Opened 6 months ago

Last modified 6 months ago

#3067 new task

Perform email authenticity checks before accepting them

Reported by: strk Owned by: sac@…
Priority: major Milestone: Sysadmin Contract 2024-III
Component: SysAdmin/Postfix Keywords: spoof, email authentication, discourse, mailman
Cc: robe, cvvergara, lnicola

Description

We want to prevent spoofing, see: https://discourse.osgeo.org/t/spoofing-test/4755

Change History (4)

comment:1 by strk, 6 months ago

Keywords: spoof email authentication added

See also #3009 which may help with this

comment:2 by strk, 6 months ago

Cc: robe cvvergara lnicola added
Component: SysAdmin/DiscourseSysAdmin/Postfix
Keywords: discourse mailman added
Priority: normalmajor

It looks like Mailman is also not preventing spoofing, see https://lists.osgeo.org/pipermail/sac/2023-December/016229.html

so I'm changing this ticket to be generically for MTA (postfix)

comment:3 by strk, 6 months ago

Summary: Perform email authenticity checks before accepting them in discoursePerform email authenticity checks before accepting them

comment:4 by strk, 6 months ago

Milestone: Sysadmin Contract 2024-III
Note: See TracTickets for help on using tickets.