Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Tue May 31, 2005 6:57 pm 
Offline
Junior Member

Joined: Thu May 12, 2005 2:06 pm
Posts: 48
Hi,

I was thinking about this, and I would like to know if it is possible.

My idea: gpg-sign all mails to remote server which I send from my Windows PC. I mean, my email client (The Bat!, or whatever, from everywhere) connects to my account smtp (postfix), authenticates (pop-before-smtp, ehlo, ...?) and postfix gets the email. Then postfix "signs" (how?) the email using gpg (?) and queues it for either local or remote delivering.

If I understand it well (I'm a newbie w/ postfix), nobody should be able to use my smtp server to send remote emails (no open relay), but everyone could send emails using my smtp to any of the domains I host -- perfectly normal. (Note: I host email for several domains, but I want to implement this thing in only one of them). The important point is that nobody can authenticate against smtp in my account and then send emails to other servers -- I'm the only one. Correct?

That's what I plan, to take advantage of this fact and auto-gpg-sign those emails, which I send using whatever client in whatever computer (even webmail, if possible) and get them signed before delivering.

The reason: I won't need to install PGP/GPG in every computer I touch, and more important, I won't need to type my passphrase in insecure places (say a cyber, where a keylogger can be running), but my emails (and only my emails) would be digitally signed for others to trust -- if I sent them using my smtp.

I'm almost certain I would need to write a plugin or bash script or whatever to get the email signed, but does postfix allow this kind of things?

Thank you ;)


Top
   
 Post subject:
PostPosted: Tue May 31, 2005 7:23 pm 
Offline
Senior Member

Joined: Sat Jun 05, 2004 12:49 am
Posts: 333
no, well you could but it would totally defeat the point of signing your emails


Top
   
 Post subject:
PostPosted: Tue May 31, 2005 9:13 pm 
Offline
Senior Member
User avatar

Joined: Sun Feb 08, 2004 7:18 pm
Posts: 562
Location: Austin
Quote:
no, well you could but it would totally defeat the point of signing your emails


Why? A lot of people have their clients automatically sign outgoing mail. Why not the server? He'll be responsible for making sure that he's the only one with the SMTP password etc etc...


Top
   
 Post subject:
PostPosted: Fri Jun 03, 2005 3:11 pm 
Offline
Senior Member

Joined: Sun Nov 30, 2003 2:28 pm
Posts: 245
It's the "etc. etc." that makes this idea weak. With straight GPG on the client, you only need to do one thing: keep your passphrase secret. The OPs proposal has a *lot* more links, of which breaking any one invalidates the whole sequence.

_________________
The irony is that Bill Gates claims to be making a stable operating system and Linus Torvalds claims to be trying to take over the world.
-- seen on the net


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group