12 May 2008)
. . . \ Arne Hoffmann (12 May 2008)
. . . . \ Mike Selner (12 May 2008)
. . . . . \ mouss (12 May 2008)
. . . . . \ Arne Hoffmann (12 May 2008)
. . . \ mouss (12 May 2008)
. \ Ralf Hildebrandt (9 May 2008)
. . \ Jacqui Caren (9 May 2008)
. \ Arne Hoffmann (9 May 2008)
. . \ Bill Cole (9 May 2008)
. \ Bill Cole (9 May 2008)

7 msgmy solution to fight backscatter email
2 msgAUTO: Joe Grastara is out of the office (return...
12 msgQ about sender_dependent_relayhost_maps inbound...
16 msgMilter Suggestions
9 msgTransport table and postmap
3 msgArchiving e-mail?
8 msgError 550: unable to relay
1 msgFW: new subject
13 msgTLS handshake error
6 msgSeperating SMTP and POP/IMAP services
3 msgTest 2
1 msgTesting
12 msg[Fwd: ldap users & aliases config]
Subject:Question about 'standards' WRT BATV and SAV
Group:Postfix-users
From:Robert Fournerat
Date:8 May 2008


 
Please forgive me if this has already been discussed. I saw
that in May of '06, Ralf, Victor, and Wietse had a small
discussion about BATV. I know this is not a BATV list, but
there are people here with whom I tend to be more "policy
aligned". So I beg some latitude and guidance.

BATV is mucking with the envelope FROM: address. It appears
to me that when Postfix does a SAV, Postfix is trying to
verify the envelope's FROM: address (ie: the thing that BATV
modified). Can someone please confirm that or correct me?

Unlike Ralf, regardless of what address_verify_sender value
I use, the SAV's fail. Does this mean that the sender's
have misconfigured their BATV? Does this mean that the senders
cannot use BATV if their ingress and egress servers are
different and share no BATV info? Otherwise, how can BATV
possibly help with the backscatter problem? Maybe I just
don't understand BATV (but I think I do).

So BATV offuscates the FROM: address. This seems like a
TERRIBLE idea to me. Isn't the BATV methodology making an
email look MORE suspicious by forging a FROM: address?
This seems like a very slippery slope. Doesn't this
create more problems? Is BATV even complient with the SMTP
RFC standards?

I know that some belive that SAV is evil because it enables
the possibility of being abused in a DOS attach against some-
one else. I think SAV catches enough junk that it is worth
using. For those that do not use SAV, have you devised
other methods that are as effective, and if so, can you share?

thanks,
Robert


----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.



© 2004-2008 readlist.com