Restricting Specific Users

Discuss the Scalix Server software

Moderators: ScalixSupport, admin

MailMan
Posts: 30
Joined: Sun Sep 23, 2007 12:56 pm

Restricting Specific Users

Postby MailMan » Sun Sep 23, 2007 1:02 pm

Hi there,

We're about to roll out Scalix as a standard in our medium enterprise and one of the requirements we have right now is the ability to restrict users differently.

We want some users to be able to mail outside from one of our "World Accessible" domain names but for security reasons, we don't want others to be able to mail outside. That is, they should only be allowed to send mail to users who exist on that machine and no-one else.

So far the best suggestion is to just use a simple internal DNS address that doesn't exist in the outside world, but this only means that the users cannot receive mail from the outside, it doesn't mean they can't send it.

It can't be blocked by IPTables either as we want the same servers to be able to mail to the outside world for privileged users.

Does anyone have any ideas of if / how Scalix can resolve this matter?

Thanks and regards,

Ken

mikethebike
Posts: 566
Joined: Mon Nov 28, 2005 4:16 pm
Location: England

Postby mikethebike » Mon Sep 24, 2007 5:57 am

Ken,

you should be able to set up an acl for unix queue (man omaddacln).

Mick

MailMan
Posts: 30
Joined: Sun Sep 23, 2007 12:56 pm

Postby MailMan » Mon Sep 24, 2007 10:57 am

Ok go raibh maith agat Mick. Taistailfaidh me e

mikethebike
Posts: 566
Joined: Mon Nov 28, 2005 4:16 pm
Location: England

Postby mikethebike » Mon Sep 24, 2007 11:14 am

hahahaha! I had to translate, not a native, but applying for it :-)

adh mor ort

Mick

dkelly
Scalix
Scalix
Posts: 593
Joined: Thu Mar 18, 2004 2:03 pm

Postby dkelly » Mon Sep 24, 2007 12:54 pm

You can achieve what you need by using service levels for the users.

Using ommodu like this

Code: Select all

ommodu -o "User Name" -s lvl
where lvl is a number, you can add a message delivery rule set to /var/opt/scalix/NN/s/rules/


Take a look at http://www.scalix.com/forums/viewtopic.php?t=125&highlight=senderservicelevel for more information.

Message Delivery rulesets are documented in the Administration guide on page 136 at http://www.scalix.com/documents

Cheers

Dave

mikethebike
Posts: 566
Joined: Mon Nov 28, 2005 4:16 pm
Location: England

Postby mikethebike » Tue Sep 25, 2007 12:00 pm

Dve,

but that would allow/stop the message at the service router? The user needs to be able to send internally, but restricted externally.

Mick

on second thoughts...sorry you are right...only apply that rule to the unix routes!! Good call Dave :-)


Return to “Scalix Server”



Who is online

Users browsing this forum: No registered users and 3 guests

cron